OAuth apps and browser extensions: how to audit who has access to the Google Workspace or Microsoft 365 of your Mexico operation
On September 14, 2026, two stories landed on the same gap. BleepingComputer announced a webinar on how malicious OAuth apps end up causing Google Workspace breaches. And The Hacker News reported a Twitch browser extension that leaked OAuth tokens from nearly 31,000 users.
If you run a plant, a warehouse or a sales office in Mexico from abroad, this one matters more than usual. Consent settings are tenant-wide. Whatever someone in Querétaro clicked Allow on last year is still connected to the same tenant your CFO uses.
What an OAuth grant is and why you never see it
OAuth is what sits behind Sign in with Google or Connect with Microsoft. The app asks for permissions, such as reading mail, listing Drive files or posting in Teams. The user says yes, and the app gets a token. Think of it as a spare key: it opens the door on its own.
That is the problem. Resetting the password does not cut that key. Turning on MFA does not either. Only revoking the grant does.
In our experience, the first time we open the third-party app list of a company with staff in Mexico, dozens of apps show up that nobody at headquarters approved. A PDF converter installed by the receptionist, a meeting assistant the plant manager tried once, a signature plugin from a vendor who is no longer around.
Where the list lives
| Platform | Where to look | What to check |
|---|---|---|
| Google Workspace | Admin console › Security › API controls › Manage third-party app access | Apps with Gmail, Drive or Calendar scopes and how many users granted them |
| Microsoft 365 | Entra ID › Enterprise applications, plus each user › Applications | Permissions like Mail.Read or Files.ReadWrite and apps with generic names |
| Both | Installed extensions in managed Chrome and Edge | Extensions with access to all sites or the clipboard |
Write down three things per app: who granted it, what it can do and when it was last used. If nobody in Mexico or at HQ knows what it is for, that is your answer.
Revoke first, then restrict consent
Revoking is one button. In Google, the same third-party apps screen lets you mark an app as blocked and every token goes dead. In Microsoft, you remove the user consent on the enterprise application or delete the app entirely.
Restricting consent is what actually changes the game. In Google you can decide that only admin-approved apps reach sensitive data. In Entra ID, under user consent settings, you choose that employees cannot authorize apps on their own and that requests land with your admin. That way an Allow click in Monterrey stops being a decision made alone at a desk.
Browser extensions: the side door
The Twitch case says it all. The extension did not attack Google or Microsoft. It attacked the browser where the user was already logged in. An extension allowed to read every page can copy tokens, cookies and forms.
Chrome and Edge accept an extension policy from the Google Admin console or from Intune: an allowlist, everything else blocked. It is one afternoon of work and, in our opinion, one of the best effort-to-result controls you can apply to a remote site.
Warning signs in a Mexico operation
- Mail forwarding rules nobody created.
- An app with write access to Drive or SharePoint that only needed to read.
- App sign-ins from a country where you have no staff.
- One user with five apps that do the same thing.
This audit complements what we covered on passkey phishing in Microsoft 365 and on fake IT support calls asking for remote access. Those pieces protect the front door. This one checks who already has a copy of the key.
And in your Mexico operation?
If nobody has opened that list since the site started, open it this week. It takes half an hour and something almost always shows up.
At ProcessBi the tenant review is part of the plan: connected apps, extensions, forwarding rules and consent settings, with a report in English of what we removed and why. Remote, in your time zone, with invoicing in MXN or USD.
Request your access review — we reply the same business day.
Your path
Running IT in Mexico from abroad
9 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →