> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports/azure-entities/entra-id/serviceprincipal.md).

# ServicePrincipal

The **ServicePrincipal** entity represents a service principal (enterprise application) in Azure Active Directory (Entra ID).

| Field                  | Type    | Possible Operators                                                 | Description                                                    |
| ---------------------- | ------- | ------------------------------------------------------------------ | -------------------------------------------------------------- |
| Guid                   | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Unique identifier for the entity in Forestall                  |
| ObjectID               | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Object ID of the service principal                    |
| FSName                 | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name used in Forestall                                 |
| Enabled                | BOOLEAN | True / False                                                       | Whether the service principal is enabled                       |
| IsAZPrivileged         | BOOLEAN | True / False                                                       | Whether the service principal has privileged access in Azure   |
| IsStealth              | BOOLEAN | True / False                                                       | Whether the service principal is a stealth (shadow) admin      |
| IsInactive             | BOOLEAN | True / False                                                       | Whether the service principal is inactive                      |
| IsAdmin                | BOOLEAN | True / False                                                       | Whether the service principal has admin privileges             |
| DisplayName            | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name of the service principal in Azure AD              |
| Description            | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Description of the service principal                           |
| AppOwnerOrganizationID | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Organization ID of the application owner                       |
| AppDescription         | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Description of the associated application                      |
| AppDisplayName         | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name of the associated application                     |
| LoginURL               | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Login URL configured for the service principal                 |
| ServicePrincipalType   | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Type of service principal (e.g., Application, ManagedIdentity) |
| TenantID               | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Tenant ID the service principal belongs to            |
| AZTier                 | NUMBER  | Equal, Between, Smaller, Larger, Smaller or Equal, Larger or Equal | Azure tier classification assigned by Forestall                |
