B5High4 groups
Third-party apps with write access to the directory
Four applications can change directory objects without any approval step. Consent was granted once, by one person, and it does not expire.
Evidence
| Application | Permission | Consented by | Consented | Last used |
|---|---|---|---|---|
| HR Sync Connector | User.ReadWrite.All | adm.jsandvik@vestholm.no | 09 Jan 2024 | 20 Aug 2026 |
| Printer Fleet Manager | Device.ReadWrite.All | adm.kfloen@vestholm.no | 22 May 2024 | 17 Aug 2026 |
| Legacy Intranet | Group.ReadWrite.All | adm.legacy@vestholm.no | 03 Oct 2022 | — |
| Onboarding Forms | User.ReadWrite.All | adm.jsandvik@vestholm.no | 14 Feb 2025 | 12 Aug 2026 |
After upgrading, Entra Logic appears in this list. That is correct, and it is the point: write access moves from people to one service that can only do what an approved order asks for. The full permission list is on the security page.
How this was derived
servicePrincipal.appRoleAssignments contains '*.ReadWrite.All' AND servicePrincipal.tags != 'internal'
- Service principals read
- 144
- Holding write permissions
- 4
If closed
+2 points1 unused consent revoked3 consents documented with an owner
Fix
Revoke the consent nothing has used since 2022, and record a named owner and a review date against the three that remain.
requires write access
Related findings