Because these permissions can provide access to University data, UWSP reviews and manages application access to help protect institutional information and reduce security risk.
What Is an OAuth Application?
An OAuth application is any application or service that allows you to sign in using your UWSP Microsoft 365 account.
Examples include:
- Productivity and collaboration tools
- Scheduling and calendar applications
- Research and educational platforms
- File management or document editing tools
- Other software and cloud services that offer "Sign in with Microsoft"
When you sign in, the application may request permission to access certain information from your UWSP account.
Why OAuth Permissions Matter
Unlike a traditional password, OAuth permissions can allow an application to continue accessing approved Microsoft 365 data without storing or knowing your password.
Depending on the permissions granted, an application may be able to:
- View or manage your calendar
- Access email messages
- Read or modify files stored in OneDrive or SharePoint
- Access basic profile information
- Perform other actions on your behalf
For this reason, applications requesting access to University data are carefully reviewed to ensure that access is appropriate and limited to what is necessary.
How UWSP Reviews Application Access
UWSP uses Microsoft Entra ID controls to help protect University information.
In many cases:
- Applications published by a Microsoft-verified publisher and requesting only low-risk permissions may be eligible for user self-consent under UWSP security policies.
- Applications requesting higher-risk permissions may require administrator review and approval.
- Applications that have not been verified by Microsoft may also require additional review before they can be used with UWSP accounts.
- If administrator approval is required, users will be prompted to submit a request rather than granting access directly.
This review process helps ensure that applications requesting access to University data are evaluated for security, privacy, and institutional risk before access is granted.
Un-Vetted Applications
An un-vetted application is an application that has not completed UWSP's review process for security, privacy, and data protection considerations.
Student Access
Certain un-vetted applications may be approved for student use when appropriate safeguards can be applied.
These applications may be permitted to request:
- Basic sign-in and profile permissions required for application functionality
- Calendar access
- Email access
Approval is limited to situations where the associated risk is acceptable and access can be appropriately restricted.
Faculty and Staff Access
For faculty and staff, un-vetted applications are generally limited to:
- Basic sign-in and profile permissions required for authentication and normal application functionality
Applications requesting access to email, calendars, files, or other institutional data will typically require additional review before approval.
Vetted Applications
A vetted application has undergone review by UWSP Information Technology and Information Security.
The review may consider:
- Business or academic need
- Vendor reputation
- Security controls
- Privacy and data handling practices
- Compliance requirements
- The permissions requested by the application
When justified by the application's purpose, vetted applications may be approved for permissions such as:
- Calendar access
- Email access
- File access
Permissions are granted according to the principle of least privilege and only when required for the application to function.
Why Some Applications Require Approval
Not all Microsoft 365 permissions present the same level of risk.
Applications requesting access to content such as email, calendars, files, Teams data, or other institutional information may require additional review before they can be connected to UWSP accounts.
During the review process, UWSP may evaluate:
- Whether the application is necessary for academic, research, or business purposes
- Whether the requested permissions are appropriate
- Whether the vendor follows acceptable security and privacy practices
- Whether the application has been verified by Microsoft
- Whether the requested access follows the principle of least privilege
Applications that do not meet UWSP security requirements may be denied or approved with reduced permissions.
Ongoing Review of Approved Applications
Application approval is not necessarily permanent.
To help protect University data, UWSP periodically reviews applications that have been granted access to Microsoft 365 resources.
As part of this process:
- Previously approved applications may be re-evaluated.
- Applications requesting excessive permissions may be reviewed.
- Permissions may be reduced if they are no longer necessary.
- Access may be removed when security risks, excessive permissions, or changes in vendor practices create unacceptable risk to University data.
These reviews help ensure that applications continue to meet UWSP's security and data protection requirements.
Best Practices
When using applications connected to your UWSP account:
- Use approved and vetted applications whenever possible.
- Review permission requests when they are presented.
- If an application requires administrator approval, provide a clear business or academic justification when submitting your request.
- Request only applications that are necessary for your work, research, or coursework.
- Remove applications you no longer use.
- Report suspicious or unexpected application requests to Information Technology.
- Contact IT if you are unsure whether an application is appropriate for University use.
Need Assistance?
If you have questions about application approvals, OAuth permissions, or requests for access to third-party applications, contact the IT Service Desk for assistance.
Third-party applications often use Microsoft 365 OAuth permissions to access University data such as email, calendars, files, and user profile information. While these applications can improve productivity, granting excessive permissions may expose UWSP data to unauthorized access.