What it is
Least privilege reduces blast radius by granting only what is necessary. It applies to users, services, networks, and data paths.
Key points
- Use role‑based or attribute‑based access.
- Time‑bound and just‑in‑time elevation.
- Review entitlements and remove excess.