Entra ID App Sprawl & Poor App Governance are Real Threats
You can't improve what you can’t measure. With sprawling SaaS apps in many tenants, it's important to focus first on the highest risk areas. Overprivileged apps, expired secrets, and ownerless enterprise apps all create massive risk blind spots.
AppGov Score shines a light on your Entra ID app environment by:
- Scanning your tenant for risky applications and misconfigurations
- Providing an easy-to-understand score based on real-world governance standards from Microsoft recommendations and Microsoft MVPs
- Giving you actionable insights and expert guidance via our App Governance & Security community
🛡️You’ll receive a report and score that measures your risk level across 20+ key security and governance checks in your Entra ID tenant, including:
- High-risk apps
- Apps using public client flows
- Apps with no assigned owner
- Overprivileged and BEC-risky apps
- Apps with expired/expiring secrets
- Apps missing admin consent
- Accounts with elevated app permissions
Don't wait for a breach to identify and close gaps in your application governance.

🎯 Who Needs AppGov Score?
If you're a M365 Leader, Identity Admin, Security Engineer, or Entra ID Owner, and you're tired of the "black box" of SaaS app security, AppGov Score is built for you.
🧠 Built with Community. Backed by Microsoft MVPs.
Join a network of security-minded professionals and Microsoft MVPs. Get tips, discuss findings, and learn how others are reducing risk, all in our free AppGov community forum.
Why AppGov Score is Different
Feature |
AppGov Score |
Microsoft Built-ins |
Real-world governance risk scoring |
✅ Yes |
❌ No |
Tenant-wide Entra ID app scan |
✅ Yes |
⚠️ Limited |
Expert Explanations about why each check is important and App Governance community access |
✅ Yes |
❌ No |
Free to use |
✅ Yes |
✅ Some tools |
📥 How to Get ENow AppGov Score
Know your app risk in under 10 minutes.
- Fill out your information
- Review the permissions needed and grant consent
- Get your AppGov Score report
- Review your report and score
- Ask experts and peers for guidance in our Entra ID Application Governance & Security Forum
- See if upgrading to App Governance Accelerator makes sense for your organization (7-day free trial available for App Governance Accelerator - Standard)
Start Free. No Strings Attached.
Scan. Score. Secure.
- Free AppGov Score Scan & Report
- No credit card required
- Quick Report Turnaround
- Community access and resources
Questions? Need Help?
Join the AppGov Score Community Forum and get advice from Microsoft MVPs and peers like you.
If you run into any issues accessing AppGov Score, please contact us at info@appgovscore.com.
Frequently Asked Questions
- To get your AppGov report, somebody with Entra ID (formerly Azure AD) will need to consent.
- The application will require the following read only permissions:
Permission Name Description Directory.Read.All Read directory data. EntitlementManagement.Read.All Read all entitlement management resources. Policy.Read.All Read your organization's policies. Policy.Read.PermissionGrant Read consent and permission grant policies. RoleManagement.Read.All RoleManagement.Read.All
- For organizations with under 2,000 apps, it take approximately 5 minutes. For larger organizations it can take up to an hour. You can be notified via text or email when the report is ready.
- You can also bookmark the page and come back to it in about 20 minutes. This is recommended if the email address you signed up with is not mail-enabled.
- The AppGov Score methodology was created following Microsoft's recommended practices for Application Security & Governance and is governed by several long-time Microsoft Security & Identity MVPs. If you have feedback, please post in our community forum or contact us.
Yes, it is free. No payment or credit card information is required to obtain your AppGov Score and assessment report. ENow is grateful for all we've learned through the IT and Microsoft community over the years. We created this free tool and free blog and forum resources to give back and help out our fellow IT Pro! We truly believe that we're in this and stronger together.
If you're looking for expanded capabilities, there are paid versions available (Standard, Professional, and Enterprise).
AppGov Score is built by ENow Software | 20+ years of Microsoft expertise | Trusted in 130+ countries
Managing the volume of Entra ID Apps is very challenging. The native Microsoft tools do not make it easy to understand how big the problem is in a tenant. Misconfigured and overprivileged apps are a huge problem and are now being exploited by adversaries. It's awesome ENow has tackled this problem head on.

Application Governance is a crucial aspect of Zero Trust, as it ensures that your applications are secure and compliant. With App Governance Accelerator, I can monitor my Application Governance using a simple and intuitive score card. The application will help me achieve our application governance goals with ease and confidence.
