The risks of Sites.Read.All

Did you know that Sites.Read.All provides access to ALL SharePoint sites and ALL
personal OneDrive folders?
Overprivileged identities are one of the biggest hidden security threats in cloud environments. The word doing the work in that sentence is hidden. Nothing breaks, no alert fires, and the permission looks reasonable in the consent dialogue. It is a read permission, after all.
When Entra ID roles, app permissions and Azure RBAC assignments are not regularly assessed, organisations face risks such as:
- Silent privilege escalation
- Increased blast radius during a breach
- Lack of visibility
- Compliance exposure
A 360-degree view of who can do what
At PB Security we have developed tools to provide a complete 360-degree permission assessment across all of Azure, covering both Entra ID and RBAC. An Entra ID and Azure RBAC Permission Assessment reviews:
- Overprivileged users and admins
- Enterprise Applications with excessive permissions
- Managed identities with unnecessary Contributor or Owner access
- Unused or stale service principals
- Custom roles that grant more power than intended
- Shadow permissions inherited through group nesting
That last one is the one that tends to surprise people. A group nested inside a group inherits what the outer group holds, and the path from a user to a permission can be several hops long. Nobody granted it deliberately, and nobody can see it by looking at the user.
You get a clear, actionable overview of exactly who can do what across your tenant.
Elevate your cloud security posture with PB Security, where confidence, control and expertise come standard.