2026 Critical Cloud Identity Detection: Anomalous Certificate Credential Added t

Detects the addition of certificate-type credentials (AsymmetricX509Cert, usage=Verify) to Microsoft Entra ID (Azure AD) applications or service principals. This behavior is indicative of an attacker adding an adversary-controlled certificate to impersonate an application or service principal to achieve persistent, long-lived access.