Datadog access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Datadog, Black Cat runs 20 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Datadog connector needs.
Checks (20)
severity: high SSO Disabled fix difficulty: medium #
Enable SAML SSO in Datadog organization settings
- Navigate to Organization Settings > Login Methods
- Click the SAML tab
- Toggle "Enable SAML" to on
- Upload your IdP metadata XML or enter the IdP SSO URL and certificate
- Save the configuration and verify the IdP connection is active
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high SSO Not Enforced fix difficulty: medium #
Enable SAML strict mode to require SSO for all users
- Navigate to Organization Settings > Login Methods
- Click the SAML tab
- Ensure SAML is already enabled and configured with a valid IdP
- Enable "SAML Strict" mode to prevent username/password login
- Save the configuration
- Notify all users that SSO is now required for login
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Admin Redundancy fix difficulty: easy #
Assign the Datadog Admin role to at least two users for redundancy
- Navigate to Organization Settings > Users
- Identify users who should serve as backup administrators
- Click the user's name to open their profile
- Under Roles, add the Datadog Admin role
- Save and verify the user now appears with the Admin role
- Repeat for any additional backup administrators required
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Admins fix difficulty: easy #
Reduce the number of admin users to limit blast radius of compromised accounts
- Navigate to Organization Settings > Users
- Filter users by the Datadog Admin role
- Review each admin's business justification for that level of access
- For users who do not require full admin, click their name and edit their roles
- Remove the Datadog Admin role and assign a least-privilege role (e.g., Standard or Read-Only)
- Save changes and notify the affected users
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high External Admin fix difficulty: easy #
Remove admin privileges from users outside the organization's email domain
- Navigate to Organization Settings > Users
- Filter or sort users to identify those with email addresses outside the corporate domain
- Review each external admin's role and business justification
- Click the user's name and edit their roles to remove the Datadog Admin role
- If the external user no longer requires access, disable or delete the account
- Save changes and document the decision
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Unverified User fix difficulty: easy #
Ensure all active users have completed email verification or re-send the invitation
- Navigate to Organization Settings > Users
- Identify users shown as pending or unverified
- Confirm the user's email address is correct
- Click the user's name and select "Resend Invite" to trigger a new verification email
- If the user is no longer expected to join, delete the pending invitation
- Follow up with the user to confirm they have completed verification
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Disabled User Present fix difficulty: easy #
Remove disabled users from the organization directory to reduce attack surface
- Navigate to Organization Settings > Users
- Filter or search for disabled users
- Review each disabled account to confirm it is no longer needed
- Click the user's name and select "Delete User" to permanently remove them
- Revoke any API or application keys associated with the deleted user
- Document the offboarding action in your access review records
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low External User Access fix difficulty: easy #
Review and justify external user accounts or remove those no longer required
- Navigate to Organization Settings > Users
- Identify users whose email domain differs from the corporate domain
- Review each external user's role, last login date, and business justification
- For users who no longer require access, click their name and select "Delete User"
- For retained external users, ensure they are assigned the minimum required role (Read-Only or Standard)
- Document the review outcome and schedule a recurring access review for external accounts
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Dashboard Permissions Open fix difficulty: easy #
Restrict dashboard access by limiting edit permissions to specific roles
- Open the flagged dashboard in Datadog
- Click the Settings (gear) icon in the top-right corner of the dashboard
- Navigate to the Permissions section
- Change the edit permission from "Everyone" to specific roles or teams
- Optionally restrict view access as well if the dashboard contains sensitive data
- Save the updated permissions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Dashboard Read-Only Without Role Restriction fix difficulty: easy #
Add role-based restrictions to read-only dashboards that may contain sensitive data
- Open the flagged dashboard in Datadog
- Click the Settings (gear) icon in the top-right corner of the dashboard
- Navigate to the Permissions section
- Under viewer access, change the setting from "Everyone" to specific roles or teams
- Select the appropriate roles that should be permitted to view this dashboard
- Save the updated permissions and verify access with a test account if possible
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high External Admin Service Account fix difficulty: medium #
Remove admin privileges from service accounts with external email domains
- Navigate to Organization Settings > Service Accounts
- Identify service accounts whose email address is outside the corporate domain
- Click the service account name to open its detail page
- Edit the roles to remove the Datadog Admin role
- If the service account is no longer needed, disable or delete it
- Rotate any API or application keys associated with the account if compromise is suspected
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Service Account Admin Privileges fix difficulty: medium #
Remove admin privileges from service accounts and assign a least-privilege role
- Navigate to Organization Settings > Service Accounts
- Click the flagged service account name to open its detail page
- Review which integrations or pipelines use this service account
- Edit the roles to remove the Datadog Admin role
- Assign the minimum role required for the service account's function (e.g., Standard or a custom scoped role)
- Rotate the service account's API keys to ensure no active sessions carry the old permissions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Service Account Custom Role fix difficulty: medium #
Review service account custom roles and replace with least-privilege built-in roles where possible
- Navigate to Organization Settings > Service Accounts
- Identify service accounts assigned custom roles
- Click the service account name to review the permissions granted by the custom role
- Determine whether a built-in role (Standard, Read-Only) would satisfy the service account's requirements
- Edit the service account roles to replace the custom role with the appropriate built-in role
- If a custom role is required, audit the permissions to remove any that are not needed
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Application Key Write Scopes fix difficulty: medium #
Restrict application key scopes to read-only permissions where write access is not required
- Navigate to Organization Settings > Application Keys
- Identify application keys with write-level scopes
- Click the application key name to view its current scopes
- Assess whether each write scope is actively needed by the integration or script using the key
- Edit the key to remove unnecessary write scopes, retaining only the minimum required
- Regenerate the key if it may have been exposed or shared
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Application Key Has No Scopes fix difficulty: medium #
Add explicit scopes to application keys to prevent implicit full-permission inheritance from the key owner
- Navigate to Organization Settings > Application Keys
- Click the flagged application key name to open its settings
- Review the key's intended use case and determine the minimum required scopes
- Edit the key and add only the scopes that the consuming integration genuinely needs
- Save the updated key configuration
- Test the integration to confirm it functions correctly with the restricted scopes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium External Service Account fix difficulty: easy #
Review and justify external service accounts or remove those no longer required
- Navigate to Organization Settings > Service Accounts
- Identify service accounts whose email address is outside the corporate domain
- Review each external service account's role and business justification
- If no longer needed, disable or delete the service account
- Rotate any API or application keys associated with the account
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: critical Admin User Not Verified fix difficulty: easy #
Ensure admin users complete email verification or remove unverified admin accounts
- Navigate to Organization Settings > Users
- Identify the unverified admin user
- Resend the verification email if the user is expected to join
- If the user is not recognized, remove their admin role immediately
- If the invitation is stale, delete the pending user account
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Disabled Admin User fix difficulty: easy #
Remove the admin role from disabled users or delete the account entirely
- Navigate to Organization Settings > Users
- Locate the disabled admin user
- Remove the Datadog Admin role from the user
- If the user is no longer needed, delete the account
- Revoke any API or application keys owned by the user
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Application Key Excessive Scopes fix difficulty: medium #
Reduce application key scopes to the minimum required set
- Navigate to Organization Settings > Application Keys
- Click the flagged application key to view its scopes
- Review which scopes are actively used by the consuming integration
- Remove unnecessary scopes to reduce the key's blast radius
- Save the updated key configuration and test the integration
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high API Key Critical Age fix difficulty: medium #
Immediately rotate API keys older than two years
- Navigate to Organization Settings > API Keys
- Identify the flagged key by name and note which integrations use it
- Create a new API key with an appropriate descriptive name
- Update all integrations using the old key with the new key value
- Verify the new key works in all affected systems
- Revoke the old API key immediately
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2