Keys to the Azure Kingdom: Detecting Service Principal Abuse

No ratings

Presented at RSAC 2025 by

New advanced Azure attacks (e.g. Blizzard) abuse OAuth and managed identities, which use underlying service principals to gain persistence and privilege escalation. We'll review a design-based approach to better detection and lockdown including custom roles, conditional access, signed changes, and low-FP detection rules to mitigate service principal abuse common to these rapidly evolving attacks.