How Least Privilege works
Three-step view of how it operates in practice.
- Inventory. Identify every account, role, and system. Document what it currently has access to.
- Right-size. For each role, define the minimum permissions needed. Remove everything else. Convert admin-by-default setups to just-in-time.
- Review. Privileges drift. Quarterly access reviews, automated recertification, and offboarding discipline keep the baseline clean.
Why Least Privilege matters
Least privilege doesn't stop the first bad click — it decides what the click costs: malware runs with the victim's permissions, so a standard user losing their laptop for a day beats an over-privileged one exposing the entire file server. It's also among the cheapest controls available to a small organization, since it's mostly configuration and discipline rather than product spend, and it shows up on nearly every insurance and compliance questionnaire.
Least privilege vs need-to-know vs separation of duties
- Least privilege. Every account gets the minimum permissions its job requires, nothing more. It applies to people, applications, and service accounts alike.
- Need-to-know. A data-focused cousin: even among people with similar roles, you only see the specific information your work requires. Least privilege limits capabilities; need-to-know limits knowledge.
- Separation of duties. No single person can complete a sensitive process alone, the one who creates a vendor isn't the one who approves payment to it. It's a fraud control as much as a security control.
- Zero trust. The broader architecture that verifies every request continuously. Least privilege is one of its load-bearing walls, not a synonym for it.
Common Least Privilege mistakes
- Local admin for everyone. Making every user an administrator of their own laptop feels convenient until one phishing click installs whatever the attacker wants at full power. Standard user accounts plus an on-demand elevation tool keep convenience without the standing risk.
- Access that only ever grows. People change roles and keep old permissions, so ten-year employees end up able to touch everything the company owns. Quarterly access reviews with actual removals are what keep the principle true over time.
- Shared and generic logins. An 'office' or 'scanner-admin' account used by five people can't be audited, can't be cleanly offboarded, and its password never changes. Named accounts per person, always, even when it's mildly inconvenient.