Skip to content

Application.ReadWrite.All

Critical 81.2 / 100 · application · microsoft-graph

Creates and modifies any application or service principal in the tenant, including adding credentials to existing ones. That last capability is the critical one: the application can add a certificate to any other service principal and then authenticate as it, inheriting that principal’s permissions. Where a privileged application already exists, this is a direct path to tenant compromise, and it does so through ordinary configuration changes that look unremarkable in an audit log.

Factor Value Score Domain
Exfiltration Potential Export or tenant-wide exfiltration 40 Data Sensitivity & Leakage
Impersonation Capability Directory-wide impersonation 40 Identity & Privilege Escalation
Permission Breadth Tenant-wide 40 Access Surface & Blast Radius
Privilege Depth Global administrator 40 Identity & Privilege Escalation
Privilege Elevation Role assignment 40 Identity & Privilege Escalation
Permission Operation Manage 30 Access Surface & Blast Radius
Permission Type Application 25 Access Surface & Blast Radius
Token Persistence Refresh token 25 Data Sensitivity & Leakage
Access Policy Modification Group or role edits 20 Access Surface & Blast Radius
App Role Bundles Broad admin role 20 Identity & Privilege Escalation
User Breadth All users 20 Access Surface & Blast Radius
Data Classification Internal 15 Data Sensitivity & Leakage
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 140 / 140 100% 40% 40
Access Surface & Blast Radius 135 / 165 81.8% 30% 24.55
Data Sensitivity & Leakage 80 / 120 66.7% 25% 16.67
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 81.2

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard