Azure service principal has administrator-equivalent RBAC rights and can read data from crown jewel storage

Description

An Azure service principal has administrator-equivalent Azure RBAC rights at the tenant root, a management group, or a subscription, and can read data from a crown jewel blob container. Compromise of this principal could expose business-critical data and allow an attacker to control resources and security settings within that scope.

Remediation

  1. Remove administrator-equivalent role assignments from the service principal and grant only the permissions required by the workload. See Remove Azure role assignments.
  2. Remove unnecessary Blob data read permissions from the service principal.