Service Principal Assigned to Privileged Azure AD Directory Role

Detects when a Service Principal is assigned to a highly privileged administrative role in Azure Active Directory (Entra ID). This activity can be an indicator of an adversary establishing persistence or escalating privileges by leveraging non-human identities.