Service Principals CloudConsoleGrapApi with Global Admin role

AH 25 Reputation points
2024-07-15T20:07:35.12+00:00

Hi,

I'm doing review on Microsoft Entra and notice several service principals named "CloudConsoleGrapApi" with Global Administrator role. Looking at their activity but found nothing for months.

Any idea what are these service principals and how they end up having Global Admin role?

Thank you in advance.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,465 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 144.8K Reputation points MVP
    2024-07-15T20:28:05.65+00:00

  2. Luis Arias 5,981 Reputation points
    2024-07-15T20:53:45.5033333+00:00

    Hi AH,

    It looks like you have an third party integration that is causing that Service Principal creation with that specific role I suggest to check the activity log for the account that have the Global Administrator role because only with that role you can assign that high privileged role.

    References:

    If the information helped address your question, please Accept the answer.

    Luis

    0 comments No comments