2026 Critical Cloud Identity Detection: Privileged Directory Role Assigned to Service Principal
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
YARA-L

