SP Credential Added by Non-Owner or Outside Business Hours

Detects the addition of secrets or certificates to service principals by identities that are not currently registered as owners of those applications, or modifications occurring outside of standard business hours. This behavior is often indicative of an adversary with compromised administrative privileges (e.g., Application Administrator) attempting to establish persistent, lateral access without alerting legitimate application owners.