A “connected app” can feel harmless. You click “Sign in with Google” or “Continue with Microsoft,” approve a few prompts, and move on. Weeks later, that same app may still be pulling data quietly, because OAuth tokens don’t need your password to keep working.
If you care about privacy, this is one of the highest-return habits you can build. In about 20 minutes, you can review which apps have access, remove what you don’t trust, and reduce the chance of silent data pulls from email, files, contacts, and calendars.
Quick disclaimer: the steps below cover both personal accounts and common small-business setups, but enterprise tenants (Microsoft work or school, Google Workspace with admin policies) can look different, and some removals may be controlled by an admin.
Minute 0 to 5: Take inventory and score risk fast (before you click Remove)
Start by getting a quick picture of what’s connected. Think of this like checking who has spare keys to your house. Some keys open only the mailbox, others open every door, and some never expire unless you take them back.
- Open two tabs: one for Google, one for Microsoft, and sign in.
- Google: go to your Google Account, then open the connections area described in Google’s third-party connections help page.
- Microsoft: if you use a work or school account, permissions often live in the My Apps portal, see Microsoft’s My Apps permissions guide.
- Scan for “unknown” and “unused” first. If you don’t recognize the app name, logo, or publisher, that’s a reason to pause. Same if you haven’t used it in months.
- Look for high-power scopes, especially anything tied to email, files, or “offline” access. When you see “offline access,” it often means refresh tokens, which can keep working in the background.
Here’s a simple rubric you can use in the moment:
| Risk level | Typical access you’ll see | Why it matters |
|---|---|---|
| Low | Basic profile, sign-in, openid, email address | Usually identifies you, doesn’t read your content |
| Medium | Contacts, calendar, limited file access, basic mail metadata | Can expose relationship data and scheduling |
| High | Read or send mail, read Drive/OneDrive files, full mailbox, full file access, offline access | Enables large-scale copying and long-lived background pulls |
A practical rule: if an app has High access and you can’t explain why it needs it, plan to remove it. You can always reconnect later with tighter permissions.
Minute 5 to 12: Google connected apps purge (stop “Sign in with Google” data access)
On Google, you’re looking for third-party apps and services that have account access. The labels shift over time, so use the intent of the menu, not the exact wording.
- Go to myaccount.google.com.
- In the left menu, choose Security (on mobile, it may be a top tab).
- Scroll to a section labeled something like:
- Your connections to third-party apps & services, or
- Third-party apps with account access, or
- Sign in with Google
- Open the management view (often labeled Manage third-party access or See all connections).
Now work through the list with purpose, not panic:
- Click an app to view its details. You’re looking for what it can access, such as Gmail, Google Drive, Contacts, Calendar, or “additional access.”
- If you decide it shouldn’t have access, choose Remove access (sometimes shown as Delete connection). Confirm the prompt.
A few common gotchas:
- Duplicate entries: Some services show more than one connection (for sign-in plus data access). Remove each one that looks unnecessary.
- Email clients and recent OAuth changes: If an email app suddenly broke, you may have re-authorized it quickly. It’s worth verifying the scopes you granted, especially as Gmail continues tightening auth flows. Context on what’s changing shows up in coverage like Gmail OAuth 2.0 changes in 2026, but your best signal is still the scopes listed in your account.
- Revoking doesn’t claw back data: Removing access stops future pulls. It doesn’t erase what an app already copied. If you’re worried about retention, you may need to contact the vendor and request deletion.
This is also a good moment to use the exact move you came for: revoke oauth access for anything that reads mail, accesses Drive, or requests offline access without a clear need.
Minute 12 to 20: Microsoft connected apps purge (personal accounts, then work or school)
Microsoft splits this by account type. A personal Microsoft account (Outlook.com, Hotmail, Live) often shows connected apps under the Privacy area. Work or school accounts often use My Apps and Entra.
Personal Microsoft account (Outlook.com, Hotmail, Live)
- Sign in at account.microsoft.com.
- Open Privacy or Privacy dashboard (it may be in the top menu, or under your profile icon).
- Find a section named Apps and services or Third-party apps with account access.
- Select an app, then choose Remove these permissions or Revoke access.
As you review, treat these as higher risk in most cases:
- Mail access that can read, write, or send.
- Files access for OneDrive that allows broad reads.
- Any permission that implies long-running access (often paired with background sync features).
Work or school account (Microsoft 365 business)
If your sign-in is tied to an organization (Entra ID), the safest path is usually:
- Go to myapps.microsoft.com.
- Open My Apps or My account, then look for Manage your apps or Permissions.
- Remove apps you don’t use, and review what remains.
Small-business admins may also need the admin-side view for enterprise apps. Microsoft documents how permissions are granted and reviewed in Entra, see Review permissions for enterprise applications.
One more note: if you remove access but the app still has an active session on its side, sign out inside that app too. Token revocation is the key step, but you want both doors closed.
Safe list guidance (keep good apps, reduce scope)
You don’t need to remove everything. You want fewer connections, from reputable publishers, with the smallest scope that still works.
- Prefer apps that offer sign-in only (basic profile) instead of mailbox or file access.
- Keep vendors you can verify (clear company name, real support pages, a history of updates).
- If an app offers a choice, pick read-only over read-write, and avoid offline access unless you truly need background sync.
- Reconnect important apps after cleanup, but watch the consent screen carefully.
When to escalate (possible compromise)
Escalate beyond app cleanup if you see any of these:
- A connected app you never approved that has mail or file access.
- Password reset emails you didn’t request.
- New sign-in alerts from places or devices you don’t recognize.
- Mail rules or forwarding you didn’t set (a common way to siphon data).
At that point: change your password, confirm MFA is on, review recent sign-in activity, and consider contacting your provider or your organization’s admin. App removal is necessary, but it may not be enough.
Conclusion: Make connected apps reviews a small, steady habit
Connected apps are useful, but they shouldn’t be permanent. A quick review every few months keeps your accounts tidy and reduces silent data pulls. Spend 20 minutes, remove what you don’t trust, and keep a short list of apps that earn their access. Your future self will thank you the next time a random service asks for your inbox.

