Directory.Read.All
Medium 37.3 / 100 · application · microsoft-graph
Reads the entire directory: users, groups, applications, service principals, role assignments, and organisational configuration. It grants no ability to change anything, but it is the standard reconnaissance step before an identity attack, because it reveals exactly which accounts and applications are privileged and worth targeting.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Data Classification | PII or regulated | 40 | Data Sensitivity & Leakage |
| Exfiltration Potential | Export or tenant-wide exfiltration | 40 | Data Sensitivity & Leakage |
| Permission Breadth | Tenant-wide | 40 | Access Surface & Blast Radius |
| Permission Type | Application | 25 | Access Surface & Blast Radius |
| Token Persistence | Refresh token | 25 | Data Sensitivity & Leakage |
| User Breadth | All users | 20 | Access Surface & Blast Radius |
| Access Policy Modification | None | 0 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Permission Operation | Read | 0 | Access Surface & Blast Radius |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 0 / 140 | 0% | 40% | 0 |
| Access Surface & Blast Radius | 85 / 165 | 51.5% | 30% | 15.45 |
| Data Sensitivity & Leakage | 105 / 120 | 87.5% | 25% | 21.88 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 37.3 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard