Four times in the last twelve months, attackers walked into large companies' Salesforce, Google Workspace and Microsoft 365 data without touching a password or an MFA prompt. They used OAuth tokens a third-party app was holding, Salesloft's Drift AI chat agent in August 2025, Gainsight in November, Context.ai's abandoned AI office suite in April 2026, and, as reported by Nudge Security, Klue in June. Salesforce's own advisory on the Gainsight case says the quiet part: the incident "was not the result of a vulnerability in the Salesforce platform itself." The platform did exactly what the consent screen said it would, months or years earlier.
AI apps make this worse for a structural reason: they ask for broad scopes (read all your mail, all your files) because that is what makes them useful, employees grant them in a hurry, and nobody revokes them. Material Security's June 2026 study of 22,332 OAuth apps across 21 Google Workspace environments found that 91% of the AI and automation apps had first appeared since January 2024, that 47% of all apps had not been used in 90 days, and that 1,064 apps still held live tokens for users who had left the company. This is the audit that finds your version of those numbers. Every command and path below is taken from Microsoft's and Google's current documentation.
Step 1 — Inventory every grant
Microsoft 365 / Entra ID
Delegated grants (what users consented to) live in oauth2PermissionGrants; application permissions (what admins granted to the app itself) live in appRoleAssignments. Pull both.