Skip to content

Sites.FullControl.All

Medium 43.3 / 100 · application · microsoft-graph

Full control of every SharePoint site collection in the tenant, including site permissions. The permission-management capability is what separates this from Files.ReadWrite.All: the application can grant continuing access to identities it chooses, establishing persistence that survives revocation of the original consent.

Factor Value Score Domain
Exfiltration Potential Export or tenant-wide exfiltration 40 Data Sensitivity & Leakage
Permission Breadth Tenant-wide 40 Access Surface & Blast Radius
Permission Operation Manage 30 Access Surface & Blast Radius
Data Classification Confidential 25 Data Sensitivity & Leakage
Permission Type Application 25 Access Surface & Blast Radius
Token Persistence Refresh token 25 Data Sensitivity & Leakage
Access Policy Modification Group or role edits 20 Access Surface & Blast Radius
User Breadth All users 20 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 135 / 165 81.8% 30% 24.55
Data Sensitivity & Leakage 90 / 120 75% 25% 18.75
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 43.3

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard