Federated Identity Credential Added to Service Principal
Detects the creation or modification of federated identity credentials within Azure Active Directory (Entra ID). This technique allows external services like GitHub Actions, Kubernetes, or other identity providers to authenticate as an application without stored secrets, bypassing traditional secret-rotation and credential-scanning security controls. The rule identifies potential unauthorized persistence by highlighting external or unrecognized issuers.
Microsoft Sentinel (KQL)

