How to Audit Service Principal and App Registration Credentials in Entra ID
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.
Step 1: Inventory high-privilege applications
List applications with application permissions such as:
- Microsoft Graph:
Mail.Read,Mail.ReadWrite,Files.Read.All,Sites.FullControl.All,Directory.ReadWrite.All,RoleManagement.ReadWrite.Directory,AppRoleAssignment.ReadWrite.All. - Exchange:
full_access_as_app.
Microsoft Graph PowerShell, the Entra admin center, Defender for Cloud Apps app governance and Microsoft's Zero Trust Assessment can all help produce this list.
Step 2: Review credentials
For each app:
- How many secrets and certificates exist?
- When do they expire? (Long-lived secrets are risky.)
- When was each added, and by whom?
Remove unused credentials; replace secrets with certificates or, for Azure-hosted workloads, managed identities.
Step 3: Assign owners
Every app should have a business and technical owner. Apps with no owner and no recent sign-ins are candidates for removal.
Step 4: Restrict who can manage apps
Limit the Application Administrator and Cloud Application Administrator roles, manage them with PIM, and consider app instance property lock and app management policies to restrict credential types and lifetimes.
Step 5: Scope permissions
For mail access, use Exchange RBAC for Applications or application access policies to restrict apps to specific mailboxes.
Step 6: Monitor
Alert on credential additions to high-privilege apps and new app role assignments.
Verify
Repeat quarterly. Track: number of high-privilege apps, apps with secrets older than a year, apps without owners.