Skip to content

Mail.Read

Low 14.1 / 100 · delegated · microsoft-graph

Reads the signed-in user’s mailbox in full, including message bodies and attachments. Mail routinely contains credentials, contracts, and personal data, so sensitivity is high even though reach stops at one user. Read-only and single-user scope keep this well below the tenant-wide variants.

Factor Value Score Domain
Data Classification Confidential 25 Data Sensitivity & Leakage
Exfiltration Potential Basic read 15 Data Sensitivity & Leakage
Permission Breadth Single user or object 10 Access Surface & Blast Radius
Permission Type Delegated 10 Access Surface & Blast Radius
Token Persistence Short-lived 10 Data Sensitivity & Leakage
Access Policy Modification None 0 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Permission Operation Read 0 Access Surface & Blast Radius
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
User Breadth One user 0 Access Surface & Blast Radius
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 20 / 165 12.1% 30% 3.64
Data Sensitivity & Leakage 50 / 120 41.7% 25% 10.42
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 14.1

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard