Find and Remove Delegated Access After a Breach: Shared Inboxes, View‑Only Users, and Linked Apps

A password reset is essential after a breach, but it is not enough. Attackers often create quiet paths back into your account by adding delegated users, linking third‑party apps, setting up hidden mailbox rules, or connecting single‑sign‑on (SSO) sessions across multiple services. This guide shows you, step by step, how to find and remove those lingering access points in common accounts and what to check if you use shared inboxes, view‑only users, or linked apps.

Why Delegated Access Matters After a Breach

Delegated access lets another person or application use your account or its data without your password. That’s convenient for teamwork and integrations, but it’s also a favorite persistence method for attackers. They may:

  • Add mailbox delegates (shared inbox helpers) who can read, send, or delete mail as you.
  • Create “view‑only” or guest users in your cloud storage or productivity suite.
  • Authorize third‑party apps via OAuth, which continue to access data even after a password change.
  • Set hidden inbox rules and email forwarding to copy messages elsewhere.
  • Register security keys or add recovery methods that help them regain access later.

After any suspected compromise, audit and revoke these paths, then rebuild trust with new credentials and stronger security settings.

Quick Triage: The 15‑Minute Sweep

If time is tight, do this first to stop ongoing data leakage:

  1. Change your password on the breached account and anywhere else you reused it.
  2. Enable multi‑factor authentication (MFA) with an authenticator app or security key.
  3. Revoke active sessions/devices and sign out everywhere.
  4. Check linked apps (OAuth/connected apps) and remove anything you don’t recognize.
  5. Disable email forwarding and suspicious rules that auto‑move or forward mail.

Then proceed with the deeper audit below.

Deeper Audit: What to Check in Any Account

These categories apply broadly to email, cloud storage, collaboration suites, and social accounts.

  • Authorized apps and sites: Look for “Connected apps,” “Security & privacy,” or “Apps with access to your account.” Revoke unknown or unneeded apps.
  • Delegates and shared access: Review “Delegation,” “Shared mailboxes,” “Users and groups,” or “Members” lists. Remove anyone you don’t expect.
  • Email rules and forwarding: Inspect rules/filters for auto-forward, delete, mark‑as‑read, or move actions. Delete suspicious entries.
  • Sign‑in and device history: Sign out everywhere, remove unknown devices, and look for unusual locations or IPs.
  • Recovery methods: Remove unknown phone numbers, emails, and hardware security keys. Regenerate backup codes.
  • API tokens and app passwords: Revoke legacy app passwords, personal access tokens, and SSH keys not in use.

How to Remove Delegated Access in Popular Services

Gmail and Google Workspace

  • Delegated mailbox access: Gmail Settings > See all settings > Accounts and Import > Grant access to your account. Remove unknown delegates.
  • Forwarding and filters: Settings > Forwarding and POP/IMAP. Turn off forwarding; delete unknown forwarding addresses. In Filters and Blocked Addresses, remove suspicious filters.
  • Connected apps: myaccount.google.com > Security > Third‑party access and Your devices. Remove unrecognized apps/devices. Also check myaccount.google.com/permissions.
  • Recovery methods: myaccount.google.com > Security > Ways we can verify it’s you. Remove unknown phone/email; regenerate backup codes.
  • Workspace admins: Admin console > Directory > Users > User details > Security for app passwords and OAuth tokens; Groups for members; Gmail routing and compliance for domain‑level forwarding.

Microsoft Outlook and 365

  • Mailbox delegates and permissions: Outlook on the web > Settings > Mail > Accounts > Sharing/Permissions. Remove delegates or shared mailbox permissions.
  • Inbox rules and forwarding: Settings > Mail > Rules; Settings > Mail > Forwarding. Delete suspicious rules and disable forwarding.
  • Connected apps and sessions: myaccount.microsoft.com > Privacy & security > Apps and services; Security info for methods and sessions. Remove unfamiliar entries.
  • Azure/Entra admins: Entra ID > Users > User > Sign‑in logs, App registrations, Enterprise apps (User consent), and Mailbox audit logs in Purview to trace delegate actions.

Apple iCloud Mail

  • Rules: iCloud Mail (web) > Settings > Rules. Delete unknown rules.
  • Forwarding: iCloud Mail > Preferences > General. Disable forwarding.
  • Devices and app‑specific passwords: appleid.apple.com > Devices; Sign‑In and Security > App‑Specific Passwords. Remove unrecognized devices and revoke app passwords.

Yahoo/AOL Mail

  • Filters and forwarding: Settings > More Settings > Filters; Mailboxes. Remove odd filters and forwarding addresses.
  • Connected apps and sessions: Account Security > Manage app passwords; Recent activity. Revoke unrecognized entries.

Slack and Collaboration Tools

  • Workspace access: Slack > Workspace Settings > Manage members. Remove unknown accounts and guests.
  • App integrations: Slack > Settings & administration > Manage apps. Remove suspicious apps/bots and revoke tokens.
  • Email bridges: If using email-to-Slack or third‑party connectors, disable or rotate tokens.

Google Drive, OneDrive, Dropbox

  • File/folder sharing: Check recent and shared views; remove unknown viewers/commenters, especially “Anyone with the link” access.
  • Connected apps: Each service’s security settings for app integrations. Revoke unknown apps and regenerate tokens where supported.
  • Activity logs: Review activity/audit logs for mass downloads or permission changes.

Social Platforms (Facebook, Instagram, Twitter/X, LinkedIn)

  • Connected apps and websites: Security/Settings > Apps and Websites/Connected apps. Remove anything you don’t recognize.
  • Business/brand account roles: Review Page Roles, Business Manager members, or Organization admins for unknown users.
  • Login sessions and recovery: End active sessions; update recovery emails/phones.

Shared Inboxes: Risks and Remediation

Shared inboxes (support@, info@, billing@) often have multiple delegates, forwarding rules, and third‑party tools. Attackers love them because access can blend in with normal team activity.

Checklist for Shared Inboxes

  • Inventory every delegate with send‑as or full‑access rights. Remove anyone not currently required.
  • Audit forwarding and routing at the mailbox and domain level (catch‑all, journaling, transport rules).
  • Review third‑party connectors (helpdesk, CRM, marketing, ticketing) and rotate API keys.
  • Examine mailbox rules for delete/move/forward actions that could hide replies or exfiltrate data.
  • Enable audit logging if your provider supports it, and export logs for the incident period.
  • Implement least privilege: default to read‑only or restricted roles; grant send‑as only when needed; set expiry dates for temp access.

View‑Only Users: Silent Data Exposure

“View‑only” sounds safe, but it still exposes data. An attacker with view rights can copy files, scrape contacts, or capture screenshots.

  • Review access lists across drives, wikis, project tools, and calendars. Remove stale guests and public links.
  • Expire shared links and require sign‑in for access to sensitive material.
  • Enable watermarking or viewer restrictions where available (e.g., disable downloads/printing for sensitive docs).

Linked Apps and OAuth Tokens

OAuth lets you “Sign in with Google/Microsoft/Apple” or grant an app limited access. After a breach, these tokens can keep working until you revoke them.

How to Safely Prune Linked Apps

  1. List all authorized apps from your account’s security page.
  2. Remove apps you don’t need or don’t recognize. Be cautious with apps tied to business processes—coordinate with your team first.
  3. Rotate tokens and passwords for remaining apps; re‑authorize only when necessary.
  4. Disable broad scopes (e.g., full mailbox or drive access) in favor of least‑privilege alternatives.
  5. Turn off universal user consent in business tenants and require admin approval.

Hidden Persistence to Hunt For

  • Inbox rules that mark as read, move to archive, or forward to external addresses to hide alerts and siphon data.
  • Auto‑forwarding at the domain level set by a former admin or compromised rule.
  • Legacy protocols (IMAP/POP/SMTP) left enabled for “app passwords.” Disable if not needed.
  • New recovery options quietly added by an attacker (phone, email, hardware key).
  • Unfamiliar SSO connections from identity providers you don’t use.

Team and Business Considerations

  • Communicate changes: Removing delegates or apps may disrupt workflows. Notify stakeholders and schedule rotations.
  • Document evidence: Save screenshots of suspicious rules, delegates, and app scopes before removal.
  • Centralize logs: Export sign‑in, audit, and mailbox logs to a secure location for later review.
  • Set access reviews: Quarterly recertification for delegates, guests, and app permissions.
  • Use role‑based access: Replace personal account access with group‑based roles linked to tickets or approvals.

Strengthen Your Account Going Forward

  • Use phishing‑resistant MFA (hardware keys or passkeys) for primary accounts.
  • Turn off legacy authentication and require modern auth only.
  • Adopt password managers with unique, long passwords and breach alerts.
  • Enable login alerts and monitor security dashboards for unusual activity.
  • Set data‑loss prevention and automatic alerts for mass downloads or external sharing (business tiers).

What to Do If You Find Signs of Ongoing Abuse

  • Preserve evidence: Export rules, app permissions, and logs before removing them.
  • Revoke access broadly: Disable app tokens, remove delegates, sign out all devices, and reset passwords again.
  • Notify affected contacts if emails or files were exposed or forwarded externally.
  • Monitor financial identity for new credit lines, address changes, or suspicious transactions if personal data was involved. A dedicated monitoring service can alert you to new inquiries or account changes that signal identity misuse. For ongoing visibility, consider credit and identity monitoring alongside your security cleanup.

Sample Post‑Breach Audit Plan

  1. Containment (Day 0)
    • Change passwords; enable MFA; sign out everywhere.
    • Disable forwarding and suspicious rules.
  2. Eradication (Days 1–2)
    • Remove delegates, guests, and unknown group members.
    • Revoke linked apps and tokens; rotate keys and app passwords.
    • Audit recovery methods and security keys.
  3. Recovery (Days 2–3)
    • Restore required access with least privilege and expiration dates.
    • Re‑enable needed integrations with limited scopes.
  4. Monitoring (Days 3–30)
    • Watch logs, login alerts, and email rules daily for re‑appearance.
    • Schedule a 30‑day follow‑up to remove any temporary access.

Red Flags You Shouldn’t Ignore

  • Emails marked as read that you never opened, or messages disappearing from the inbox.
  • Contacts reporting strange messages “from you.”
  • Unknown apps requesting “read, send, delete” or “full drive access.”
  • New devices or locations in login history you don’t recognize.
  • Security notifications auto‑archived by a mysterious rule.

FAQ

Will changing my password remove delegated access and linked apps?

No. Delegates, forwarding rules, and OAuth tokens usually persist after a password change. You must remove them explicitly.

What should I remove first if I’m overwhelmed?

Start with forwarding and inbox rules, then revoke linked apps, then remove delegates and guest users. Finally, review recovery methods and sessions.

Is “view‑only” access safe to leave in place?

It still exposes information. If you don’t actively need a viewer or public link, remove it or set an expiration.

How often should I review delegated access?

After any incident and at least quarterly for business accounts; twice a year for personal accounts.

Conclusion

A breach cleanup is not complete until you remove every backdoor the attacker could use. Go beyond passwords: revoke linked apps and tokens, delete suspicious rules and forwarding, remove unused delegates and guests, and lock down recovery methods. With least‑privilege access, regular reviews, and strong MFA, you can prevent quiet data leakage and stop attackers from returning. If sensitive personal or financial details may have been exposed, add ongoing credit and identity monitoring to catch misuse early while you strengthen your accounts and habits.

Good to Know

Attackers often create quiet backdoors like email forwarding rules and long‑lived app tokens; even if you change your password, those connections can keep exfiltrating data until you explicitly revoke them.