Files.ReadWrite.All
Medium 36.8 / 100 · application · microsoft-graph
Read and write access to every file in every OneDrive and SharePoint site in the tenant, acting without a signed-in user and therefore without any user able to notice. Write access matters as much as read: content can be altered or destroyed, not merely copied. Bulk enumeration makes wholesale exfiltration practical rather than theoretical.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Permission Breadth | Tenant-wide | 40 | Access Surface & Blast Radius |
| Exfiltration Potential | Sync | 35 | Data Sensitivity & Leakage |
| Data Classification | Confidential | 25 | Data Sensitivity & Leakage |
| Permission Type | Application | 25 | Access Surface & Blast Radius |
| Token Persistence | Refresh token | 25 | Data Sensitivity & Leakage |
| Permission Operation | Write | 20 | Access Surface & Blast Radius |
| User Breadth | All users | 20 | Access Surface & Blast Radius |
| Access Policy Modification | None | 0 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 0 / 140 | 0% | 40% | 0 |
| Access Surface & Blast Radius | 105 / 165 | 63.6% | 30% | 19.09 |
| Data Sensitivity & Leakage | 85 / 120 | 70.8% | 25% | 17.71 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 36.8 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard