Service principals often hold elevated permissions and are a common target for attackers. If they are misused or left unmanaged they can create serious security risks. Blocking sign-ins from unused or suspicious applications reduces the attack surface. This ensures only trusted apps access the organization's resources.
Below are some effective ways to control service principal sign-ins in Microsoft 365.
- Log in to the Microsoft Entra admin center and navigate to Entra ID » Enterprise apps.
- Click the service principal you want to restrict and go to Properties under the Manage tab.
- Set Enabled for users to sign-in? to No, and click Save to disable user sign-ins to the application.
Note:Disabling user sign-in for a service principal application only blocks delegated access. It does not block application access via client secret, certificate-based authentication (CBA), or managed identity.
While the previous method completely blocks service principal access, Conditional Access policy gives you more control. You can restrict sign-ins based on specific conditions like location, network, risk level, and more. This ensures legitimate access is allowed while blocking unusual or risky sign-in attempts.
Follow the steps below to create a Conditional Access policy for service principals in Microsoft 365(requires Microsoft Entra ID P1 or P2 license).
- Log in to the Microsoft Entra admin center and navigate to Entra ID » Conditional Access.
- Click +Create new policy and enter a name for the policy.
- Under Assignments, go to Users or workload identities.
- Select Workload identities under What does this policy apply to. Under Include, click Select service principals and choose the appropriate service principals from the list.
- In the Target resources section, go to Include and select All resources (formerly 'All Cloud apps').
- Under the Conditions section, configure specific requirements to determine when the policy should trigger.
- Under Access controls, go to 'Grant', select Block access and click 'Select'.
- Set Enable policy to On and click 'Create' to create a Condition Access policy for Microsoft Entra workload identities.
Note:You can also use Report-only mode to test your Conditional Access policy before enabling it.
By either disabling sign-in access or applying Conditional Access policies, administrators can control service principal sign-ins in Microsoft 365. This approach helps minimize the risk of unauthorized access, supports enforcement of security requirements, and restricts potentially malicious sign-ins.