2026 Critical Enterprise Intrusion Chain Detection: New Service Principal or App Registration Credential Added by Recently Compromised Identity

Detects instances where a risky Azure AD sign-in (e.g., token replay or confirmed compromise) is closely followed (within 24 hours) by sensitive application or service principal credential modifications by the same user account. This behavior is indicative of potential persistence establishment via account manipulation.