This warning-triangle badge next to a credential means it holds real elevated access somewhere in your fleet. Click the badge for a breakdown of exactly which server, database, and role triggered it.
Automatic scan
Worker connects as the credential to every active target server and asks SQL Server itself which roles it currently holds -- sysadmin, db_owner, and the rest of the seeded elevated list (editable under Admin -> Elevated Roles). This is a real, live check against each server, not a guess or an inference from the credential's name or type.
It runs on a schedule (every 6 hours by default) and on demand from the Credentials page's Refresh Now button.
Manual flag: Windows local admin
For a WindowsUser credential only, an Elevated (Windows local admin) checkbox covers the one thing the automatic scan structurally can't see: whether that Windows account is also a local administrator on the box itself. A SQL Server role query can't answer that, no matter which SQL roles the account holds -- so this one is set by hand.
This checkbox doesn't show up for SqlLogin or AzureServicePrincipal credentials. For those, the automatic scan above is already the full answer -- there's nothing left for a manual flag to add.
What's never checked
AzureServicePrincipal and SmtpAuth credentials never show a scan result at all. Neither ever connects to a SQL Server, so there's nothing for the scan to ask a role-membership question about.
This covers what to expect day to day. For the full technical version -- exactly what gets queried, every fail-open case, and the scan schedule in detail -- see Elevated-Role Scan: Technical Reference.
See also: Glossary for related terms.