Azure service principal has administrator-equivalent RBAC rights

Description

An Azure service principal has administrator-equivalent Azure RBAC rights at the tenant root, a management group, or a subscription. These permissions can allow the principal to create or delete resources, change security configurations, or grant additional access within that scope.

Remediation

Review the service principal’s role assignments and remove assignments that grant unnecessary administrator-equivalent permissions. Replace them with the least-privileged roles required for the application’s intended function. For guidance, refer to Remove Azure role assignments.