Admin -> Security -> Elevated Roles tab is where "what counts as elevated" is actually decided -- it's not fixed. Two lists, Server Roles and Database Roles, each a checkbox per SQL Server fixed role. Check a role and any credential the automatic scan finds holding it gets flagged; uncheck it and existing findings for that role disappear once the scan runs again.

Seeded starting point: every fixed server role is checked, including bare public membership -- uncheck it here if that shouldn't count on its own for your fleet. Only the higher-privilege fixed database roles are checked by default (db_owner, db_securityadmin, db_accessadmin, db_ddladmin); ordinary read/write/backup access (db_datareader, db_datawriter, db_backupoperator, and the rest) is treated as non-elevated out of the box.

Changes here take effect on the next scan, not retroactively -- see the Credentials page's Refresh Now button, or wait for the next scheduled sweep (every 6 hours by default).

See also: Elevated Credentials for what the badge itself means, and Glossary for related terms.