Learning path

Full curriculum

Full curriculum

Unit content

Least privilege

The principle of least privilege gives each account, service or component only the authority it needs for its current role.

A service that only needs to read one directory should not run with unrestricted filesystem access. A helper that needs one privileged operation can often be isolated from the larger application rather than giving the whole application that privilege.

Least privilege limits blast radius. If a component is compromised, the adversary inherits only the permissions available to that component instead of automatically gaining broader authority.

Privilege should be narrow in several dimensions where practical: which resources can be accessed, which operations are allowed, and how long the privilege remains active.

Convenience often pushes systems toward broad administrative roles or shared credentials. Security pushes in the opposite direction: authority should be explicit and no broader than the operation actually requires.