Service principals do not use interactive MFA. Long-lived secrets and orphaned apps create quiet persistence paths.
Preface
Non-human identities are powerful programmatic gateways into Azure and directory APIs. Their credentials need a strict lifecycle.
Problem
Credential drift leaves abandoned service principals with high privileges and multi-year secrets. Compromises rarely trigger user-focused alerts because the activity is non-interactive.
Solution
Align with NIST SP 800-162:
- Limit secret lifetimes to a maximum of about 3 months.
- Run continuous access reviews of service principal permissions.
- Alert on credential additions to existing application objects.
PowerShell: Find Long-Lived Secrets
Connect-MgGraph -Scopes "Application.Read.All"
$apps = Get-MgApplication -All
foreach ($app in $apps) {
foreach ($password in $app.PasswordCredentials) {
if ($password.EndDateTime -gt (Get-Date).AddYears(1)) {
[PSCustomObject]@{
AppName = $app.DisplayName
AppId = $app.AppId
SecretId = $password.KeyId
Expiration = $password.EndDateTime
}
}
}
}