Skip to content

Files.ReadWrite.All

Medium 36.8 / 100 · application · microsoft-graph

Read and write access to every file in every OneDrive and SharePoint site in the tenant, acting without a signed-in user and therefore without any user able to notice. Write access matters as much as read: content can be altered or destroyed, not merely copied. Bulk enumeration makes wholesale exfiltration practical rather than theoretical.

Factor Value Score Domain
Permission Breadth Tenant-wide 40 Access Surface & Blast Radius
Exfiltration Potential Sync 35 Data Sensitivity & Leakage
Data Classification Confidential 25 Data Sensitivity & Leakage
Permission Type Application 25 Access Surface & Blast Radius
Token Persistence Refresh token 25 Data Sensitivity & Leakage
Permission Operation Write 20 Access Surface & Blast Radius
User Breadth All users 20 Access Surface & Blast Radius
Access Policy Modification None 0 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 105 / 165 63.6% 30% 19.09
Data Sensitivity & Leakage 85 / 120 70.8% 25% 17.71
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 36.8

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard