A reliable test has two distinct goals: confirm that disconnecting an app removes its access, then confirm that access can be restored and a representative task can proceed. Here, “disconnection” means removing app access—not testing an internet outage.
How to run the test
| Stage | Test action | What to confirm |
|---|---|---|
| Prepare | Record the affected workflow, the access the app currently has, and who controls the connection. | There is a clear state to compare before access is removed. |
| Disconnect | Disconnect the app, or ask the workspace administrator to disable it. | The app no longer has the access it had before the test. |
| Check removal | Inspect the connection state and try a low-impact task that depends on the app. | The result matches the expected access-removal state. |
| Restore access | Return through the normal connection or administrative process. | The app can regain only the access intended for it. |
| Resolve warnings | If a connection displays a warning or error, select it and use Fix connection or Re-authenticate, as applicable. | The connection reaches a usable state without an unexplained error. |
| Verify recovery | Repeat the representative task and record the result. | Access and the workflow behave as expected after recovery. |
Keep the disconnection result separate from the recovery result. A test can show that access was successfully removed but reveal that restoring it requires administrator action or reauthentication. Those are different findings and should not be treated as a single pass or failure.
What the test does not prove
The cited guidance does not specify what happens to data created before disconnection, whether that data remains accessible or can be exported, or how queued work, shared content, and audit records are affected. It also does not define a recovery deadline or guarantee that every warning will disappear after one reauthentication attempt.
The team must still confirm its own permission model, administrative responsibilities, data-retention expectations, and applicable security requirements. If those points are not documented, they should remain open questions rather than assumed test results.