More Info:
Access to create the token sub-resource of ServiceAccounts can be used to obtain persistent unauthorized access to the cluster. It should be limited to trusted administrators only.Risk Level
HighAddress
SecurityCompliance Standards
- CIS AKS
Triage and Remediation
- Remediation
Remediation
Using Console
Using Console
Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.

