EN - FR - DE - ES - IT - PT -

LexiconDream

🔽 Least Privilege

Granting users only the minimum access needed to do their jobs.

Least Privilege

Least privilege means giving users only the access they need to do their jobs. Nothing more. A marketing coordinator needs to edit campaign files. She does not need domain administrator rights. A database analyst needs to read production data. He does not need to modify the schema. The principle sounds obvious. Most organizations violate it constantly. Permissions accumulate over time. People change roles, and old access stays. Temporary grants become permanent. The result is a network where everyone can reach everything.

Implementing least privilege takes work. You need to know what each role actually requires. That means inventorying systems, mapping workflows, and reviewing access regularly. It means removing local administrator rights from everyday accounts, a change that generates complaints until people adjust. It means using privileged access management tools to control and audit administrative accounts. The payoff is significant. If an attacker compromises a low-privilege account, they cannot move freely. They have to escalate, which takes time and generates noise. The 2013 Target breach started with credentials from an HVAC vendor. That vendor had network access it did not need. Least privilege would have limited the damage. It is not a silver bullet. It is a fundamental control that too many organizations skip.

Least privilege in practice

Least privilege is inconvenient. That inconvenience is the point. It slows attackers down and makes their activity visible.

Comments

No comments yet. Be the first to share a thought.

Leave a comment