Why this matters
Third-party access runs through almost every identity incident on the Incident Desk: a supplier's employee, a partner platform, an integration nobody owns. In Microsoft 365 that access is an enterprise app with permissions someone approved years ago.
Application permissions work with no user present and apply to the whole tenant. Admin consent for every user hands a vendor what each of your people can reach. The review shows both, so you can cut what isn't needed.