PA-08Moderate

How to Fix: Risky Service Principal Detection

Step-by-step guide to implement risky service principal detection in your Microsoft 365 environment.

5-10 minutes

Estimated Time

4

Steps

critical

Severity

Enhanced Security

Baseline Level

Why This Matters

Compromised service principals provide persistent, automated access to your tenant. Unlike user accounts, service principals operate without MFA and can perform actions at scale. Detecting risky service principals is critical for preventing supply chain attacks.

Prerequisites

  • 1Global Administrator or appropriate admin role in Microsoft Entra ID
  • 2Access to Microsoft Entra admin center (entra.microsoft.com)
  • 3Microsoft Entra ID P1 or higher license
  • 4Privileged Role Administrator role

Expected Configuration

  • Identity Protection monitors service principal risk
  • No medium or high-risk service principals are active
  • Compromised service principals are investigated and disabled promptly

Remediation Steps

1

Review Current State

Assess your current privileged access configuration in Entra ID.

  • Navigate to Microsoft Entra admin center
  • Go to Identity > Roles and administrators
  • Review current role assignments
2

Plan Changes

Determine what changes need to be made to meet the expected configuration.

  • Identify users with excessive privileges
  • Document required role assignments
  • Plan implementation timeline
3

Implement Configuration

Apply the necessary changes to your Entra ID environment.

  • Configure PIM if applicable
  • Update role assignments
  • Set appropriate access reviews
4

Verify and Test

Confirm the changes are working as expected.

  • Run a TrueConfig scan to verify compliance
  • Test user access with affected accounts
  • Document the changes made

Auto-Remediation Available

TrueConfig can automatically fix this control for you. Enable auto-remediation to have this configuration applied and maintained automatically.

Learn about auto-remediation

Related Resources

Automate Your Security Configuration

TrueConfig continuously monitors your Microsoft 365 environment and can automatically fix configuration drift. Start your free trial today.

Start Free Trial