Entra ID Service Principal Federated Identity Credential Added
Detects when a new federated identity credential is successfully added to an Azure Active Directory (Entra ID) application. This activity is a common method for attackers to establish persistent access to cloud resources by bypassing password-based authentication.
Microsoft Sentinel (KQL)

