offline_access
Low 10.2 / 100 · delegated · microsoft-graph
Grants no data access of its own, which is why it is easy to wave through. Its risk is entirely durational: it issues refresh tokens that let an application keep acting long after the user has stopped paying attention, surviving password changes and going unnoticed in review. Its real impact is as a multiplier on whatever else the application holds, which is why it appears in several entries in combos.yaml rather than scoring highly alone.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Token Persistence | Offline or long-lived | 40 | Data Sensitivity & Leakage |
| Permission Type | Delegated | 10 | Access Surface & Blast Radius |
| Access Policy Modification | None | 0 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Data Classification | No data access | 0 | Data Sensitivity & Leakage |
| Exfiltration Potential | No data access or read-self only | 0 | Data Sensitivity & Leakage |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Permission Breadth | Self | 0 | Access Surface & Blast Radius |
| Permission Operation | Read | 0 | Access Surface & Blast Radius |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
| User Breadth | One user | 0 | Access Surface & Blast Radius |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 0 / 140 | 0% | 40% | 0 |
| Access Surface & Blast Radius | 10 / 165 | 6.1% | 30% | 1.82 |
| Data Sensitivity & Leakage | 40 / 120 | 33.3% | 25% | 8.33 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 10.2 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard