What Is the Principle of Least Privilege?
Each person gets only the access their job requires. How to apply it and how often to review.
The principle of least privilege means every user, account and system gets only the access it needs to do its job, and nothing more. It limits how much damage a compromised account, a malicious insider or an honest mistake can do.
Why it matters
Most breaches involve an account that could reach far more than it should have. If a receptionist's phished password opens the whole file server, the attacker gets the whole file server. If it opens the front-desk calendar, the incident is contained. Excessive access is also the most common insider risk; see what is the biggest insider cybersecurity risk.
Where to apply it
- Files and folders. Department-based permissions on SharePoint and file shares, not "everyone" access because it was easier.
- Local administrator rights. Users should not be admins on their own computers. Most malware needs those rights to install.
- Admin accounts. Administrators use a normal account for email and browsing and a separate, MFA-protected admin account only when needed. See what is privileged access management.
- Cloud apps and SaaS. Role-based access in accounting, CRM and HR systems.
- Service accounts and integrations. Scoped to the one task they perform.
- Third parties. Vendors get access to what they support, for as long as they support it.
How to get there
- Inventory who has access to what. The results usually surprise people.
- Define roles and the access each role needs.
- Remove standing access that does not match a role, starting with admin rights.
- Grant elevated access temporarily, with approval, when a task requires it.
- Review permissions on a schedule (quarterly is common) and at every role change and departure.
Least privilege is a core part of identity security; see what is identity and access management. Mentis Group applies least privilege, permission reviews and identity governance as part of Enhanced Cybersecurity and our managed IT standards.
Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.