Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Blog

OAuth audit: Google vs Microsoft vs Okta

IdP comparison for third-party grant visibility. Entra labelled Beta/Roadmap.

Three admin consoles, one estate (on paper)

Post-M&A companies run Google and Okta and Entra and then tell the auditor they have "an identity program." Third-party OAuth lives in different blades with different nouns. A Google-only export is not the estate. An Okta-only export misses everyone who clicked Allow on accounts.google.com. Entra's enterprise gallery is not the same object as a Graph-consent grant.

This is a field comparison for operators, plus what ScopeMantle actually connects today. Honest Beta label on Microsoft Entra. Deep Google how-to: Workspace audit guide.

Google Workspace

Where. Security, Access and data control, API controls, Manage third-party app access.

Strength. You can see user-consent apps, client IDs, scopes, user counts. You can trust/limit/block. Chrome policy is a sibling control for extensions.

Weakness. No composite score, no attestation workflow, no Okta join. User-level detail is clicky. Reports API scripts 429. Authorize logs are not cumulative state.

ScopeMantle Google connector is GA.

Microsoft Entra

Strength. Enterprise app gallery and SSO assignments are mature for the apps you intended to provision.

Weakness. Third-party access to Microsoft Graph is split across blades. Many tenants I have seen do not have a single "here are all user-consent grants with scopes" export that a Google admin would recognize. Inventory is immature compared to Workspace's Apps with access list. That is why our connector is Beta, not a quiet GA.

If you are Entra-heavy, manual-export what you can and disclose incompleteness in the CC9.2 narrative. Do not let a seller (including us, on a bad day) talk as if Graph consent were fully solved.

Okta

Strength. When Okta is the authorization server, the OAuth client registry is a real object. API access is good. Assignments vs consents can be distinguished if you bother.

Weakness. Okta does not see Google-native grants. Users bypass Okta for SaaS all day. An Okta-only program in a Google mail shop is a comforting lie.

ScopeMantle Okta connector is GA.

Side-by-side

GoogleEntraOkta
User-consent OAuth listStrongSplit / immatureStrong if Okta is the AS
SSO gallery appsDifferent featureStrongStrong
Sees the other IdP's grantsNoNoNo
ScopeMantle connectorGABetaGA

Unified inventory

Normalize on client ID and owner email. Score once. Attest once. Revoke per IdP. Required for CC9.2 after M&A when the workforce still has two mail systems. ScopeMantle merges what it can see. It will not invent Entra rows that the Beta connector cannot fetch.

What to do this week

  1. Export all three if you have all three. Count unique client IDs after join. That number is the meeting.
  2. Write the audit footnote for Entra Beta if Microsoft is in play.
  3. Read shadow OAuth so you do not expect CASB to join these lists.
  4. Trial at $5 / $6. No seat min. Custom 500+.

How to run a three-IdP week without a hero engineer

  1. Monday: Google Admin export. Filename dated. Client ID column required.
  2. Tuesday: Okta OAuth clients and admin-approved apps. Split consents vs assignments in a note column.
  3. Wednesday: Entra. Export enterprise apps and whatever consent report your tenant actually offers. Label the file "partial."
  4. Thursday: join on owner email. Produce three counts: Google-only, Okta-only, both. The both-bucket is often smaller than people expect. The Google-only bucket in an "Okta shop" is the meeting.
  5. Friday: pick ten rows with mail or directory scopes. Decide sanctioned / tolerate / revoke. Write the rule. Do not revoke production on Friday afternoon unless IR demands it.

M&A addendum: keep both exports for ninety days after mail cutover. People will re-consent on the new IdP and leave the old grant live. Duplicate rows are expected. Unowned rows are not.

What each admin team usually believes (and is wrong about)

Google admins believe Apps with access is complete. It is complete for Google-mediated OAuth. It is not Okta. It is not Salesforce Connected Apps. Okta admins believe the app tile list is OAuth. Tiles are assignments. Consents are a different API. Entra admins believe gallery plus Conditional Access covers third-party Graph. Conditional Access governs tokens it can see. User-consent grants still need a list.

Put those three sentences in the architecture review. You will save a quarter of arguing.

Metrics per IdP

  • Grant count and grants per employee.
  • Percent with mail or directory scopes.
  • Median age of unattested grants.
  • Terminated owners still present (needs HRIS).
  • Time to export (if it is four hours, you will not do it monthly).

When to wait on ScopeMantle versus when to buy

If you are Google plus Okta and you already hate the Thursday join, buy. If you are Entra-only, buy only if you accept Beta and keep a manual export in the audit pack. If you are a 40-person shop with twelve apps, export once a quarter and read the Google guide. Our $5 list price has no seat minimum, so the product still works. The value story is weaker until grant volume hurts.

HIPAA: still not attested. Multi-cloud: we do not need an agent on endpoints. SIEM: optional. Super-admin: do not hand it to the MSSP for a look-see. Delegated app-access roles exist for a reason.

Auditor one-pager

IdPs in scope. Connectors GA vs Beta. Last export hashes. Join rule (client ID, owner email). Known blind spots (Entra, non-IdP Salesforce, warehouse keys). Point at CC9.2 mapping. That is a complete story. Adding a vendor logo wall is not.

Field guide: arguing with three identity teams

Google admins will say they already have Apps with access. Ask for last month's dated CSV with client IDs. If they produce a screenshot, you do not have a program. Okta admins will show you tiles. Ask for consents versus assignments. If they cannot split them, the next termination will surprise them. Entra admins will show Conditional Access. Ask for a single export of user-consent Graph grants with scopes. If the answer is three blades and a maybe, write Beta in the audit narrative and move on.

Put those three asks in a shared doc before the meeting. The meeting is then short. People argue less when the artifact is missing in public.

Join rules that survive a reorg

Primary key: OAuth client ID plus IdP name. Secondary: owner email. Do not join on display name. Do not join on "Salesforce" as a string. After M&A, keep IdP name on the row for ninety days. When someone asks why grant count went up after cutover, you can show methodology, not incompetence.

Normalize scores only after the join. A Google-only row should not be compared to an Okta assignment as if they were the same permission. Scope strings differ. Your rubric should say so. ScopeMantle normalizes what its GA connectors see. It does not invent Entra completeness.

Manual Entra export, good enough for a footnote

Export enterprise applications. Export any consent or permissions report your tenant offers. Screenshot the blade path and date it. Hash the files. Label the packet partial. That is better than implying Google plus Okta is the whole estate. When our Entra connector is GA, replace the packet and say so in the next cover memo.

$5 / $6, no seat min, custom 500+, trial. HIPAA not attested. Deep Google how-to: Workspace guide.

Mistakes I keep seeing after the first workshop

People export once and call it culture. People revoke by display name after a rebrand. People promise Entra completeness. People put OAuth rows in the user-access matrix. People send DSAR mail without a case ID. People treat a CASB invoice as grant inventory. People change a score threshold the night before audit. People staff an MSSP sprint with someone who cannot read a scope string. Each of those has a fix already on this page. The failure is skipping the fix because the demo looked polished.

Write the one thing you will not skip this week. Put it on a calendar. If you want the inventory to stay current, the 30-day trial is the productized version of the export. Five dollars per employee per month billed annually, or six dollars monthly. No seat minimum. Custom terms at 500+ employees. Microsoft Entra stays labelled Beta. HIPAA is not attested. Templates stay operator-reviewed. No fabricated customer counts on the customers page.

If you are evaluating us next to a GRC tool, keep both jobs honest. If you are evaluating us next to a consent-intercept tool, stack prevention and inventory. If you are an MSP, register the deal before the demo and keep the counsel gate in the SOW. If you are writing a board slide, use last quarter as the only benchmark we will stand behind. That is enough program for a quarter. The next quarter is whether the leftover-grant count actually moved.

A note for the identity architect after M&A

Keep dual exports for ninety days. Join on client ID plus IdP name, then owner email. Celebrate mail cutover separately from OAuth cutover. People re-consent and leave the old token live. Entra stays a labelled gap until GA. Salesforce and warehouse lists stay separate packets. $5 / $6, no seat min. The Thursday join is the meeting. The tile screenshot is not.

What you can do without buying anything

Export the IdP list. Deduplicate on client ID. Revoke three rows you cannot explain. Write the CC9.2 versus CC6.7 sentence for your auditor. Add OAuth grants equals zero to offboarding. Put an extension allow-list in one OU. Schedule a Friday tabletop with a fictional client ID. Hash a file and put it in GRC. Those steps do not require ScopeMantle. They do require a calendar and a human who will not skip them.

When those steps start to rot (and they will, usually by week six), the productized version is daily Google and Okta sync, scores, attestation expiry, bulk revoke, and DSAR snapshot on the same inventory. Price is public. Beta labels stay on the page. We will not invent a case study to make the last paragraph feel finished. Start the trial if the calendar is already losing.

Write the three identity-team asks in a doc before the meeting: dated Google CSV, Okta consents versus assignments, Entra partial packet. The meeting is then short. Missing artifacts argue better than architects do.

Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.

Start the trial from /demo when the manual export starts to rot. That is usually week six, not week one.

FAQ

Common questions

About ScopeMantle

ScopeMantle is an OAuth-grant audit and DSAR-automation platform for mid-market SaaS companies, sold primarily through an open MSSP partner program (70/30 wholesale split, deal registration, no direct-sale conflict in partner territories) and secondarily direct. Built in 2026.

Explore the partner program →

70 / 30 wholesale · deal registration honoured · no direct-sale conflict

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.