IT security

Least Privilege

Also known as: Principle of Least Privilege · PoLP

In short

Least privilege means every account and system gets only the access rights it actually needs for its task, and nothing more.

Least privilege is the principle of granting every user account, application, and system only the access rights required for its specific task, and no more. The point is to limit the damage a single compromised account can do – someone with no access to accounting can't encrypt or exfiltrate anything there, even if their account gets taken over.

In practice, least privilege shows up as staff only being able to reach the folders, applications, and systems their role requires, and nobody working with administrator rights by default. Rights aren't just granted once and left in place; they get reviewed periodically to see whether they still match the person's current task.

A common mistake is granting rights generously to avoid follow-up requests and then never revoking them, even long after a person's role has changed. Over years this builds up a situation where many accounts hold far more access than their current role justifies.

What it means in practice

For a business, least privilege means a stolen account can only cause limited damage instead of opening access to the entire network. A sign that it's missing is former employees or people who've changed roles still able to reach systems they no longer need. NDVDL sets up access rights according to this principle and reviews them as part of ongoing support.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.