Detecting Service Principal Credential Abuse: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission changes is key.
Signals worth watching
- New client secrets or certificates added to applications, especially high-privilege ones.
- New application permissions (app role assignments) granted, particularly mail, files or directory write.
- Service principal sign-ins from new IP addresses or countries.
- Applications accessing many mailboxes (MailItemsAccessed events by an app).
- New applications created by accounts that don't normally create them.
Where the data lives
- Entra ID audit logs: "Update application – Certificates and secrets management," "Add service principal credentials," "Add app role assignment to service principal."
- Service principal sign-in logs (
AADServicePrincipalSignInLogs). - Unified audit log for mailbox access.
- Defender for Cloud Apps app governance and Entra Workload ID Protection risk detections.
A starting query
New credentials on service principals and applications:
AuditLogs
| where OperationName has_any ("Certificates and secrets management", "Add service principal credentials")
| extend Actor = coalesce(tostring(InitiatedBy.user.userPrincipalName), tostring(InitiatedBy.app.displayName))
| extend App = tostring(TargetResources[0].displayName)
| project TimeGenerated, OperationName, Actor, App
Prioritize events for apps on your high-privilege list.
Response
- Confirm the change with the app owner.
- If unauthorized, remove the credential and review service principal sign-ins since it was added.
- Review data accessed by the app.
- Investigate how the actor obtained permission to modify the app.