Skip to content

User.Read.All

Medium 37.3 / 100 · application · microsoft-graph

Reads the full user profile of every account in the tenant without a signed-in user. The directory is regulated personal data — names, contact details, job titles, manager chains, office locations — and it is also the raw material for targeted social engineering, because it maps the organisation. Read-only, but the whole directory is readable in a single enumeration.

Factor Value Score Domain
Data Classification PII or regulated 40 Data Sensitivity & Leakage
Exfiltration Potential Export or tenant-wide exfiltration 40 Data Sensitivity & Leakage
Permission Breadth Tenant-wide 40 Access Surface & Blast Radius
Permission Type Application 25 Access Surface & Blast Radius
Token Persistence Refresh token 25 Data Sensitivity & Leakage
User Breadth All users 20 Access Surface & Blast Radius
Access Policy Modification None 0 Access Surface & Blast Radius
App Role Bundles No bundle 0 Identity & Privilege Escalation
Impersonation Capability None 0 Identity & Privilege Escalation
Legacy API Risk Modern API 0 Compliance & Trust Heuristics
Permission Operation Read 0 Access Surface & Blast Radius
Privilege Depth No administrative depth 0 Identity & Privilege Escalation
Privilege Elevation None 0 Identity & Privilege Escalation
Domain Raw Normalized Weight Contribution
Identity & Privilege Escalation 0 / 140 0% 40% 0
Access Surface & Blast Radius 85 / 165 51.5% 30% 15.45
Data Sensitivity & Leakage 105 / 120 87.5% 25% 21.88
Compliance & Trust Heuristics 0 / 40 0% 5% 0
Composite 37.3

Disagree with this rating? That is the point — open a rating change request naming the factor you would change and the evidence for it.

OARS — Open App Risk Standard is derived from the Graph Consent Risk Framework by Khurram Chaudhary.

Specification and dataset licensedCC BY 4.0; tooling and site licensed MIT. © 2026 Khurram Chaudhary and the Citadel Project contributors.

A Citadel Project standard ·GitHub ·Cite this standard