Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryPrinciple of Least Privilege
Glossary

Principle of Least Privilege

The principle of least privilege is a security rule that gives every user, device and program only the access its job needs, and only for as long as needed.

Definition

What is Principle of Least Privilege?

The Principle of Least Privilege is a security design rule stating that every user, account, device, and program should have only the permissions required to perform its function, and no more, for no longer than necessary. A bookkeeper needs the accounting system, not the ability to install software on every computer. A web server needs to read its own files, not the company's personnel folder.

In practice least privilege is applied in layers. On workstations it means employees run as standard users and administrator rights are granted to a separate account, or on request for a limited time, so that malware launched by a click runs with the user's limited permissions rather than the machine's full control. In the directory it means administrator roles are scoped narrowly, assigned to dedicated accounts, and activated just in time through a tool such as Entra Privileged Identity Management rather than held permanently. For applications and service accounts it means each integration gets its own credential with the minimum scopes. Privileged access management tools vault and rotate shared administrative passwords and record the sessions that use them, so that raised access is auditable and temporary.

For a small or mid-sized business the most common violation is the simplest: everyone is a local administrator because it was easier when the computers were set up, and the owner's everyday account is also the global administrator for Microsoft 365. Both make a single phished password or a single bad download catastrophic. Removing standing administrator rights is the single change that most reduces ransomware impact, and it is a routine question on cyber insurance applications. It does require a process for the times people legitimately need more access, or they will find workarounds.

NetSys includes privileged access management and privileged identity management in every managed agreement rather than selling them as add-ons, which reflects how central least privilege is to its approach. Standing local administrator rights are removed and replaced with a request process, and Microsoft 365 administrator roles are made time-limited. Shared credentials are vaulted and rotated. Joel Baum, NetSys's founder, writes regularly on the subject, and the firm publishes a comparison of PIM and PAM for readers deciding which controls apply to them.

Why it matters for a small business

Every attack on your business ends up using someone's permissions, and the damage is bounded by how much that someone was allowed to do. If the receptionist's account can install software and the owner's email account can reset every password in the company, one phishing email becomes a full takeover. Least privilege shrinks that blast radius without buying anything. It is also the control that insurers and enterprise customers ask about first when they want to know whether a company takes security seriously. The inconvenience is real but small, and it is far smaller than a rebuild.

Common Questions

Principle of Least Privilege: FAQs

What is the principle of least privilege in simple terms?

The principle of least privilege means giving each person and each program only the access it needs to do its job, and nothing extra. An employee who only needs to read reports should not be able to delete them, and a user who occasionally needs administrator rights should get them for the task and then lose them again. The idea limits how much harm a compromised account or a mistake can do, because the permissions available to the attacker are the permissions the victim had.

What is an example of least privilege?

A common example is removing local administrator rights from everyday user accounts on company computers. Staff work as standard users, and when someone needs to install approved software, a separate administrator credential or a temporary approval is used. Another example is Microsoft 365, where the owner's daily email account is a normal user and a separate account, protected by phishing-resistant authentication, holds the global administrator role and is activated only when needed. Service accounts for integrations get their own narrowly scoped credentials.

How does least privilege help prevent ransomware?

Ransomware runs with the permissions of the account that launched it. If that account is a standard user, the malware cannot disable security software or delete backups it has no rights to, and it cannot spread to other machines through administrative shares. Attackers then have to work much harder to obtain administrator access, which takes time and generates the noisy activity that detection tools catch. Removing standing administrator rights and making privileged roles time-limited are two of the most effective ransomware controls available.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.