Skip to content

RoleManagement.ReadWrite.Directory

High 64.6 / 100 · application · microsoft-graph

Reads and writes directory role assignments, which includes assigning Global Administrator. An application holding this can promote any identity it controls to full tenant administration, making it equivalent to Global Administrator regardless of what other permissions it holds. There is no legitimate low-risk use of this scope.

Factor Value Score Domain
Permission Breadth Tenant-wide 40 Access Surface & Blast Radius
Privilege Depth Global administrator 40 Identity & Privilege Escalation
Privilege Elevation Role assignment 40 Identity & Privilege Escalation
Permission Operation Manage 30 Access Surface & Blast Radius
Permission Type Application 25 Access Surface & Blast Radius
Token Persistence Refresh token 25 Data Sensitivity & Leakage
Access Policy Modification Group or role edits 20 Access Surface & Blast Radius
App Role Bundles Broad admin role 20 Identity & Privilege Escalation
User Breadth All users 20 Access Surface & Blast Radius
Data Classification Internal 15 Data Sensitivity & Leakage
Exfiltration Potential Basic read 15 Data Sensitivity & Leakage
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 100 / 140 71.4% 40% 28.57
Access Surface & Blast Radius 135 / 165 81.8% 30% 24.55
Data Sensitivity & Leakage 55 / 120 45.8% 25% 11.46
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 64.6

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard