Start with Identity
Concept

Service Principal

A service principal is the identity an application or automated workload uses to sign in to Microsoft Entra ID and access Azure or Microsoft Graph resources: the instance of an app registration inside a specific tenant.

Service principals authenticate with a client secret, a certificate, or a federated credential, and receive permissions through Azure role assignments and Microsoft Graph application permissions. Managed identities are a special kind of service principal whose credentials Azure creates and rotates, so there is no secret to leak. The recurring problems are the ones common to every non-human identity: client secrets copied into code, tickets and chat, broad roles such as Contributor granted at subscription scope for convenience, and no named owner to review them. In September 2026, Microsoft described an attacker using a service principal whose secret appeared in a public GitHub issue to delete recovery locks and destroy Azure resources in seven minutes.

See also: workload identity, workload identity federation, client credentials, Microsoft Entra

Last reviewed By SWI Community TeamSuggest a correctionHow we research