EIDAPP-017: Service Principal Sign-In Activity

Platform
Entra ID / M365
Category
Consent
Severity
Info
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
2
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Monitoring service principal sign-in activity provides visibility into which applications are actively authenticating and from which IP addresses. Unusual sign-in patterns such as authentication from unexpected geographic locations, abnormal request volumes, or sign-ins from applications that should be dormant can indicate credential compromise or unauthorized use. This baseline activity data is essential for detecting anomalies and investigating incidents.

Recommended value

Service principal sign-in logs reviewed regularly with baseline activity profiles established for critical applications

Remediation

Review service principal sign-in logs in Entra ID > Monitoring > Sign-in logs > Service principal sign-ins. Establish baseline activity profiles for critical applications including normal authentication frequency, source IP ranges, and target resources. Configure alerts for anomalous service principal sign-in patterns such as authentication from new IP addresses, unusual time-of-day activity, or sign-ins from applications that have been dormant.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDAPP-017
ScenarioExpected verdict
cleanPASS
no-dataNot Assessed

Framework mappings

NIST SP 800-53
AU-6