Perhaps:
Service Principals CloudConsoleGrapApi with Global Admin role
Hi,
I'm doing review on Microsoft Entra and notice several service principals named "CloudConsoleGrapApi" with Global Administrator role. Looking at their activity but found nothing for months.
Any idea what are these service principals and how they end up having Global Admin role?
Thank you in advance.
2 answers
Sort by: Most helpful
-
-
Luis Arias 5,981 Reputation points
2024-07-15T20:53:45.5033333+00:00 Hi AH,
It looks like you have an third party integration that is causing that Service Principal creation with that specific role I suggest to check the activity log for the account that have the Global Administrator role because only with that role you can assign that high privileged role.
References:
- https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/assign-admin-roles?view=o365-worldwide
- https://learn.microsoft.com/en-us/answers/questions/1458056/i-see-a-few-enterprise-applications-named-cloudcon
- https://www.reddit.com/r/AZURE/comments/141f5y0/service_principal_accounts_with_admin_rights/
If the information helped address your question, please Accept the answer.
Luis