Service principals do not use interactive MFA. Long-lived secrets and orphaned apps create quiet persistence paths.

Preface

Non-human identities are powerful programmatic gateways into Azure and directory APIs. Their credentials need a strict lifecycle.

Problem

Credential drift leaves abandoned service principals with high privileges and multi-year secrets. Compromises rarely trigger user-focused alerts because the activity is non-interactive.

Solution

Align with NIST SP 800-162:

  1. Limit secret lifetimes to a maximum of about 3 months.
  2. Run continuous access reviews of service principal permissions.
  3. Alert on credential additions to existing application objects.

PowerShell: Find Long-Lived Secrets

Connect-MgGraph -Scopes "Application.Read.All"
$apps = Get-MgApplication -All
foreach ($app in $apps) {
    foreach ($password in $app.PasswordCredentials) {
        if ($password.EndDateTime -gt (Get-Date).AddYears(1)) {
            [PSCustomObject]@{
                AppName = $app.DisplayName
                AppId = $app.AppId
                SecretId = $password.KeyId
                Expiration = $password.EndDateTime
            }
        }
    }
}