2026 Critical Cloud Identity Detection: Admin-Consent Grant of High-Privilege Graph App Permission to Service Principal
Detects when high-privilege application permissions (e.g., Directory.ReadWrite.All, Application.ReadWrite.All) are granted to a service principal via admin consent. This behavior can be used by attackers to gain persistent, stealthy administrative access to a Microsoft Entra ID tenant.
Cortex XDR

