Sites.FullControl.All
Medium 43.3 / 100 · application · microsoft-graph
Full control of every SharePoint site collection in the tenant, including site permissions. The permission-management capability is what separates this from Files.ReadWrite.All: the application can grant continuing access to identities it chooses, establishing persistence that survives revocation of the original consent.
Factor assignments
Section titled “Factor assignments”| Factor | Value | Score | Domain |
|---|---|---|---|
| Exfiltration Potential | Export or tenant-wide exfiltration | 40 | Data Sensitivity & Leakage |
| Permission Breadth | Tenant-wide | 40 | Access Surface & Blast Radius |
| Permission Operation | Manage | 30 | Access Surface & Blast Radius |
| Data Classification | Confidential | 25 | Data Sensitivity & Leakage |
| Permission Type | Application | 25 | Access Surface & Blast Radius |
| Token Persistence | Refresh token | 25 | Data Sensitivity & Leakage |
| Access Policy Modification | Group or role edits | 20 | Access Surface & Blast Radius |
| User Breadth | All users | 20 | Access Surface & Blast Radius |
| App Role Bundles | No bundle | 0 | Identity & Privilege Escalation |
| Impersonation Capability | None | 0 | Identity & Privilege Escalation |
| Legacy API Risk | Modern API | 0 | Compliance & Trust Heuristics |
| Privilege Depth | No administrative depth | 0 | Identity & Privilege Escalation |
| Privilege Elevation | None | 0 | Identity & Privilege Escalation |
How the score is reached
Section titled “How the score is reached”| Domain | Raw | Normalized | Weight | Contribution |
|---|---|---|---|---|
| Identity & Privilege Escalation | 0 / 140 | 0% | 40% | 0 |
| Access Surface & Blast Radius | 135 / 165 | 81.8% | 30% | 24.55 |
| Data Sensitivity & Leakage | 90 / 120 | 75% | 25% | 18.75 |
| Compliance & Trust Heuristics | 0 / 40 | 0% | 5% | 0 |
| Composite | 43.3 |
References
Section titled “References”Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.
OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.
Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.
A Citadel Project standard ·GitHub ·Cite this standard