ServicePrincipalRiskDetections
Returns risk detections associated with service principals, including detection type, risk level, activity, and location details.
View-Specific Information
SELECT
SELECT * FROM ServicePrincipalRiskDetections
Note: Querying this view requires additional scopes than the default. In order to access this view, you must have the IdentityRiskEvent.Read.All permission and the signed-in user must be assigned a supported Microsoft Entra ID role or a custom role with a supported role permission of Global Reader, Security Operator, Security Reader, or Security Administrator.
Columns
| Name | Type | Description |
| id [KEY] | String | The unique identifier for the service principal risk detection. |
| activity | String | The type of activity associated with the risk detection. |
| activityDateTime | Datetime | The date and time when the activity associated with the risk detection occurred. |
| additionalInfo | String | Additional information related to the risk detection. |
| appId | String | The unique identifier of the application associated with the service principal. |
| correlationId | String | The correlation identifier that links the risk detection to a specific sign-in activity. |
| detectedDateTime | Datetime | The date and time when the risk was detected. |
| detectionTimingType | String | The timing of the risk detection, indicating whether it was detected in real time or offline. |
| ipAddress | String | The IP address of the client from which the risk occurred. |
| keyIds | String | The identifiers of the keys associated with the risk detection. |
| lastUpdatedDateTime | Datetime | The date and time when the risk detection was last updated. |
| location_city | String | The city in which the risk detection occurred. |
| location_countryOrRegion | String | The country or region in which the risk detection occurred. |
| location_geoCoordinates_altitude | Double | The altitude of the location, in meters, where the risk detection occurred. |
| location_geoCoordinates_latitude | Double | The latitude of the location where the risk detection occurred. |
| location_geoCoordinates_longitude | Double | The longitude of the location where the risk detection occurred. |
| location_state | String | The state or province in which the risk detection occurred. |
| requestId | String | The identifier of the request associated with the risk detection. |
| riskDetail | String | The detail providing further information about the risk detection. |
| riskEventType | String | The type of risk event detected. |
| riskLevel | String | The level of risk associated with the detection, such as low, medium, or high. |
| riskState | String | The state of the reported risk, such as atRisk, confirmedSafe, or remediated. |
| servicePrincipalDisplayName | String | The display name of the service principal associated with the risk detection. |
| servicePrincipalId | String | The unique identifier of the service principal associated with the risk detection. |
| source | String | The source of the risk detection. |
| tokenIssuerType | String | The type of token issuer for the detected risk. |