PA-08: Risky Service Principal Detection
Frequently asked questions about implementing and managing the PA-08 security control in Microsoft 365 and Entra ID.
QWhat is PA-08 (Risky Service Principal Detection)?▼
PA-08 is a security control that compromised service principals provide persistent, automated access to your tenant. unlike user accounts, service principals operate without mfa and can perform actions at scale. detecting risky service principals is critical for preventing supply chain attacks. It requires that identity protection monitors service principal risk and no medium or high-risk service principals are active, compromised service principals are investigated and disabled promptly.
QWhy is Risky Service Principal Detection important for Microsoft 365 security?▼
Compromised service principals provide persistent, automated access to your tenant. Unlike user accounts, service principals operate without MFA and can perform actions at scale. Detecting risky service principals is critical for preventing supply chain attacks.
QHow do I implement PA-08 in my tenant?▼
Can disable compromised service principals. Requires Workload Identities Premium.
QWhat license do I need for PA-08?▼
This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.
QWhich security baseline includes PA-08?▼
PA-08 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
QWhy is PA-08 marked as critical severity?▼
PA-08 is rated critical because failure to implement this control significantly increases the risk of security incidents. Compromised service principals provide persistent, automated access to your tenant. Unlike user accounts, service principals operate without MFA and can perform actions at scale. Detecting risky service principals is critical for preventing supply chain attacks.
6
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial