There are plenty of PowerShell scripts/free tools out there that do this, and most the information is available without even needing additional licensing. Look them up an pick the one that best suits your needs, or modify it accordingly. Here's one of mine for example: https://michev.info/blog/post/5922/reporting-on-entra-id-integrated-applications-service-principals-and-their-permissions
Export full list of Overprivileged apps in Defender for Cloudapps
Landrover
20
Reputation points
From cloud app Security portal , How can i export a detailed report of Over privileged apps including granted permissions per app,whether in use or not,Privileged level, Type(Application or delegated).
The default export does not include all these details
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
A tool that provides visibility, control, and threat protection for cloud-based applications and services
2 answers
Sort by: Most helpful
-
Vasil Michev 123.5K Reputation points MVP Volunteer Moderator2025-09-10T15:41:07.4+00:00 -
EduardsGrebezs 1,096 Reputation points2025-11-18T07:56:33.89+00:00 Hi,
Check this one - https://github.com/AzureAD/MSIdentityTools
- PS > Install-Module MSIdentityTools,
- PS > Import-Module MSIdentityTools,
- PS > Install-Module ImportExcel,
- PS > Connect-MgGraph -Scope Application.Read.All
- PS > Export-MsIdAppConsentGrantReport -ReportOutputType ExcelWorkbook -ExcelWorkbookPath .\Appconsent.xlsx (change location before execution)