Service Principal
A service principal is the identity an application or automated workload uses to sign in to Microsoft Entra ID and access Azure or Microsoft Graph resources: the instance of an app registration inside a specific tenant.
Service principals authenticate with a client secret, a certificate, or a federated credential, and receive permissions through Azure role assignments and Microsoft Graph application permissions. Managed identities are a special kind of service principal whose credentials Azure creates and rotates, so there is no secret to leak. The recurring problems are the ones common to every non-human identity: client secrets copied into code, tickets and chat, broad roles such as Contributor granted at subscription scope for convenience, and no named owner to review them. In September 2026, Microsoft described an attacker using a service principal whose secret appeared in a public GitHub issue to delete recovery locks and destroy Azure resources in seven minutes.
See also: workload identity, workload identity federation, client credentials, Microsoft Entra
Related on Start with Identity
- GlossaryService Account
A non-human account used by an application or service to authenticate. Often over-permissioned and rarely rotated, making service accounts a frequent breach vec
- GlossaryAgentic Identity
Identity for autonomous AI agents that act on a user's behalf, call APIs, and chain tools. Requires scoped, delegated, auditable, and revocable credentials rath
- GlossaryAPI Key
A static secret string used to authenticate an application or caller to an API. Simple but weak: it does not expire on its own, is easy to leak, and should be v
- BlogA password-spraying campaign across 5,700 accounts found its way in through seven service accounts on default passwords
Proofpoint tracked a TeamFiltration campaign against 28 Microsoft 365 tenants in Chile. It sprayed more than 5,700 accounts and compromised seven, every one an
- BlogA service sold 153 million driver's licenses scraped from an identity verification vendor
Nexus, advertised on a Russian cybercrime forum, sold access to more than 153 million US and Canadian driver's licenses that its operators say they exfiltrated
- CVEKeycloak TLS 1.2 renegotiation denial of service
Keycloak could be knocked over by TLS 1.2 renegotiation. Availability of the IdP is an identity incident. Not an auth bypass.