Skip to content

Directory.Read.All

Medium 37.3 / 100 · application · microsoft-graph

Reads the entire directory: users, groups, applications, service principals, role assignments, and organisational configuration. It grants no ability to change anything, but it is the standard reconnaissance step before an identity attack, because it reveals exactly which accounts and applications are privileged and worth targeting.

Factor Value Score Domain
Data Classification PII or regulated 40 Data Sensitivity & Leakage
Exfiltration Potential Export or tenant-wide exfiltration 40 Data Sensitivity & Leakage
Permission Breadth Tenant-wide 40 Access Surface & Blast Radius
Permission Type Application 25 Access Surface & Blast Radius
Token Persistence Refresh token 25 Data Sensitivity & Leakage
User Breadth All users 20 Access Surface & Blast Radius
Access Policy Modification None 0 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Permission Operation Read 0 Access Surface & Blast Radius
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 85 / 165 51.5% 30% 15.45
Data Sensitivity & Leakage 105 / 120 87.5% 25% 21.88
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 37.3

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard