Microsoft.Directory/servicePrincipals/credentials/update
Microsoft.Directory/servicePrincipals/credentials/update
Event
The title is a directory permission. The illustrated audit activity is Add service principal credentials, targeting a ServicePrincipal object. Application registration credentials and service-principal credentials are separate object changes; ownership of one should not be assumed to establish authority over the other.
Security Context
Unauthorized additional credentials can support persistent access (T1098.001), subject to effective permissions, credential expiry, and authentication policies. Creating a credential does not itself grant additional application permissions.
Log Source
Microsoft Entra directory audit logs, illustrated with activityDisplayName: Add service principal credentials. The catalog title is a permission label. Match target IDs and result; Graph-style JSON and Azure Monitor exports use different wrappers and casing.
Key Fields
| Field | Investigation value |
|---|---|
activityDisplayName, result | Recorded activity and outcome. |
initiatedBy, correlationId | Initiating identity and related changes. |
targetResources | Target object type and ID; distinguish applications from service principals. |
targetResources[].modifiedProperties | Illustrative prior/new values; exact serialization needs captured-log validation. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm the target service-principal object ID, initiating authority, and approved credential rotation.
- Inspect credential type, key ID, validity, and previous/new credential inventory; avoid exposing secret values.
- Correlate service-principal sign-ins, effective grants, and resource use; do not assume the new credential was used.
Sample Event
Synthetic scenario. The sample adds a password credential to the Phoenix-Backup service principal. KeyDescription is illustrative metadata; no secret value, expiration, or subsequent authentication is shown.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000011001100_5E2F8_91029384", "category": "ApplicationManagement", "correlationId": "90000000-0000-4000-8000-000011001100", "result": "success", "resultReason": "", "activityDisplayName": "Add service principal credentials", "activityDateTime": "2026-04-15T19:18:32.7038714Z", "loggedByService": "Core Directory", "operationType": "Add", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "40000000-0000-4000-8000-000000000010", "displayName": "Phoenix-Backup", "type": "ServicePrincipal", "userPrincipalName": null, "modifiedProperties": [ { "displayName": "KeyDescription", "oldValue": "[]", "newValue": "[\"KeyIdentifier=60000000-0000-4000-8000-000011001101,KeyType=Password,KeyUsage=Verify,DisplayName=BackupRotation2026\"]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"KeyDescription\"" } ] } ], "additionalDetails": [ { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.