The principle of least privilege restricts access rights to what a role genuinely requires. It applies to user accounts, service accounts, and administrative privileges, and includes removing access when roles change.
It limits the reach of any single compromised credential.
Alternative Names:
Principle of Least Privilege, Minimum Necessary Access
Why it Matters?
Privilege accumulation is the recurring failure, since users gain access as roles change and rarely lose what they no longer need. A partner who moved practice groups three times may hold access to every matter they ever touched. Periodic access review is the control, and it matters most for administrative accounts where a single compromise reaches everything.
Frequently Confused with
Related terms
Frequently asked questions
What is privilege accumulation?
How is it controlled?





