TL;DR: Every AI tool someone connected to email, files, calendars, or offline access left an OAuth consent grant in your identity provider. You don't need a new product to see it. Pull the list from Entra, Google Workspace, Okta, or whatever you run, this week, for free. Most teams find more than they expected.
Key takeaways:
Every OAuth consent click creates a record in your identity provider, whether IT approved the tool or not.
This exact pattern showed up in three separate client walkthroughs between June and September 2026, most recently on a live call with a two-person security team at a therapeutics company.
Todd Inskeep, an IANS Faculty member, points to a client that counted 150 AI agents on its own list. CrowdStrike's services team found more than 500 actually running.
A 30 minute walkthrough in Microsoft Entra, Enterprise applications sorted by creation date, turns into a first AI agent registry, with no new purchase.
Okta's Cross App Access, with Anthropic as a launch client, is starting to replace the consent screen entirely for new AI connections.
What is an OAuth consent grant?
An OAuth consent grant is the record created the moment someone clicks "allow" to connect an AI tool to their email or their files. It lives in your identity provider, whether IT approved the tool or not. Microsoft Entra logs a person's own approval as an object called oAuth2PermissionGrant, and an app-to-app connection as an app role assignment. Either way, the click already got recorded somewhere you can read.
That consent click is the whole control event. Someone connects a note-taking AI to their calendar, or a writing assistant to their inbox, and the tool now runs with that person's own access, indefinitely, until somebody revokes it.
George Gerchow talks about three places shadow AI shows up: the endpoint, the browser, and identity. Most security teams watch the first two. An endpoint tool sees what's installed on the laptop. A browser extension sees an AI site open in a tab. Almost nobody checks the third one, and it's the one that's free to pull this week.
Why does this count for AI agent governance?
A desktop AI tool can reach whatever it's been approved to reach. That list grows every time someone clicks allow, and it grows quickly.
This exact pattern showed up in three separate client walkthroughs between June and September 2026. A global manufacturer needed the Microsoft Graph object model explained before its own team could read what they already had. A big-box retailer corrected a common assumption: identity logs only show apps connected through the identity provider. A tool that connects straight into a SaaS platform's own login screen leaves no trace there at all. A two-person security team at a therapeutics company ran the full point-and-click version live on a single call, no scripting, no budget.
Three industries, same finding every time. The screen with the answer had been sitting open the whole time.
The scale problem is real too. Todd Inskeep, an IANS Faculty member, said in a June 2026 poll that CrowdStrike's services team has never found a company with an accurate AI inventory. One client counted 150 agents on its own list. CrowdStrike found more than 500 actually running. That's the difference between what a team thinks it governs and what's actually connected.
How do you audit OAuth grants in Microsoft Entra?
Four steps, about 30 minutes, one person, no scripting required.
First, open the Entra admin center and go to Enterprise applications, All applications. Every tool anyone in the company has ever clicked "allow" for shows up as a row, including the consumer ones like a popular AI chat app or a meeting note-taker.
Second, change the filter from the default, which hides Microsoft's own apps, to Application type equals Enterprise Applications. Sort by created date. The newest rows are your discovery list.
Third, open a tool you don't recognize and click Permissions. Look at the user consent tab. That tells you who approved it and what it can reach: mail, files, calendar, or offline access, plus whether it's read-only or can also write and send. Anything with broad write access goes to the top of the list.
Fourth, export the list. Add one column: owner. That sheet is your registry, version one.
Microsoft's own guide to reviewing these permissions walks through the admin center version, Entra PowerShell, Graph PowerShell, and the raw Graph API calls, for whichever one your team can run.
What about Google Workspace and Okta?
The same record exists in every identity provider. The screen just has a different name.
In Google Workspace, it's under Admin console, Security, API controls. Each connected app shows its user count and which Google scopes it touched: Gmail, Calendar, Drive, or something outside Google's own apps, listed as Other. Watch for domain-wide delegation separately. That's a higher-risk category, because those apps can act as any user in the company, not just the person who approved them.
Okta works differently. Most access there gets provisioned by an admin rather than clicked through by a user, so the silent-consent surface is smaller. The System Log's token grant events show which app made calls on behalf of which person, which does the same job.
What should you do the same afternoon?
Close the front door before you start pruning.
In Entra, go to User consent settings and change the default from "allow anyone to consent to anything" to verified publishers only, or admin consent only. Turn on the admin consent workflow so a new request routes to a named reviewer instead of getting silently approved.
Then revoke the grants that fail an honest look. Tell the person first. A controlled path lets them ask for it back after review, which turns a blunt prune into a real filter and tells you who actually depended on what.
One more thing worth saying plainly: a consent policy stops new grants from piling up. It does nothing about an app that was already approved and starts behaving badly later. Watching for that is a separate, ongoing job, usually owned by whoever administers that specific SaaS platform, checked on a monthly or quarterly cadence once the initial cleanup is done.
None of this requires a platform decision or a budget request. It's the same discipline behind assigning one accountable human to every agent: a name next to every grant, not just a switch that's on.
Where is this heading?
Toward removing the consent screen altogether.
Enterprise-Managed Authorization moves the approval decision from an individual's click to a policy your identity provider enforces up front. Okta shipped the first version, called Cross App Access, and Anthropic is a launch client on the connecting side. A user logs in once, and the policy decides which AI tools they can reach, with no consent screen and one place to revoke access.
That's the direction worth planning for. It doesn't replace the work above. Checking what you already own before buying a new security tool still applies here: do the consent lockdown with what you have now, and put policy-based provisioning on next year's roadmap.
Frequently asked questions
Do I need to buy a new tool to find shadow AI this way?
No. Every identity provider already logs this. Microsoft Entra, Google Workspace, and Okta all show connected apps and their permissions in an admin screen you already have access to. A dedicated discovery product adds risk scoring and automation, but the base inventory is free.
What's the difference between a delegated permission and an app permission?
A delegated permission is what a person approved for themselves. An app permission, also called an app role assignment, is a daemon-style connection that runs on its own, not tied to one person's click. Both show up on the same Enterprise Applications screen in Entra, under different tabs.
Will revoking a grant break something for the employee?
It can, so tell them before you revoke it. Publish the approved path first, prune what fails the sniff test second, and let people ask for a re-review if they actually needed the tool. That sequence turns a blunt cutoff into a real filter.
Does this catch every AI tool in the company?
No. It only catches tools connected through your identity provider. A tool signed up with a personal email and password, used only in a browser, leaves no trail here at all. That population needs network and expense-record discovery, a separate project.
Is this a replacement for a full AI governance program?
No. It's the fastest, cheapest first step: know what's already connected before you write a policy about it. A blast radius only gets smaller once someone measures it, and this list is where that measuring starts.
The screen with the answer on it has been open the whole time. Somebody on your team just has to look at it.
