Mail.Send
Low 28 / 100 · delegated · microsoft-graph
Lets the application originate mail as the signed-in user. Messages carry the user’s real address and pass internal authenticity checks, which makes this a well-documented phishing and business-email-compromise pivot. Audit trails attribute the message to the user rather than to the application, so the action is hard to trace after the fact. Reach is limited to the consenting user, which keeps blast radius low.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Exfiltration Potential | Send-as or message delivery | 35 | Data Sensitivity & Leakage |
| Permission Operation | Send | 30 | Access Surface & Blast Radius |
| Data Classification | Confidential | 25 | Data Sensitivity & Leakage |
| Impersonation Capability | Delegated send-as | 15 | Identity & Privilege Escalation |
| Permission Breadth | Single user or object | 10 | Access Surface & Blast Radius |
| Permission Type | Delegated | 10 | Access Surface & Blast Radius |
| Token Persistence | Short-lived | 10 | Data Sensitivity & Leakage |
| Access Policy Modification | None | 0 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
| User Breadth | One user | 0 | Access Surface & Blast Radius |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 15 / 140 | 10.7% | 40% | 4.29 |
| Access Surface & Blast Radius | 50 / 165 | 30.3% | 30% | 9.09 |
| Data Sensitivity & Leakage | 70 / 120 | 58.3% | 25% | 14.58 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 28 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard