Risky service principal log triggering

Aqil Isayev 0 Reputation points
2025-02-05T14:13:08.4433333+00:00

I have enabled diagnostic settings for RiskyServicePrincipals and ServicePrincipalRiskEvents in Microsoft Entra ID and set up logs to flow both storage account and event hub. I want to have an example log for these types of logs, tried multiple ways ex:

  1. Flood of successful and failure requests using service principal.
  2. Sending requests from different IP's(very distant) in a short time period.
  3. Marking service principal as compromised and confirming/dismissing multiple times in https://entra.microsoft.com/

Which none of these generated either one of these logs. What could be other options to achieve this, any manual way or action to trigger it

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,112 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.