Enterprise Application or Service Principal Granted Privileged Directory Role
Detects when a high-privileged administrative role is assigned to an Azure Service Principal. This technique is often used for persistent, stealthy control over a tenant, as service principals are not subjected to user-centric access reviews or MFA challenges. The rule triggers on both permanent and PIM-eligible role assignments.
Microsoft Sentinel (KQL)

