service_principal_risk_detections
Creates, updates, deletes, gets or lists a service_principal_risk_detections resource.
Overview
| Name | service_principal_risk_detections |
| Type | Resource |
| Id | entra_id.identity_protection.service_principal_risk_detections |
Fields
The following fields are returned by SELECT queries:
- get
- list
Retrieved navigation property
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
activity | | Indicates the activity type the detected risk is linked to. |
activityDateTime | string (date-time) | Date and time when the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
additionalInfo | string | Additional information associated with the risk detection. This string value is represented as a JSON object with the quotations escaped. |
appId | string | The unique identifier for the associated application. |
correlationId | string | Correlation ID of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. |
detectedDateTime | string (date-time) | Date and time when the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
detectionTimingType | | Timing of the detected risk , whether real-time or offline. The possible values are: notDefined, realtime, nearRealtime, offline, unknownFutureValue. |
ipAddress | string | Provides the IP address of the client from where the risk occurred. |
keyIds | array | The unique identifier for the key credential associated with the risk detection. |
lastUpdatedDateTime | string (date-time) | Date and time when the risk detection was last updated. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
location | | Location from where the sign-in was initiated. |
requestId | string | Request identifier of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. Supports $filter (eq). |
riskDetail | | Details of the detected risk. Note: Details for this property are only available for Workload Identities Premium customers. Events in tenants without this license will be returned hidden. |
riskEventType | string | The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication. |
riskLevel | | Level of the detected risk. Note: Details for this property are only available for Workload Identities Premium customers. Events in tenants without this license will be returned hidden. The possible values are: low, medium, high, hidden, none. |
riskState | | The state of a detected risky service principal or sign-in activity. The possible values are: none, dismissed, atRisk, confirmedCompromised. |
servicePrincipalDisplayName | string | The display name for the service principal. |
servicePrincipalId | string | The unique identifier for the service principal. Supports $filter (eq). |
source | string | Source of the risk detection. For example, identityProtection. |
tokenIssuerType | | Indicates the type of token issuer for the detected sign-in risk. The possible values are: AzureAD. |
Retrieved collection
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier for an entity. Read-only. |
activity | | Indicates the activity type the detected risk is linked to. |
activityDateTime | string (date-time) | Date and time when the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
additionalInfo | string | Additional information associated with the risk detection. This string value is represented as a JSON object with the quotations escaped. |
appId | string | The unique identifier for the associated application. |
correlationId | string | Correlation ID of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. |
detectedDateTime | string (date-time) | Date and time when the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
detectionTimingType | | Timing of the detected risk , whether real-time or offline. The possible values are: notDefined, realtime, nearRealtime, offline, unknownFutureValue. |
ipAddress | string | Provides the IP address of the client from where the risk occurred. |
keyIds | array | The unique identifier for the key credential associated with the risk detection. |
lastUpdatedDateTime | string (date-time) | Date and time when the risk detection was last updated. (pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$) |
location | | Location from where the sign-in was initiated. |
requestId | string | Request identifier of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. Supports $filter (eq). |
riskDetail | | Details of the detected risk. Note: Details for this property are only available for Workload Identities Premium customers. Events in tenants without this license will be returned hidden. |
riskEventType | string | The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication. |
riskLevel | | Level of the detected risk. Note: Details for this property are only available for Workload Identities Premium customers. Events in tenants without this license will be returned hidden. The possible values are: low, medium, high, hidden, none. |
riskState | | The state of a detected risky service principal or sign-in activity. The possible values are: none, dismissed, atRisk, confirmedCompromised. |
servicePrincipalDisplayName | string | The display name for the service principal. |
servicePrincipalId | string | The unique identifier for the service principal. Supports $filter (eq). |
source | string | Source of the risk detection. For example, identityProtection. |
tokenIssuerType | | Indicates the type of token issuer for the detected sign-in risk. The possible values are: AzureAD. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | service_principal_risk_detection_id | Read the properties and relationships of a servicePrincipalRiskDetection object. | |
list | select | Retrieve the properties of a collection of servicePrincipalRiskDetection objects. | ||
insert | insert | |||
update | update | service_principal_risk_detection_id | ||
delete | delete | service_principal_risk_detection_id | If-Match |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
service_principal_risk_detection_id | string | The unique identifier of servicePrincipalRiskDetection |
If-Match | string | ETag |
SELECT examples
- get
- list
Read the properties and relationships of a servicePrincipalRiskDetection object.
SELECT
id,
activity,
activityDateTime,
additionalInfo,
appId,
correlationId,
detectedDateTime,
detectionTimingType,
ipAddress,
keyIds,
lastUpdatedDateTime,
location,
requestId,
riskDetail,
riskEventType,
riskLevel,
riskState,
servicePrincipalDisplayName,
servicePrincipalId,
source,
tokenIssuerType
FROM entra_id.identity_protection.service_principal_risk_detections
WHERE service_principal_risk_detection_id = '{{ service_principal_risk_detection_id }}' -- required
;
Retrieve the properties of a collection of servicePrincipalRiskDetection objects.
SELECT
id,
activity,
activityDateTime,
additionalInfo,
appId,
correlationId,
detectedDateTime,
detectionTimingType,
ipAddress,
keyIds,
lastUpdatedDateTime,
location,
requestId,
riskDetail,
riskEventType,
riskLevel,
riskState,
servicePrincipalDisplayName,
servicePrincipalId,
source,
tokenIssuerType
FROM entra_id.identity_protection.service_principal_risk_detections
;
INSERT examples
- insert
- Manifest
No description available.
INSERT INTO entra_id.identity_protection.service_principal_risk_detections (
id,
activity,
activityDateTime,
additionalInfo,
appId,
correlationId,
detectedDateTime,
detectionTimingType,
ipAddress,
keyIds,
lastUpdatedDateTime,
location,
requestId,
riskDetail,
riskEventType,
riskLevel,
riskState,
servicePrincipalDisplayName,
servicePrincipalId,
source,
tokenIssuerType
)
SELECT
'{{ id }}',
'{{ activity }}',
'{{ activityDateTime }}',
'{{ additionalInfo }}',
'{{ appId }}',
'{{ correlationId }}',
'{{ detectedDateTime }}',
'{{ detectionTimingType }}',
'{{ ipAddress }}',
'{{ keyIds }}',
'{{ lastUpdatedDateTime }}',
'{{ location }}',
'{{ requestId }}',
'{{ riskDetail }}',
'{{ riskEventType }}',
'{{ riskLevel }}',
'{{ riskState }}',
'{{ servicePrincipalDisplayName }}',
'{{ servicePrincipalId }}',
'{{ source }}',
'{{ tokenIssuerType }}'
RETURNING
id,
activity,
activityDateTime,
additionalInfo,
appId,
correlationId,
detectedDateTime,
detectionTimingType,
ipAddress,
keyIds,
lastUpdatedDateTime,
location,
requestId,
riskDetail,
riskEventType,
riskLevel,
riskState,
servicePrincipalDisplayName,
servicePrincipalId,
source,
tokenIssuerType
;
# Description fields are for documentation purposes
- name: service_principal_risk_detections
props:
- name: id
value: "{{ id }}"
description: |
The unique identifier for an entity. Read-only.
- name: activity
value: "{{ activity }}"
description: |
Indicates the activity type the detected risk is linked to.
- name: activityDateTime
value: "{{ activityDateTime }}"
description: |
Date and time when the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z
- name: additionalInfo
value: "{{ additionalInfo }}"
description: |
Additional information associated with the risk detection. This string value is represented as a JSON object with the quotations escaped.
- name: appId
value: "{{ appId }}"
description: |
The unique identifier for the associated application.
- name: correlationId
value: "{{ correlationId }}"
description: |
Correlation ID of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity.
- name: detectedDateTime
value: "{{ detectedDateTime }}"
description: |
Date and time when the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
- name: detectionTimingType
value: "{{ detectionTimingType }}"
description: |
Timing of the detected risk , whether real-time or offline. The possible values are: notDefined, realtime, nearRealtime, offline, unknownFutureValue.
- name: ipAddress
value: "{{ ipAddress }}"
description: |
Provides the IP address of the client from where the risk occurred.
- name: keyIds
value:
- "{{ keyIds }}"
description: |
The unique identifier for the key credential associated with the risk detection.
- name: lastUpdatedDateTime
value: "{{ lastUpdatedDateTime }}"
description: |
Date and time when the risk detection was last updated.
- name: location
value: "{{ location }}"
description: |
Location from where the sign-in was initiated.
- name: requestId
value: "{{ requestId }}"
description: |
Request identifier of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. Supports $filter (eq).
- name: riskDetail
value: "{{ riskDetail }}"
description: |
Details of the detected risk. Note: Details for this property are only available for Workload Identities Premium customers. Events in tenants without this license will be returned hidden.
- name: riskEventType
value: "{{ riskEventType }}"
description: |
The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.
- name: riskLevel
value: "{{ riskLevel }}"
description: |
Level of the detected risk. Note: Details for this property are only available for Workload Identities Premium customers. Events in tenants without this license will be returned hidden. The possible values are: low, medium, high, hidden, none.
- name: riskState
value: "{{ riskState }}"
description: |
The state of a detected risky service principal or sign-in activity. The possible values are: none, dismissed, atRisk, confirmedCompromised.
- name: servicePrincipalDisplayName
value: "{{ servicePrincipalDisplayName }}"
description: |
The display name for the service principal.
- name: servicePrincipalId
value: "{{ servicePrincipalId }}"
description: |
The unique identifier for the service principal. Supports $filter (eq).
- name: source
value: "{{ source }}"
description: |
Source of the risk detection. For example, identityProtection.
- name: tokenIssuerType
value: "{{ tokenIssuerType }}"
description: |
Indicates the type of token issuer for the detected sign-in risk. The possible values are: AzureAD.
UPDATE examples
- update
No description available.
UPDATE entra_id.identity_protection.service_principal_risk_detections
SET
id = '{{ id }}',
activity = '{{ activity }}',
activityDateTime = '{{ activityDateTime }}',
additionalInfo = '{{ additionalInfo }}',
appId = '{{ appId }}',
correlationId = '{{ correlationId }}',
detectedDateTime = '{{ detectedDateTime }}',
detectionTimingType = '{{ detectionTimingType }}',
ipAddress = '{{ ipAddress }}',
keyIds = '{{ keyIds }}',
lastUpdatedDateTime = '{{ lastUpdatedDateTime }}',
location = '{{ location }}',
requestId = '{{ requestId }}',
riskDetail = '{{ riskDetail }}',
riskEventType = '{{ riskEventType }}',
riskLevel = '{{ riskLevel }}',
riskState = '{{ riskState }}',
servicePrincipalDisplayName = '{{ servicePrincipalDisplayName }}',
servicePrincipalId = '{{ servicePrincipalId }}',
source = '{{ source }}',
tokenIssuerType = '{{ tokenIssuerType }}'
WHERE
service_principal_risk_detection_id = '{{ service_principal_risk_detection_id }}' --required
RETURNING
id,
activity,
activityDateTime,
additionalInfo,
appId,
correlationId,
detectedDateTime,
detectionTimingType,
ipAddress,
keyIds,
lastUpdatedDateTime,
location,
requestId,
riskDetail,
riskEventType,
riskLevel,
riskState,
servicePrincipalDisplayName,
servicePrincipalId,
source,
tokenIssuerType;
DELETE examples
- delete
No description available.
DELETE FROM entra_id.identity_protection.service_principal_risk_detections
WHERE service_principal_risk_detection_id = '{{ service_principal_risk_detection_id }}' --required
AND If-Match = '{{ If-Match }}'
;