User.Read.All
Medium 37.3 / 100 · application · microsoft-graph
Reads the full user profile of every account in the tenant without a signed-in user. The directory is regulated personal data — names, contact details, job titles, manager chains, office locations — and it is also the raw material for targeted social engineering, because it maps the organisation. Read-only, but the whole directory is readable in a single enumeration.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Data Classification | PII or regulated | 40 | Data Sensitivity & Leakage |
| Exfiltration Potential | Export or tenant-wide exfiltration | 40 | Data Sensitivity & Leakage |
| Permission Breadth | Tenant-wide | 40 | Access Surface & Blast Radius |
| Permission Type | Application | 25 | Access Surface & Blast Radius |
| Token Persistence | Refresh token | 25 | Data Sensitivity & Leakage |
| User Breadth | All users | 20 | Access Surface & Blast Radius |
| Access Policy Modification | None | 0 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Permission Operation | Read | 0 | Access Surface & Blast Radius |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 0 / 140 | 0% | 40% | 0 |
| Access Surface & Blast Radius | 85 / 165 | 51.5% | 30% | 15.45 |
| Data Sensitivity & Leakage | 105 / 120 | 87.5% | 25% | 21.88 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 37.3 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard