
Principle of least privilege
24
MENTIONS
7
EPISODES
5
PODCASTS
Search complete. 24 mentions across 7 episodes found for "Principle of least privilege".
Sep 17, 2026
CompTIA Security+ SY0-801: 1.1 Security Concepts and Controls
S
5:45Sec GuyHOST
The cryptographic proof eliminates plausible deniability.
S
5:49Sec GuyHOST
This brings us to our core operating doctrine, least privilege.
S
5:53Sec GuyHOST
Lease privilege dictates that every user, application, and service account must operate with only the minimum permissions necessary to complete their job and strictly for the time needed.
S
6:05Sec GuyHOST
If a junior analyst only needs read-only access to customer support tickets, granting them database administrator privileges is an architectural defect.
Cloud IAM: STS, Roles, SCP, and Policies
S
1:56Sec GuyHOST
Because that instance had an IAM role with a policy that was too broad, the attacker was able to use the server's own identity to steal an API key from the metadata service.
S
2:07Sec GuyHOST
This is why we follow the principle of least privilege.
S
2:11Sec GuyHOST
Your policies should never use a wildcard asterisk to grant all permissions.
S
2:16Sec GuyHOST
They should be granular.
Mastering Access Control: RBAC, MAC, DAC & The AAA Framework
S
4:47Sec GuyHOST
They will show up on the test.
S
4:50Sec GuyHOST
And the foundation, principle of least privilege.
S
4:54Sec GuyHOST
Least privilege means giving users only the permissions they need to do their job, nothing extra.
S
5:00Sec GuyHOST
This minimizes damage from mistakes or compromised accounts.
Least Privilege Best Practices: Where to Start
W
0:10W. Curtis PrestonHOST
That cost them 400,000 euros in fines.
W
0:13W. Curtis PrestonHOST
And when they appealed, the court basically said they didn't even try the concept of least privilege.
W
0:20W. Curtis PrestonHOST
Today, that's what we're talking about.
W
0:21W. Curtis PrestonHOST
Least privilege, best practices.
W
0:24W. Curtis PrestonHOST
What does that mean exactly? And also, where do you start when everybody already has domain admin? Finally, we talk about role-based administration and why that's really the only realistic path here.
W
0:37W. Curtis PrestonHOST
We talk about privileged account inventories, fire call accounts, segregation of duties, non-repudiation, and three backup roles that you should split apart before somebody quietly deletes your backup configuration.
W
4:53W. Curtis PrestonHOST
My God, we've already spent 20 minutes on this.
W
4:56W. Curtis PrestonHOST
So let's go.
The Growing Trend of AI Agents in the Health System & What Leaders Can Do to Keep Operations Secure
J
8:20Jason ElrodGUEST
So this is why it's essential that we give AI, especially ag- agents, their own identity.
J
8:28Jason ElrodGUEST
That way, we can assign least privilege, ba- basically the minimum permissions necessary.
J
8:33Jason ElrodGUEST
Segmentation is intensely important here, so only in the environments required for its function.
J
8:40Jason ElrodGUEST
And I mentioned identity.
9 MINS LATER
E
17:26Erica Spicer-MasonHOST
But I wanna give our, our listeners just kind of a forward-looking view of, uh, where this approach that we've talked today, whether that's segmentations, creating, you know, constrained or contained environments, w- where might that approach stop helping, and what risks would you leave listeners with to consider even after they've achieved the constrained access and segmentation?
J
17:50Jason ElrodGUEST
Segmentation's critical, right? We, we've already mentioned that.
J
17:52Jason ElrodGUEST
Least privilege, again, also helps dramatically reduce risk.
J
17:56Jason ElrodGUEST
So segmentation and least privilege dramatically reduces risk.
#445 - Sponsor Spotlight - Twine Security
B
3:59Benny PoratGUEST
We need to make sure to deliver access to the business.
B
4:02Benny PoratGUEST
But in the same time, we need, of course, to make sure for security perspective, to have least privilege.
B
4:08Benny PoratGUEST
But at the same time, we are so lack of context.
B
4:12Benny PoratGUEST
At the end, we are not running the business.
18 MINS LATER
B
22:34Benny PoratGUEST
It don't know what it's going to use.
B
22:37Benny PoratGUEST
So for sure, you actually want to restrict it.
B
22:40Benny PoratGUEST
You want to start and just give it the minimum, the least privilege as possible.
B
22:45Benny PoratGUEST
And least privilege is difficult.
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473
R
17:43Rob AllenGUEST
It's like, where does it, where do you draw, where do you draw the line? Where does it draw the line? Um, but yeah, as I said, sensible guardrails external to the thing itself, I think.
R
17:53Rob AllenGUEST
Uh, I mean, it'll, it's, it's effectively the principle of least privilege, which is realistically best practices, or best practice for all security, you could argue.
R
18:03Rob AllenGUEST
This is just another layer.
T
18:04Tyler ShieldsHOST
Yeah.