The security practice of giving each task only the permissions it requires, scoped as narrowly as possible.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Least privilege in context, with comparison tables and the common traps.
Terms in this definition
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
Related terms
- Allow Azure services and resources to access this server
Networking option on Azure SQL that lets in connections from every Azure IP address, even resources owned by other customers. Leaving it off follows least privilege.
- Application permissions
Microsoft Entra permissions granted to the app itself and used without any signed-in user, which means they reach every user's data. For per-user access they are not least privilege.
- Hybrid Identity Administrator
The Entra role for managing federation, PHS, PTA, cloud sync and Entra Connect settings. It is the cloud role with the least privilege that still covers Entra Connect.
- JEA
Just-enough access, a Zero Trust idea where every identity receives only the rights a given job requires; paired with just-in-time access, it puts least privilege into practice.
- Storage Account Contributor
Manages storage accounts at the management plane, yet because listKeys is among its permissions it can reach every piece of data via Shared Key. For data access, that is broader than least privilege.
- Storage Blob Data Contributor
Data-plane built-in role that can read, write and delete blobs and containers. Paired with Reader, it is the least privilege needed to upload through the portal.