RiskyServicePrincipals
Returns service principals flagged as risky by identity protection, including risk level, risk state, and processing status.
View-Specific Information
SELECT
SELECT * FROM RiskyServicePrincipals
Note: Querying this view requires additional scopes than the default. In order to access this view, you must have the IdentityRiskyServicePrincipal.Read.All permission and the signed-in user must be assigned a supported Microsoft Entra ID role or a custom role with a supported role permission of Global Reader, Security Operator, Security Reader, or Security Administrator.
Columns
| Name | Type | Description |
| id [KEY] | String | The unique identifier for the risky service principal. |
| appId | String | The unique identifier of the application associated with the service principal. |
| displayName | String | The display name of the service principal. |
| isEnabled | Bool | Indicates whether the service principal account is enabled. |
| isProcessing | Bool | Indicates whether the risk state of the service principal is currently being processed. |
| riskDetail | String | The detail providing further information about the risk associated with the service principal. |
| riskLastUpdatedDateTime | Datetime | The date and time when the risk state of the service principal was last updated. |
| riskLevel | String | The level of risk associated with the service principal, such as low, medium, or high. |
| riskState | String | The state of the reported risk for the service principal, such as atRisk, confirmedSafe, or remediated. |
| servicePrincipalType | String | The type of the service principal. |