Non-Human Identity: Service Principal Impossible Travel & Credential/MFA Tamperi

This rule detects potentially malicious activity involving Service Principals in Microsoft Entra ID. It identifies two scenarios: 1) Impossible travel, where a service principal authenticates from two distinct geographic locations within a 60-minute window, and 2) Administrative modifications to a service principal's credentials or authentication methods (e.g., adding secrets, certificates, or MFA methods), which may indicate persistence or credential abuse.