What does the least-privilege principle demand, and which four design principles follow from it?
An authenticated identity receives only the access rights needed to fulfil a concrete task (need to know): as much access as necessary and as little as possible, for exactly the task, resource and moment that require it. It implies fine-grained resources, minimal context-dependent permissions, just-in-time and just-enough access, and traceability.
* Least privilege and the four design consequences it forces. *
Least privilege is the design principle behind good authorisation. The four consequences:
- Fine-grained resources: you cannot grant "only what is needed" if the smallest grantable unit is "the whole database". Resources must be cut small enough.
- Minimal, context-dependent permissions: restrict the actions, the scope, the time and the context in which a right applies.
- Just-in-time and just-enough access: rights are granted when the task starts and withdrawn when it ends, and only to the extent the task needs, instead of standing rights held forever.
- Traceability: every grant and every use must be logged, so that it can be reviewed.
The reason is damage limitation: a compromised or careless account can only do what its rights allow, so fewer standing rights mean a smaller blast radius.
Go deeper:
Principle of least privilege (Wikipedia) โ history, benefits and the practical difficulty of applying it.