Back to glossary

Least privilege

1 min read

Least privilege is the principle of granting each identity only the access it needs for its task, and nothing more. In an intrusion it is the control that decides consequences: it does not stop an attacker getting in, it decides how far the first account they compromise can take them.

July 24, 2026
Compartir:

The principle is uncontroversial and the practice fails in the same way everywhere: permissions are granted at the moment something is broken and are never removed, because nobody can prove the removal is safe. Over years this produces identities whose granted rights bear no relation to what they actually use, and the gap is invisible unless something measures it.

It applies with more force to identities that are not people. A service account, a pipeline credential or a workload identity has a narrow and stable job, so the gap between what it may do and what it does is both larger and easier to close than for a human. In cloud estates that measurement is what CIEM tooling exists to provide, and for human administrators it is what privileged access management brackets with time and approval.

On an engagement this is what determines whether a compromised account is an observation or the finding the report is built around. We take the identity we obtained and enumerate what it can actually reach, then compare that with what it used in the available logs. The recommendation that follows is a specific set of permissions to remove with evidence that they were unused, which is a different and far more actionable statement than an instruction to apply least privilege. That measurement is part of the cloud testing where effective permissions are measured rather than assumed.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.