How to Audit Apps Connected to Your Online Accounts

A scheduling tool you tried once may still have permission to read your calendar. A document utility may remain connected to your cloud storage long after you uninstall it. An old social publishing service may still be able to post on your behalf.
Connected apps are easy to approve and easy to forget. Reviewing them means opening each important account's connection settings, checking what every app can do, and removing access that no longer serves a purpose. Before removing a sign-in connection, confirm how you will get back into any service you intend to keep.
This is a useful maintenance task even when nothing appears wrong. You are reducing the number of companies and tools that can reach your information, and making the connections you retain easier to understand.
Understand Which Kind of Connection You Have
An app connection can serve several different purposes. Do not assume that every entry grants the same access.
A sign-in connection lets another service use your existing account to identify you. A data-access connection gives an app permission to read or change particular information. Some apps have both, and a provider may display them separately.
For example, signing into a service with your Google account is different from allowing that service to read files in Google Drive. Removing the sign-in link and revoking file access are separate decisions. Review every connection type listed for the app.
Also distinguish account permissions from software installed on your device. Deleting a phone app or browser extension does not establish that its cloud connection has been revoked. Check the account itself. If you are cleaning up browser software too, follow the separate process for auditing browser extensions.
Start With Accounts That Hold Important Data
You do not need a perfect inventory of every account before making progress. Begin with primary email, cloud storage, calendars, work collaboration tools, and any account that manages a public profile or business service.
Open each provider through its known website or official app. Look in account settings for connected apps, linked apps, integrations, authorized applications, or third-party access. Labels vary, so use the provider's own help if you cannot find the relevant section.
Check which identity is selected. Personal and work accounts may use similar names, and different browser profiles may sign you into different accounts. Repeat the review for each identity that holds information you care about.
Create a short inventory containing:
- The account being accessed.
- The app and its publisher.
- The permissions shown.
- The task the connection supports.
- Your decision: keep, investigate, or remove.
Record descriptions rather than credentials. An audit note does not need passwords, access tokens, recovery codes, or copies of private documents.
Translate Permissions Into Real Consequences
Open the details for each connection. The important question is what the app can actually do, rather than whether its name sounds familiar.
Read-only access still matters. An app that can read a calendar may learn about appointments, attendees, and meeting locations. Reading files may expose private documents. Access to contacts can reveal relationships even if the app cannot edit the address book.
Write permissions add another concern. Depending on the grant, an app might create events, modify files, send messages, or publish content. Consider what an accidental action or a compromised app could do with those permissions.

Compare access with the job you actually use. A tool that adds appointments may reasonably need calendar permissions. That does not explain a request to manage all your files. If the provider offers a narrower grant, such as selected resources rather than an entire account, consider whether it supports your workflow.
Avoid declaring an app safe solely because it is popular or has a polished permission screen. You are deciding whether this publisher needs this access to this account. Broader cloud storage security practices still matter for the information exposed through those connections.
Make a Decision for Every Entry
Keep connections with a clear current purpose, a publisher you recognize, and permissions appropriate to the task. Record what depends on them so the next review is easier.
Remove abandoned trials, duplicate tools, and integrations for projects that have ended. If you no longer use the service, leaving its access in place provides little benefit.
Investigate unfamiliar entries. A publisher name may differ from the product name, so unfamiliar does not automatically mean malicious. Compare it with the service's own account settings and documentation. Do not approve fresh permissions just to identify an old connection.
For a shared work account, ask the responsible colleague or administrator before removing a connection that might run an important process. Set a decision date for uncertain entries rather than leaving them indefinitely. If an app appears suspicious or unauthorized, contact your security team promptly instead of treating it as routine housekeeping.
Protect Your Sign-In Route Before Disconnecting
Before removing a sign-in connection from a service you still need, check its supported login methods. You may be using that connection as your only way in.
If the service allows another method, configure and verify it first. Test the alternative in a separate private browser window while retaining your existing session. Confirm that it opens the same account with the expected files, purchases, or settings. Creating an accidental second account is not a successful migration.
If there is no supported alternative, consult the service's official recovery or support process before removing the link. Do not assume a password reset will always convert a federated account into a password-based account.
Check that your primary account's recovery methods are current too. The guide to storing account recovery codes safely can help you avoid relying entirely on one device during account maintenance.
Revoke Access Through the Provider
Use the account provider's permission controls to remove the connection. Signing out of the app, hiding it from a launcher, and uninstalling it are different actions.
For Google accounts, the linked-apps area separates sign-in links from access to account data. Open the app's details and remove the relevant connection. Check for other connection types belonging to the same app before considering the review finished.
For Microsoft work or school accounts, the My Apps portal provides application management controls. You can review permissions you granted and revoke them where available. Permissions granted by an administrator require the administrator's involvement.
Read the confirmation carefully, complete the removal, then refresh the connection list. Confirm that the grant you intended to remove is gone. If you deliberately retain a sign-in link while removing data access, record that distinction.

Check any workflow that depended on the connection. A calendar sync, automated export, or scheduled publishing task may stop working. If a tool asks to reconnect, review the request again rather than restoring the old permissions reflexively.
Handle Stored Data and Subscriptions Separately
Revoking access is a boundary for account access. It is not proof that information already copied into the other service has been erased.
Visit the app's own account settings if you also want to remove stored files, close the account, or request deletion. Review its stated data-retention process. Export anything you need before closing a legitimate account, and keep the confirmation of any deletion request.
Subscription cancellation is another separate task. Disconnecting an account should not be treated as confirmation that billing has stopped. Check the billing controls for the service or the store through which you subscribed.
Where a work integration handled customer or employee information, involve the person responsible for that data. They may need to coordinate retention requirements, replacement workflows, or supplier offboarding.
Escalate Signs of Unauthorized Access
An unused connection is a maintenance finding. An app you did not authorize, unexplained outgoing messages, or unexpected account changes may indicate an incident.
Record the app name and permissions, revoke suspicious access when appropriate, and review account activity through the provider. For a work account, follow your organization's incident process. Avoid collecting or circulating sensitive account data unnecessarily.
Do not assume removing one connection completes recovery. If your inbox may have been compromised, follow the broader guide on what to do if your email account is hacked, including checking other ways an attacker might retain access.
Keep Future Reviews Small
Repeat the audit after retiring a tool, finishing a project, changing roles, or receiving an unexpected permission request. A periodic calendar reminder can catch connections that would otherwise disappear from memory.
Before approving a new app, identify the task it serves and read the requested access. Decline optional permissions you do not need when the service allows that choice. Keep work integrations owned by a named person who can explain and maintain them.
Start today with one important account. Review every connected app, remove the access you no longer need, and document the few connections worth keeping. A short, current list is easier to protect than years of forgotten approvals.