---
title: Service account can escalate privileges to access a crown jewel
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Service account can escalate privileges
  to access a crown jewel
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Service account can escalate privileges to access a crown jewel

## Description{% #description %}

A service account can escalate privileges to another service account that can read a crown jewel Cloud Storage bucket. If an attacker gains access to the first service account, they can use privilege-escalation permissions to assume the capabilities of the second account and read data from a business-critical bucket.

## Remediation{% #remediation %}

1. Review and restrict privilege-escalation permissions (e.g. `roles/iam.serviceAccountTokenCreator`, `iam.serviceAccounts.actAs`, and related bindings) between service accounts.
1. Apply [least privilege best practices for service accounts](https://cloud.google.com/iam/docs/best-practices-service-accounts) to ensure escalation paths cannot be used to reach sensitive resources.
