Why it matters
When an account is compromised, the attacker inherits its permissions. If every employee is a local administrator, every phishing click can install software and disable security tools. If a service account has full access to the cloud, one leaked key exposes everything. Least privilege keeps each compromise small.
How to apply it
Grant access based on roles, not individual requests. Remove local administrator rights from laptops. Separate everyday accounts from administrator accounts. Give applications and API keys only the permissions they use. Grant elevated access just in time and for a limited period. Remove access when people change roles or leave, and verify it regularly through access reviews.
Common obstacles
The usual resistance is convenience: broad permissions are faster to grant and generate fewer support requests. A practical approach is to start with the highest risk access, such as administrators, finance systems and cloud consoles, and to make requesting extra access quick when it is genuinely needed.
Related concepts
Least privilege is a core principle of Zero Trust and is put into practice through IAM and PAM. ISO 27001 reflects it in its access control and privileged access controls (Annex A 5.15 and 8.2), and the ENS, NIS2 and SOC 2 all expect it.




