← Back to blog Cybersecurity

OAuth apps and browser extensions: how to audit who has access to the Google Workspace or Microsoft 365 of your Mexico operation

3 min read

On September 14, 2026, two stories landed on the same gap. BleepingComputer announced a webinar on how malicious OAuth apps end up causing Google Workspace breaches. And The Hacker News reported a Twitch browser extension that leaked OAuth tokens from nearly 31,000 users.

If you run a plant, a warehouse or a sales office in Mexico from abroad, this one matters more than usual. Consent settings are tenant-wide. Whatever someone in Querétaro clicked Allow on last year is still connected to the same tenant your CFO uses.

~31,000 users had OAuth tokens leaked by a single browser extension
2 stories on the same day, September 14, 2026, about the same risk

What an OAuth grant is and why you never see it

A key that does not expire An OAuth token lets an app read your mail or files without asking for the password again. Until someone revokes it, it stays open.

OAuth is what sits behind Sign in with Google or Connect with Microsoft. The app asks for permissions, such as reading mail, listing Drive files or posting in Teams. The user says yes, and the app gets a token. Think of it as a spare key: it opens the door on its own.

That is the problem. Resetting the password does not cut that key. Turning on MFA does not either. Only revoking the grant does.

In our experience, the first time we open the third-party app list of a company with staff in Mexico, dozens of apps show up that nobody at headquarters approved. A PDF converter installed by the receptionist, a meeting assistant the plant manager tried once, a signature plugin from a vendor who is no longer around.

Where the list lives

PlatformWhere to lookWhat to check
Google WorkspaceAdmin console › Security › API controls › Manage third-party app accessApps with Gmail, Drive or Calendar scopes and how many users granted them
Microsoft 365Entra ID › Enterprise applications, plus each user › ApplicationsPermissions like Mail.Read or Files.ReadWrite and apps with generic names
BothInstalled extensions in managed Chrome and EdgeExtensions with access to all sites or the clipboard

Write down three things per app: who granted it, what it can do and when it was last used. If nobody in Mexico or at HQ knows what it is for, that is your answer.

Clean up today, change the rule for tomorrow Remove what nobody recognizes, then make new grants go through an approval instead of a single click.

Revoking is one button. In Google, the same third-party apps screen lets you mark an app as blocked and every token goes dead. In Microsoft, you remove the user consent on the enterprise application or delete the app entirely.

Restricting consent is what actually changes the game. In Google you can decide that only admin-approved apps reach sensitive data. In Entra ID, under user consent settings, you choose that employees cannot authorize apps on their own and that requests land with your admin. That way an Allow click in Monterrey stops being a decision made alone at a desk.

Browser extensions: the side door

An allowlist, not a blocklist An extension policy pushed from Google Admin or Intune lets only approved extensions in. Everything else never installs.

The Twitch case says it all. The extension did not attack Google or Microsoft. It attacked the browser where the user was already logged in. An extension allowed to read every page can copy tokens, cookies and forms.

Chrome and Edge accept an extension policy from the Google Admin console or from Intune: an allowlist, everything else blocked. It is one afternoon of work and, in our opinion, one of the best effort-to-result controls you can apply to a remote site.

Warning signs in a Mexico operation

What gives a rogue app away Forwarding rules nobody created, write permissions nobody needed and app sign-ins from countries where you have no staff.
  • Mail forwarding rules nobody created.
  • An app with write access to Drive or SharePoint that only needed to read.
  • App sign-ins from a country where you have no staff.
  • One user with five apps that do the same thing.

This audit complements what we covered on passkey phishing in Microsoft 365 and on fake IT support calls asking for remote access. Those pieces protect the front door. This one checks who already has a copy of the key.

ProcessBi technician reviewing tenant access
Tell us about your tenant — we reply the same business day Foto: Pexels

And in your Mexico operation?

If nobody has opened that list since the site started, open it this week. It takes half an hour and something almost always shows up.

At ProcessBi the tenant review is part of the plan: connected apps, extensions, forwarding rules and consent settings, with a report in English of what we removed and why. Remote, in your time zone, with invoicing in MXN or USD.

Request your access review — we reply the same business day.

Your path

Running IT in Mexico from abroad

9 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Deepfakes and CEO fraud in Mexico: how to protect your local operation from cloned voice and video scams