LoFP LoFP / service principal removed from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

Azure Service Principal Removed

Description

Identifies when a service principal was removed in Azure.

Detection logic

condition: selection
selection:
  properties.message: Remove service principal