Skip to content

User.Read

Low 7 / 100 · delegated · microsoft-graph

Reads the signed-in user’s own profile and nothing else. There is no impersonation, no elevation, and no reach beyond the consenting user. This is the baseline scope almost every application requests and is the reference point for the low end of the scale.

Factor Value Score Domain
Data Classification Internal 15 Data Sensitivity & Leakage
Permission Type Delegated 10 Access Surface & Blast Radius
Token Persistence Short-lived 10 Data Sensitivity & Leakage
Access Policy Modification None 0 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Exfiltration Potential No data access or read-self only 0 Data Sensitivity & Leakage
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Permission Breadth Self 0 Access Surface & Blast Radius
Permission Operation Read 0 Access Surface & Blast Radius
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
User Breadth One user 0 Access Surface & Blast Radius
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 10 / 165 6.1% 30% 1.82
Data Sensitivity & Leakage 25 / 120 20.8% 25% 5.21
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 7

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard