After Entra ID integration and Azure RBAC for Kubernetes are live, the old admin kubeconfig certificate still works on the canal AKS cluster. What follow-through should the security engineer perform?
Select an answer to reveal the explanation.
Short Explanation
Entra and Azure RBAC are live, but that old --admin kubeconfig still opens the door. Disable local accounts and shut the certificate back door.
Full Explanation
After Entra-integrated authentication and Azure RBAC for Kubernetes are in place, disabling AKS local accounts removes the local certificate admin back door so the legacy admin kubeconfig no longer authenticates. Deleting the cluster is unnecessary for this control. PIM elevation addresses Azure resource roles, not the local Kubernetes account back door. Ingress TLS certificate rotation does not disable local cluster accounts.