Least Privilege Principle
A security administrator is configuring permissions for a new cloud-based expense reporting application. The administrator assigns each employee only the permissions they need to perform their job functions. For example, employees in the Sales department can view expense reports but cannot approve or modify financial data. Which security principle is the administrator implementing?
Quick Answer
The correct answer is the principle of least privilege. This security concept dictates that users should be granted only the minimum permissions necessary to complete their job tasks, as demonstrated when Sales employees can view expense reports but cannot approve or modify financial data. By restricting access in this way, the attack surface is reduced, and the potential damage from a compromised account is contained. On the Microsoft SC-900 exam, this principle frequently appears in scenarios involving role-based access control (RBAC) in cloud applications like expense reporting or HR systems, often testing your ability to distinguish it from concepts like separation of duties or need-to-know. A common trap is confusing least privilege with zero trust—remember, least privilege is about limiting permissions, while zero trust is a broader security model. Memory tip: think “just enough access, just in time.”
⚠ Common exam trap
Watch out — candidates often confuse least privilege with separation of duties, because both involve restricting access, but separation of duties specifically requires splitting conflicting tasks (e.g., submit vs. approve) across different users to prevent fraud, whereas least privilege focuses on minimizing permissions per user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
The administrator is granting each employee only the permissions necessary to perform their job functions, such as Sales being able to view but not approve or modify financial data. This directly implements the principle of least privilege, which restricts access rights to the minimum required for legitimate tasks. In cloud-based applications like expense reporting systems, least privilege reduces the attack surface and limits potential damage from compromised accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a layered security strategy using multiple controls to protect assets; it does not strictly limit permissions per user role.
When this WOULD be correct
Defense in depth would be correct if the question described implementing multiple security layers (e.g., firewall, antivirus, encryption, and access controls) to protect the expense reporting application from various threats.
- ✓
Least privilege
Why this is correct
This is the correct answer because the administrator is granting the minimal permissions required for each employee's role, directly applying the least privilege principle.
- ✗
Separation of duties
Why it's wrong here
Separation of duties involves dividing critical tasks among multiple people to prevent fraud, not assigning minimal permissions per role.
When this WOULD be correct
A question where the administrator requires two different employees to approve and process expense reports to prevent a single person from both creating and approving payments would make separation of duties correct.
- ✗
Zero trust
Why it's wrong here
Zero trust is a security model that assumes no implicit trust and continuously verifies every access request, but it does not specifically focus on granting minimal permissions.
When this WOULD be correct
A question describing a network architecture where every access request, even from inside the corporate network, must be authenticated, authorized, and encrypted, with micro-segmentation and continuous monitoring, would make zero trust the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Least privilegeCorrect answer▾
Why this is correct
This is the correct answer because the administrator is granting the minimal permissions required for each employee's role, directly applying the least privilege principle.
✗Defense in depthWrong answer — click to see why▾
Why this is wrong here
Defense in depth is a layered security strategy using multiple controls, not about limiting permissions to only what is needed. The question describes assigning minimal permissions per job role, which is least privilege.
★ When this WOULD be the correct answer
Defense in depth would be correct if the question described implementing multiple security layers (e.g., firewall, antivirus, encryption, and access controls) to protect the expense reporting application from various threats.
Why candidates choose this
Candidates may confuse defense in depth with least privilege because both involve multiple security measures, but defense in depth focuses on layers, not on minimizing permissions.
✗Separation of dutiesWrong answer — click to see why▾
Why this is wrong here
The scenario describes assigning permissions based on job needs, which is least privilege. Separation of duties involves splitting critical tasks among multiple people to prevent fraud, not limiting permissions to the minimum necessary.
★ When this WOULD be the correct answer
A question where the administrator requires two different employees to approve and process expense reports to prevent a single person from both creating and approving payments would make separation of duties correct.
Why candidates choose this
Candidates may confuse 'separation of duties' with 'least privilege' because both involve restricting access, but separation of duties focuses on dividing tasks to prevent conflicts of interest, not on minimizing permissions per role.
✗Zero trustWrong answer — click to see why▾
Why this is wrong here
Zero trust is a security model that assumes no implicit trust and requires continuous verification for every access request, but the question describes assigning minimal permissions based on job roles, which is the principle of least privilege, not zero trust.
★ When this WOULD be the correct answer
A question describing a network architecture where every access request, even from inside the corporate network, must be authenticated, authorized, and encrypted, with micro-segmentation and continuous monitoring, would make zero trust the correct answer.
Why candidates choose this
Candidates may confuse zero trust with least privilege because both involve restricting access, but zero trust is broader and includes continuous verification, while least privilege focuses on minimal permissions.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's IT department implements a policy for server administrators: they must submit an access request to perform privileged tasks on critical servers. Each request is approved by a manager, and the granted elevated permissions automatically expire after four hours. This approach reduces the risk of standing privileges being exploited. Which security concept is primarily being applied?
medium- ✓ A.Just-in-time access
- B.Least privilege
- C.Defense in depth
- D.Zero Trust
Why A: Just-in-time (JIT) access is a security concept that grants elevated permissions only when needed, for a limited duration, and requires approval. In this scenario, the policy requires an access request, manager approval, and automatic expiration after four hours, which directly aligns with JIT access to reduce the risk of standing privileges being exploited.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.