azure-entra-service-principal-client-secret-create-response

addPassword returns a service-principal client secret exactly once.

azurecritical service: azure:entra emits ExposesCredential

Where it sits

locationmicrosoft.graph.passwordCredential.secretText
location kindsecret_value
data kindscredential password
emits edgeExposesCredential
serviceEntra ID (azure:entra)

Collection recipe

access modecreation_response_only
operationPOST /servicePrincipals/{servicePrincipal-id}/addPassword
response pathsecretText
encodingjson
params{"servicePrincipal-id": "\u003cservicePrincipal-id\u003e"}

Required permissions

Application.ReadWrite.All

References

move · open · esc close