Article summary: Every time someone clicks "Sign in with Google" to skip a new password, that app quietly keeps a standing connection to company email, files, or calendar data. Most small businesses never review these connections, so they pile up long after an employee leaves or a free trial ends. A short, repeatable audit process closes off this orphaned OAuth access before it becomes an entry point for an attacker.

“Sign in with Google” saves you from creating another password. A few clicks later, a new app has access to your account, and most people never think about that connection again.

‍

Multiply that across every employee who has tried a scheduling tool, PDF converter, AI app, or other online service over the past few years, and a small business can accumulate dozens of third-party connections nobody is actively tracking.

‍

Those forgotten connections can become orphaned OAuth access: apps that retain permissions long after the employee has stopped using them or the business has forgotten they were approved.

‍

A regular audit of third-party access helps uncover those lingering connections before they become an overlooked path into your Google Workspace or Microsoft 365 environment.

What "Sign In With Google" Actually Grants

“Sign in with Google” uses OAuth 2.0 and OpenID Connect to let an app verify a user's identity and, when requested, gain permission to access certain Google account data without getting the user's password.

‍

Those permissions can vary widely. Some apps only request basic profile information, while others may ask to read Gmail, access Drive files, or work with a user's calendar.

‍

The initial access token is typically short-lived, but some apps can receive a refresh token that allows them to obtain new access tokens without the user being present. That access can persist until the authorization expires, is revoked, or is otherwise invalidated.

‍

The scale of those lingering connections can be surprising. Material Security's 2026 OAuth Risk Report found as many as 13,768 OAuth grants in a single Google Workspace environment.

Across the environments analyzed, 47.2% of grants had not been used in at least 90 days, while nearly a quarter reached restricted APIs. A small business may have fewer connections, but the same problem applies: third-party access can accumulate quietly unless someone regularly reviews it.

Why Orphaned Access Piles Up in Small Businesses

Small teams rarely have someone dedicated to reviewing third-party app access. Employees connect tools when they need them, and those permissions are easy to forget once the immediate job is done.

Offboarding has to include connected apps

Disabling a Google Workspace account is important, but offboarding should also include reviewing third-party services tied to that identity. Admins can review and control third-party app access through Google Workspace.

One-time tools can linger

A scheduling app tried for one project or a resume tool used during a hiring push may be forgotten as soon as the job is done. But abandoning the app does not necessarily remove the access previously granted to it.

Someone has to own the review

Without a named owner, old app connections become another forgotten IT task. Google lets users review and remove third-party connections, but someone still has to make that review happen.

‍

Researchers have also documented OAuth-related scenarios where former employees retained access to connected services after an organization believed that access was gone.

Running the "Sign in with Google" Audit

A useful audit does not require new software. Google Workspace already provides the tools admins need to review and control third-party access.

1.    Pull the full list. In the Admin console, open Security, API controls, and Manage App Access.

2.  Start with higher-risk access.  Prioritize apps requesting access to Gmail, Drive, Calendar, or other sensitive business data.

3.    Match each app to a person and purpose. If nobody knows why an app needs access, investigate it before allowing that connection to continue.

4.     Check who is using each app. Google shows which users have accessed an app, making it easier to spot connections that no longer belong.

5.    Control future access. Admins can mark apps Trusted, Limited, Specific Google data, or Blocked to control what they can access.

A one-time cleanup is not enough. Put the audit on the calendar so forgotten connections do not start piling up again.

Turning offboarding into a real checkpoint

Employee departures are a natural time to review connected apps. Pair the check with a broader review of vendor and account access so third-party connections do not slip through the cracks.

What to Do When You Find Something You Cannot Explain

An unfamiliar app is not automatically malicious. It may simply be something an employee tried once and forgot about. But an app with broad Gmail or Drive access and no clear owner deserves a closer look before it remains connected.

‍

If you remove an app's access, it can no longer access your Google Account, but that does not erase data it has already collected. Document what you remove and why so the next audit is faster.

Ready to Close the Gaps in Your Google Account?

OAuth access is easy to grant and even easier to forget. A regular review helps make sure the apps connected to your business accounts still have a legitimate reason to be there.

‍

Vudu Consulting can help you review third-party access across Google Workspace or Microsoft 365, identify connections that no longer belong, and put a process in place to keep permissions under control.

‍

Contact Vudu Consulting or email us at contact@vuduconsulting.com to get a clearer picture of who and what has access to your business data.

Article FAQs

What is OAuth, and why does "Sign in with Google" use it?

OAuth is a standard that lets users grant an app permission to access certain account data without giving the app their Google password.

Does disabling an employee's account also remove their connected apps?

Not necessarily. Disabling the employee's account is an important first step, but offboarding should also include reviewing third-party apps and services connected to that employee's work identity so lingering access does not get overlooked.

How often should a small business run an OAuth audit?

Quarterly is a practical starting point for many small businesses. It is also worth reviewing third-party access whenever an employee leaves or when the business stops using a connected application.

‍

Start making IT magic

Schedule a Call