๐Ÿ›ก๏ธ Graph permission risk checker

Paste what an app has been granted and see which permissions are dangerous, why, and what to use instead.

๐Ÿ”’ Checked in your browser against a built-in catalogue. Nothing you paste leaves this page.

Why this matters

Attackers love application permissions because they apply to the whole tenant with no user present. AppRoleAssignment.ReadWrite.All or Application.ReadWrite.All on a forgotten app is effectively a Global Admin account that never signs in interactively.

Most apps need far less than they were given. Sites.Selected, Exchange RBAC for Applications and the OwnedBy variants exist precisely so you can grant the narrow thing.