Service Principal Added to Role-Assignable Admin Group
Detects the addition of a Service Principal to an Azure AD group that has the 'isAssignableToRole' property set to true. This behavior is a known privilege escalation technique where the service principal inherits the privileged roles assigned to that group, bypassing standard direct role-assignment monitoring.
Microsoft Sentinel (KQL)

