---
title: >-
  Service account with privilege-escalation capability can be assumed by a third
  party
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Service account with
  privilege-escalation capability can be assumed by a third party
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Service account with privilege-escalation capability can be assumed by a third party

## Description{% #description %}

A GCP service account that can be assumed by a third party or is publicly assumable also has a path to escalate privileges to another service account. An external principal, or an attacker who compromises the third-party account or assumes the publicly assumable service account, can leverage privilege-escalation permissions to gain broader access within the GCP project.

## Remediation{% #remediation %}

1. Review and restrict which principals can assume this service account, ensuring it is not assumable by third parties or the public. See [Granting, changing, and revoking access](https://cloud.google.com/iam/docs/granting-changing-revoking-access) for guidance.
1. Apply [least privilege best practices for service accounts](https://cloud.google.com/iam/docs/best-practices-service-accounts) to remove unnecessary privilege-escalation permissions.
