Least Privilege

Least Privilege

Least Privilege

The principle of least privilege restricts access rights to what a role genuinely requires. It applies to user accounts, service accounts, and administrative privileges, and includes removing access when roles change.

It limits the reach of any single compromised credential.

Alternative Names:

Principle of Least Privilege, Minimum Necessary Access

Why it Matters?

Privilege accumulation is the recurring failure, since users gain access as roles change and rarely lose what they no longer need. A partner who moved practice groups three times may hold access to every matter they ever touched. Periodic access review is the control, and it matters most for administrative accounts where a single compromise reaches everything.

Frequently Confused with

Related terms

Frequently asked questions

What is privilege accumulation?

What is privilege accumulation?

The buildup of access rights as users change roles without losing permissions they no longer need, which expands exposure from any compromise.

How is it controlled?

How is it controlled?

Through periodic access review and automated deprovisioning on role change, with particular attention to administrative accounts.