RoleManagement.ReadWrite.Directory
High 64.6 / 100 · application · microsoft-graph
Reads and writes directory role assignments, which includes assigning Global Administrator. An application holding this can promote any identity it controls to full tenant administration, making it equivalent to Global Administrator regardless of what other permissions it holds. There is no legitimate low-risk use of this scope.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Permission Breadth | Tenant-wide | 40 | Access Surface & Blast Radius |
| Privilege Depth | Global administrator | 40 | Identity & Privilege Escalation |
| Privilege Elevation | Role assignment | 40 | Identity & Privilege Escalation |
| Permission Operation | Manage | 30 | Access Surface & Blast Radius |
| Permission Type | Application | 25 | Access Surface & Blast Radius |
| Token Persistence | Refresh token | 25 | Data Sensitivity & Leakage |
| Access Policy Modification | Group or role edits | 20 | Access Surface & Blast Radius |
| App Role Bundles | Broad admin role | 20 | Identity & Privilege Escalation |
| User Breadth | All users | 20 | Access Surface & Blast Radius |
| Data Classification | Internal | 15 | Data Sensitivity & Leakage |
| Exfiltration Potential | Basic read | 15 | Data Sensitivity & Leakage |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 100 / 140 | 71.4% | 40% | 28.57 |
| Access Surface & Blast Radius | 135 / 165 | 81.8% | 30% | 24.55 |
| Data Sensitivity & Leakage | 55 / 120 | 45.8% | 25% | 11.46 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 64.6 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard