What is least privilege?
Least privilege is the principle that every account, process, and person holds only the authority its job requires, and nothing beyond it.
It is the oldest idea in access control and the one most environments implement partially. The reason is not disagreement with the principle. It is that granting authority is easy, measuring it is hard, and taking it back is unpopular.
What it applies to
| Subject | Least privilege means |
|---|---|
| A person | Rights to the systems their role needs, not to every system their team can reach |
| An administrator | Ordinary rights for ordinary work, elevated rights only for the task that needs them |
| A service account | Permission to do its one job, and no ability for a person to log in with it |
| A process | The rights of the user who launched it, not the rights of the machine |
| An application | Access to its own data, not to the whole database |
Why it is hard
Three reasons recur.
Authority accumulates. People change roles and keep the old rights. Nobody is harmed by the surplus until the account is compromised.
Nobody can see the current state. Privileged group membership, local administrator rights, SSH key distribution, and cloud entitlements live in different places. Without a combined view, the conversation is about opinions.
Removing rights breaks things. Sometimes the surplus authority is load-bearing in a way nobody documented. That risk makes removal feel more dangerous than retention, which is backwards but understandable.
The practical answer to all three is evidence: discover what authority exists, show what it reaches, and change it with a preview rather than a guess.
Where frameworks ask for it
| Framework | Requirement |
|---|---|
| NIST SP 800-53 | AC-6 Least Privilege, with enhancements AC-6(1), AC-6(2), AC-6(5), AC-6(9), AC-6(10) |
| NIST SP 800-171 | 3.1.5 employ the principle of least privilege; 3.1.6 use non-privileged accounts for nonsecurity functions; 3.1.7 prevent non-privileged users from executing privileged functions |
| CMMC Level 2 | AC.L2-3.1.5, AC.L2-3.1.6, AC.L2-3.1.7 |
| ISO/IEC 27001 | Annex A controls on privileged access rights |
| Essential Eight | Restrict administrative privileges |
What the kit does
Item
- Discover systems, accounts, privileged group membership, password age, SSH keys, and cloud access keys, so surplus authority can be found rather than guessed
- Report how many hosts and services each shared credential reaches, and reduce it, with a preview before the change
- Endpoint elevation, delegation, least privilege, application and command control, and just-in-time elevation. Windows is the most complete today. Apple Mac and Unix/Linux are expanding.
- Command restriction that blocks dangerous commands as they are typed inside a brokered session
- Start an application with credentials the user never sees, so a person can run a task without holding the rights
- Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned.
- Analysis of cloud account permissions
Common questions
Is least privilege the same as zero trust?
No. Zero trust is an architecture that stops treating network location as proof of identity. Least privilege is a rule about how much authority a verified identity holds. They are complementary.
How do we start?
With discovery. A list of who currently holds administrative rights on what, built from the systems rather than from a spreadsheet, is usually the first time the real picture is visible.
Does least privilege mean removing local administrator rights?
Often, yes, for ordinary users. The replacement is a way to elevate a specific task when it is genuinely needed, which is what privileged user management provides.
How is it different from zero standing privileges?
Least privilege is about how much. Zero standing privileges is about when.
Related pages
- What is zero standing privileges
- What is just-in-time access
- What is privileged access management
- Privileged user management
- Privileged identity management
- NIST SP 800-171 and NIST SP 800-53
- Capabilities and pricing
- Glossary