Skip to content

offline_access

Low 10.2 / 100 · delegated · microsoft-graph

Grants no data access of its own, which is why it is easy to wave through. Its risk is entirely durational: it issues refresh tokens that let an application keep acting long after the user has stopped paying attention, surviving password changes and going unnoticed in review. Its real impact is as a multiplier on whatever else the application holds, which is why it appears in several entries in combos.yaml rather than scoring highly alone.

Factor Value Score Domain
Token Persistence Offline or long-lived 40 Data Sensitivity & Leakage
Permission Type Delegated 10 Access Surface & Blast Radius
Access Policy Modification None 0 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Data Classification No data access 0 Data Sensitivity & Leakage
Exfiltration Potential No data access or read-self only 0 Data Sensitivity & Leakage
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Permission Breadth Self 0 Access Surface & Blast Radius
Permission Operation Read 0 Access Surface & Blast Radius
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
User Breadth One user 0 Access Surface & Blast Radius
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 10 / 165 6.1% 30% 1.82
Data Sensitivity & Leakage 40 / 120 33.3% 25% 8.33
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 10.2

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard