As part of your organisation's proactive threat hunting, app registrations with
secrets and passwords configured should be reviewed to look for any suspicious
entries.
The following Powershell script which I like to run in CloudShell will give you
an overview within your tenant.
Service principals work hand-in-hand with app registrations,