Lost in Permissions: Exploring the Microsoft 365 App Ecosystem

📅 2026-08-03
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses pervasive issues of excessive permission grants and insufficient transparency among third-party applications in the Microsoft 365 (M365) ecosystem, which pose significant risks to enterprise data security. It presents the first systematic security and privacy measurement of the M365 app landscape, analyzing over 8,000 applications through a novel framework that integrates neural topic modeling and unsupervised anomaly detection to assess alignment between declared functionalities and requested permissions. Leveraging large language models to interpret anomalous cases, the research identifies only 1,069 apps that publicly disclose both functional descriptions and permission details, uncovering widespread violations of the principle of least privilege—particularly through overly broad tenant-scoped authorizations. The work delivers actionable risk insights for administrators and introduces the first methodology combining topic modeling with anomaly detection for evaluating permission reasonableness, offering both methodological innovation and practical utility.
📝 Abstract
The Microsoft 365 (M365) ecosystem hosts thousands of third-party applications that integrate with enterprise tenants via fine-grained OAuth permissions, potentially granting access to sensitive organisational resources such as emails, files, calendars, chats, and user directories. Despite the security implications of these permission grants, the M365 ecosystem has not been systematically studied. We present the first privacy- and security-oriented measurement of M365 third-party applications. By combining public marketplace APIs with automated tenant-side deployment, we crawl over 8,000 applications. We find that only 1,069 of them expose both descriptions and permission sets, with significant inconsistencies in transparency across official distribution channels. Next, we leverage a topic-aware anomaly detection framework to assess whether requested permissions align with declared functionality. We cluster applications via Neural Topic Modelling and apply unsupervised anomaly detection within each topic to identify deviations from peer permission profiles. LLM-assisted analysis of the most anomalous cases and blind manual inspection reveal a correlation between anomalous permission profiles and the risk associated with the requested permissions. We find that many applications request overly broad tenant-wide scopes (e.g., directory-wide read/write access), violating least-privilege principles and increasing the organisational attack surface. Our pipeline provides tenant administrators with actionable insights by identifying anomalous applications and the permissions that most contribute to their anomalousness. Overall, our findings expose systemic opacity and structural immaturity in the M365 app ecosystem, where permission disclosure is inconsistent and over-privileged access is common.
Problem

Research questions and friction points this paper is trying to address.

Microsoft 365
third-party applications
OAuth permissions
over-privileged access
security and privacy
Innovation

Methods, ideas, or system contributions that make the work stand out.

OAuth permissions
anomaly detection
Neural Topic Modelling
least-privilege violation
third-party app ecosystem
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
V
Vincenzo Longo
Politecnico di Torino, Italy
A
Alberto Verna
Politecnico di Torino, Italy
N
Nikhil Jha
Politecnico di Torino, Italy
Marco Mellia
Marco Mellia
Politecnico di Torino, italy
Computer networksMachine LearningCybersecurityData Science