2026 Critical Cloud Identity Detection: Delegated Admin Privilege (GDAP/DAP) Abuse via Partner Tenant Service Principal
Detects the creation or modification of Granular Delegated Administrative Privileges (GDAP) relationships, or the assignment of highly privileged (Tier 0) roles, when performed by an application identified as a partner provider or via delegated administration. This rule monitors for potential abuse of trusted partner relationships to escalate privileges or establish persistence within a tenant.
Microsoft Sentinel (KQL)

