2026 Critical Cloud Control Plane Detection: Azure AD App/Service Principal Credential Addition

Detects modifications to application secrets or certificates in Azure that are performed by a user who is not the registered owner of the application, or when a new credential is added to an application that already has credentials configured, potentially indicating persistent access establishment.