Application.ReadWrite.All
Critical 81.2 / 100 · application · microsoft-graph
Creates and modifies any application or service principal in the tenant, including adding credentials to existing ones. That last capability is the critical one: the application can add a certificate to any other service principal and then authenticate as it, inheriting that principal’s permissions. Where a privileged application already exists, this is a direct path to tenant compromise, and it does so through ordinary configuration changes that look unremarkable in an audit log.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Exfiltration Potential | Export or tenant-wide exfiltration | 40 | Data Sensitivity & Leakage |
| Impersonation Capability | Directory-wide impersonation | 40 | Identity & Privilege Escalation |
| Permission Breadth | Tenant-wide | 40 | Access Surface & Blast Radius |
| Privilege Depth | Global administrator | 40 | Identity & Privilege Escalation |
| Privilege Elevation | Role assignment | 40 | Identity & Privilege Escalation |
| Permission Operation | Manage | 30 | Access Surface & Blast Radius |
| Permission Type | Application | 25 | Access Surface & Blast Radius |
| Token Persistence | Refresh token | 25 | Data Sensitivity & Leakage |
| Access Policy Modification | Group or role edits | 20 | Access Surface & Blast Radius |
| App Role Bundles | Broad admin role | 20 | Identity & Privilege Escalation |
| User Breadth | All users | 20 | Access Surface & Blast Radius |
| Data Classification | Internal | 15 | Data Sensitivity & Leakage |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 140 / 140 | 100% | 40% | 40 |
| Access Surface & Blast Radius | 135 / 165 | 81.8% | 30% | 24.55 |
| Data Sensitivity & Leakage | 80 / 120 | 66.7% | 25% | 16.67 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 81.2 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard