2026 Critical Cloud Identity Detection: Service Principal Sign-In from Unusual C

Detects anomalous sign-in activity for Azure Service Principals by comparing the current source IP/ASN and country against a 30-day historical baseline. This alert identifies potentially compromised service principals, where attackers exfiltrate secrets or certificates and attempt to authenticate from their own infrastructure.