As per best practices there must be a way to configure automountServiceAccountToken as false **Details** https://securecloud.blog/2021/08/17/azure-aks-reviewing-recommendations-from-security-center-disabling-automounting-api-credentials/