---
title: >-
  Azure service principal has administrator-equivalent RBAC rights and can read
  data from crown jewel storage
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Azure service principal has
  administrator-equivalent RBAC rights and can read data from crown jewel
  storage
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Azure service principal has administrator-equivalent RBAC rights and can read data from crown jewel storage

## Description{% #description %}

An Azure service principal has administrator-equivalent Azure RBAC rights at the tenant root, a management group, or a subscription, and can read data from a crown jewel blob container. Compromise of this principal could expose business-critical data and allow an attacker to control resources and security settings within that scope.

## Remediation{% #remediation %}

1. Remove administrator-equivalent role assignments from the service principal and grant only the permissions required by the workload. See [Remove Azure role assignments](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-remove).
1. Remove unnecessary Blob data read permissions from the service principal.
