This file records a pattern the 2025 campaign made unavoidable: durable authorisations accumulate, and almost nothing in an enterprise removes them.
The Asymmetry Is Consistent Across The Corpus
An OAuth grant at 25-0806 is created by one click and lives until revoked. An enrolled MFA device at 25-0813 survives a password reset. API tokens sat in support tickets at 25-0826. Machine keys stolen at 25-0723 worked after patching. Integration tokens reached 700 environments at 25-0818.
In each case the credential outlived the circumstance that justified it, and the removal step required somebody to decide it was time.
There Is No Expiry Pressure
Passwords expire because policy forces it. Certificates expire because the protocol does. Long-lived application authorisations have neither: no policy engine tracks them, no protocol retires them, and nothing breaks if they persist.
The failure mode of leaving one in place is invisible. The failure mode of removing one is an integration breaking during business hours, traceable to whoever removed it. Every incentive points the same way.
Which Makes The Inventory The Actual Control
You cannot revoke what you have not enumerated. An organisation that cannot list its connected applications, its enrolled factors and its service tokens has no remediation available after any of these incidents — the position at 25-0723, where the corpus could not establish what proportion of affected organisations completed key rotation.
This is unglamorous, cheap relative to most security spending, and repeatedly absent. Graded medium: it is an argument from the pattern across these files rather than a measured finding, and this desk has found no published data on revocation rates.
It generalises from the incident files in this database, supported by the vendor guidance listed below. No revocation-rate data exists that we could find. Corrections: corrections@forensicpost.com.