New Owner Added to Enterprise App or Service Principal
Detects when a user is added as an owner to an Azure AD Application or Service Principal, specifically highlighting instances where the new owner does not currently hold a privileged directory role. This pattern is often used as a persistence mechanism to maintain long-term access to an environment without requiring high-level administrative credentials.
Microsoft Sentinel (KQL)

