Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Service Principal Credential Abuse: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.

Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission changes is key.

Signals worth watching

  • New client secrets or certificates added to applications, especially high-privilege ones.
  • New application permissions (app role assignments) granted, particularly mail, files or directory write.
  • Service principal sign-ins from new IP addresses or countries.
  • Applications accessing many mailboxes (MailItemsAccessed events by an app).
  • New applications created by accounts that don't normally create them.

Where the data lives

  • Entra ID audit logs: "Update application – Certificates and secrets management," "Add service principal credentials," "Add app role assignment to service principal."
  • Service principal sign-in logs (AADServicePrincipalSignInLogs).
  • Unified audit log for mailbox access.
  • Defender for Cloud Apps app governance and Entra Workload ID Protection risk detections.

A starting query

New credentials on service principals and applications:

AuditLogs
| where OperationName has_any ("Certificates and secrets management", "Add service principal credentials")
| extend Actor = coalesce(tostring(InitiatedBy.user.userPrincipalName), tostring(InitiatedBy.app.displayName))
| extend App = tostring(TargetResources[0].displayName)
| project TimeGenerated, OperationName, Actor, App

Prioritize events for apps on your high-privilege list.

Response

  1. Confirm the change with the app owner.
  2. If unauthorized, remove the credential and review service principal sign-ins since it was added.
  3. Review data accessed by the app.
  4. Investigate how the actor obtained permission to modify the app.
detect service principal credential abuseApp credential abuse2020

More on this story