riskyServicePrincipal: confirmCompromised

Namespace: microsoft.graph

Confirm one or more riskyServicePrincipal objects as compromised. This action sets the targeted service principal account's risk level to high.

Note: Using the riskyServicePrincipal API requires an Entra Workload Identity Premium license.


One of the following permissions is required to call this API. To learn more, including how to choose permissions, see Permissions.

Permission type Permissions (from least to most privileged)
Delegated (work or school account) IdentityRiskyServicePrincipal.ReadWrite.All
Delegated (personal Microsoft account) Not supported.
Application IdentityRiskyServicePrincipal.ReadWrite.All

For delegated scenarios, the signed-in user must have one of the following Azure AD roles.

  • Security Administrator
  • Global Administrator

HTTP request

POST /identityProtection/riskyServicePrincipals/confirmCompromised

Request headers

Name Description
Authorization Bearer {token}. Required.

Request body

In the request body, specify the collection of ids of the risky service principals in a servicePrincipalIds property.


If successful, this action returns a 204 No Content response code. It does not return anything in the response body.



POST https://graph.microsoft.com/v1.0/identityProtection/riskyServicePrincipals/confirmCompromised
Content-Type: application/json

  "servicePrincipalIds": [


The following is an example of the response.

HTTP/1.1 204 No Content