How to Keep Up With Risky OAuth Grants as They Accumulate

· Original article ↗

Summary

OAuth grants can persist outside SSO and remain usable after employees leave. This sponsored article describes Nudge Security’s tools for inventorying and assessing grants, with security teams reviewing recommendations before remediation.

Key points

  • OAuth grants are separate from SSO and MFA, can remain valid while dormant, and may persist after an employee account is disabled.
  • The article says the Vercel breach began with a compromised OAuth token from Context.ai, which an employee had connected to enterprise Google Workspace months earlier.
  • Nudge Security cites an average of 88 OAuth grants per employee, including 31 with data-level permissions; these figures are attributed to the company.
  • The article estimates a thorough manual review can take 45 minutes per grant, while Nudge says its risk analyst agent can return a verdict in 15 seconds.
  • Nudge’s product inventories grants and permissions, assesses risks such as excessive scopes and broad access, and recommends whether to permit, justify, or revoke a grant.
  • Security teams review and authorize actions; the product also supports grantor justification requests, alerts, and revocation of risky or unused grants.

Article Details

Defense Focus
Discover, assess, and govern OAuth grants and app-to-app access to corporate data, including dormant grants and access that persists outside user authentication controls.
Detection Methods
  • Nudge Security claims to inventory existing and new OAuth grants without relying on activity logs, including dormant grants and identity-only integrations.
  • Inventory API keys, service accounts, and remote MCP server connections alongside OAuth grants to identify programmatic access to corporate data.
  • Classify and risk-score integrations using permission scopes, vendor security posture, grantor characteristics, organizational usage, and the sensitivity of accessible data.
  • Flag excessive permissions, suspicious domains, apps commonly used for data exfiltration, and connections with unusually broad and persistent access to email, files, or code repositories.
  • Compare granted scopes with those typical for the integration and with organizational data-sharing policy.
  • Assess the grantor's role, delegated administrative rights, user metadata, business need, and MFA status.
  • Review vendor security and compliance programs and recent breach history.
  • The advertised analyst agent evaluates new grants using discovery context and vendor security profiles, returning Permit, Justify, or Revoke recommendations with reasoning and evidence gaps.
  • Alert on new OAuth activity and identify risky or unused grants for revocation.
Data Sources
  • OAuth grant inventory, including receiving apps and vendors, grantors, permissions, scopes, and reachable corporate applications and data
  • Browser discovery context
  • Inbox discovery context
  • Identity provider context
  • Connected application context
  • Grantor roles, user metadata, and MFA status
  • Organizational application usage
  • Vendor security profiles, compliance information, and breach history
  • API key, service account, and remote MCP server connection inventories
  • Grantor justification responses
  • Audit records of authorized governance actions
Defensive Actions
  • Maintain a dedicated OAuth grant lifecycle and access-review process rather than assuming SSO, MFA, or account disabling covers all grants.
  • Inventory grants created before deployment as well as newly created grants.
  • Review high-risk grants against business need, expected permissions, and data-sharing policy.
  • Require security-team review of agent recommendations and supporting evidence before authorizing changes in the described agent workflow.
  • Request justification directly from grantors and capture their responses.
  • Revoke grants when their risk outweighs their business value.
  • Configure automatic revocation for risky or unused grants, including during employee offboarding.
  • Maintain auditable records of governance actions, including what changed, when, and why.

MITRE ATT&CK

Vendors

Products

Related Articles