2026 Critical Cloud Identity Detection: Anomalous Certificate Credential Added t
Detects the addition of certificate-type credentials (AsymmetricX509Cert, usage=Verify) to Microsoft Entra ID (Azure AD) applications or service principals. This behavior is indicative of an attacker adding an adversary-controlled certificate to impersonate an application or service principal to achieve persistent, long-lived access.
Microsoft Sentinel (KQL)

