2026 Critical Enterprise Intrusion Chain Detection: Service Principal Credential Addition for Cloud Persistence
Detects the addition of a new client secret or certificate to an application or service principal by a user account. This activity is correlated with recent high-risk or suspicious sign-in events. Adversaries often perform this action following account takeover to establish durable, MFA-immune persistence in the cloud tenant.
Microsoft Sentinel (KQL)

