EIDAPP-017: Service Principal Sign-In Activity
- Platform
- Entra ID / M365
- Category
- Consent
- Severity
- Info
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 2
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Monitoring service principal sign-in activity provides visibility into which applications are actively authenticating and from which IP addresses. Unusual sign-in patterns such as authentication from unexpected geographic locations, abnormal request volumes, or sign-ins from applications that should be dormant can indicate credential compromise or unauthorized use. This baseline activity data is essential for detecting anomalies and investigating incidents.
Recommended value
Service principal sign-in logs reviewed regularly with baseline activity profiles established for critical applications
Remediation
Review service principal sign-in logs in Entra ID > Monitoring > Sign-in logs > Service principal sign-ins. Establish baseline activity profiles for critical applications including normal authentication frequency, source IP ranges, and target resources. Configure alerts for anomalous service principal sign-in patterns such as authentication from new IP addresses, unusual time-of-day activity, or sign-ins from applications that have been dormant.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- AU-6