Workload Identity Risk Audit
TL;DR: This skill reviews every service principal and managed identity in your tenant, surfaces Entra ID Protection risk signals, ageing credentials and anomalous sign-ins, and produces a prioritised report so risky non-human accounts get attention before they are abused.
What is a workload identity in Microsoft Entra?
A workload identity is a non-human account, a service principal or managed identity, that an application, script or automation uses to authenticate and access resources. Unlike user accounts, workload identities rarely use multi-factor authentication and often hold long-lived secrets or certificates, which makes them an attractive target. Microsoft Entra ID Protection extends risk detection to these identities, flagging leaked credentials, suspicious sign-ins and anomalous behaviour that this skill collects and analyses read-only.
When should you run this skill?
- “Show me which service principals have risky sign-ins flagged by Entra ID Protection.”
- “Find workload identities with credentials that are expired or about to expire.”
- “Which managed identities have unusual sign-in patterns this month?”
- “Audit our app registrations for leaked or compromised secrets.”
- “I need a workload identity risk report before the quarterly security review.”
- “List the highest-risk non-human accounts so we can prioritise remediation.”
- “Are any service principals signing in from anomalous locations or with stale credentials?”
How this skill works, step by step
- Enumerate all service principals and managed identities in the Microsoft Entra tenant using read-only directory queries.
- Retrieve workload identity risk state and risk detections from Microsoft Entra ID Protection for each identity.
- Collect credential metadata, including secret and certificate expiry dates, and flag credentials that are expired, expiring soon or unusually long-lived.
- Gather recent sign-in activity and correlate it with anomalous sign-in and suspicious behaviour detections.
- Identify dormant workload identities that hold credentials but show no recent sign-in activity.
- Derive a composite risk score for each identity by weighting the Entra risk level, credential hygiene and sign-in anomalies.
- Prioritise the results, placing high-risk and credential-exposed identities at the top of the report.
- Compile the findings into a structured, human-readable output with remediation guidance.
Output format
The skill returns a prioritised table of workload identities followed by a summary.
| Identity | Type | Entra risk level | Credential status | Anomalous sign-ins | Risk score |
|---|---|---|---|---|---|
| Contoso-Backup-App | Service principal | High | Secret expired 14 days ago | 2 (impossible travel) | 92 |
| invoicing-managed-id | Managed identity | Medium | Certificate expiring in 9 days | 0 | 58 |
Summary:
- High-risk identities requiring immediate attention and credential rotation.
- Credential hygiene issues, including expired, expiring or long-lived secrets and certificates.
- Anomalous sign-in detections correlated from Microsoft Entra ID Protection.
- Dormant workload identities that hold active credentials but show no recent activity.
Scope and safety
This skill is read-only by default and makes no changes to your tenant, identities or credentials. It only inspects and reports.
This skill does NOT:
- Rotate, revoke, create or delete any secrets, certificates or credentials.
- Disable, block or modify any service principal or managed identity.
- Change Conditional Access, risk policies or any Microsoft Entra ID Protection configuration.
- Remediate findings automatically; all remediation remains a deliberate human action.
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence |
|---|---|
| Workload identity risk detections and risk state from Microsoft Entra ID Protection | Microsoft Entra Workload ID Premium |
| Enumerating service principals, managed identities and reading credential metadata | Microsoft Entra ID Free (read-only directory access) |
| Reading sign-in activity for workload identities | Microsoft Entra ID P1 |
Least-privilege roles
- Security Reader (read-only access to Microsoft Entra ID Protection risk data)
- Global Reader (read-only access to directory objects, service principals and credentials)
Microsoft Graph permissions (read-only)
Application.Read.All- reads service principals, app registrations and their secret and certificate credential metadataIdentityRiskyServicePrincipal.Read.All- reads workload identity risk state and risk detections from Microsoft Entra ID ProtectionAuditLog.Read.All- reads sign-in activity for service principals and managed identitiesDirectory.Read.All- reads managed identities and supporting directory objects
Related skills
- App Registration Secret Hygiene: run before this skill to find expiring secrets and over-broad API permissions on app registrations.
- OAuth Consent Risk Audit: run alongside this skill to review over-privileged or illicitly consented enterprise apps.
- Risky Users and Sign-ins Summary: run after this skill to prioritise risky human identities using Entra ID Protection detections.
- Entra Agent ID Audit: run after this skill to review agent identities and their sponsors.
- Agent Governance Guide: the pillar guide for governing agents and their identities.
Sources and compliance
- Securing workload identities with Microsoft Entra ID Protection
- What are workload identities?
- Reinforces credential hygiene expectations under the ASD Essential Eight Maturity Model .
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-06-02