
Principal Consultant
Identity Managed
What happens when users can consent to almost anything across more than 3,000 Entra ID enterprise applications? Over the course of this session, Identity Managed Founder David Lundell shares how his team turned a “permissions wilderness” into a governed, secure, and manageable application ecosystem. You’ll see how they built an application governance framework with executive sponsorship, clear ownership, and tools and processes that reduced risk and Global Admin workload while improving response times to access requests. You’ll follow David through building an application governance charter, using App Risk Scores to evaluate apps and consent requests, and triaging existing apps to eliminate the “Unholy Trio”: the unused, the overly permissioned, and the unevaluated. You’ll also see how Custom Security Attributes help apply Conditional Access at scale and clarify the difference between application and delegated permissions—and between user-level and tenant-wide consent—so you can bring order to your own app landscape.