GlossarySecurity awareness

Least privilege

Short answer

The principle of least privilege means giving every user, application and system only the access it needs to do its job, and nothing more, for no longer than necessary. It limits the damage an attacker, a mistake or a malicious insider can cause.

Why it matters

When an account is compromised, the attacker inherits its permissions. If every employee is a local administrator, every phishing click can install software and disable security tools. If a service account has full access to the cloud, one leaked key exposes everything. Least privilege keeps each compromise small.

How to apply it

Grant access based on roles, not individual requests. Remove local administrator rights from laptops. Separate everyday accounts from administrator accounts. Give applications and API keys only the permissions they use. Grant elevated access just in time and for a limited period. Remove access when people change roles or leave, and verify it regularly through access reviews.

Common obstacles

The usual resistance is convenience: broad permissions are faster to grant and generate fewer support requests. A practical approach is to start with the highest risk access, such as administrators, finance systems and cloud consoles, and to make requesting extra access quick when it is genuinely needed.

Related concepts

Least privilege is a core principle of Zero Trust and is put into practice through IAM and PAM. ISO 27001 reflects it in its access control and privileged access controls (Annex A 5.15 and 8.2), and the ENS, NIS2 and SOC 2 all expect it.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub