Microsoft has quietly made a significant change to improve security across its Microsoft 365 platform: eliminating high-privilege access.
“Eliminating high-privilege access ensures that users and applications have only the necessary access rights,”
Naresh Kannan, Deputy Chief Information Security Officer for Experiences and Devices at Microsoft, said.
“Our strategy within Microsoft’s internal Microsoft 365 environment involved fostering an ‘assume breach’ mindset, with a focus on the stringent enforcement of new standard authentication protocols.”
The company has now eliminated over 1,000 scenarios where applications had excessive access, allowing apps or services to do more than necessary. While broad permissions can expedite many IT processes, they are increasingly seen as too great a risk in the case of a cyber breach. As a result, Microsoft engaged more than 200 engineers across the company to review these accesses.
Examining Microsoft's Access Change
As part of Microsoft’s Secure Future Initiative, this move focuses on strengthening cloud security by applying the principle of least privilege—granting applications only the minimum access required to perform their functions.
Previously, legacy authentication protocols allowed applications to maintain broad permissions, creating unnecessary security vulnerabilities. Microsoft reviewed and redesigned how applications interact within the Microsoft 365 ecosystem, identified these weaknesses, and moved to adopt more granular permission models combined with stronger authentication methods to reduce risk.
Microsoft’s approach to eliminating high-privilege access involved a comprehensive three-phase process. The first phase was a review of Microsoft 365 applications and their service-to-service interactions with resource providers such as SharePoint and Exchange. This audit uncovered numerous instances where applications held permissions far beyond what was operationally necessary.
In the second phase, Microsoft deprecated legacy authentication protocols that inherently supported these broad access patterns. These older methods, once essential for compatibility, had become security liabilities. Microsoft replaced them with modern, secure authentication protocols designed to enforce minimal privilege. For example, applications that previously had permissions like “Sites.Read.All” for SharePoint now receive more precise “Sites.Selected” permissions, limiting access only to the specific sites required.
The third phase involved deploying standardized monitoring systems that continuously scan for any remaining high-privilege access within Microsoft 365 applications. These monitoring tools provide real-time alerts to security teams, ensuring ongoing compliance with the new least-privilege standards.
Why IT Leaders Need to Take Note
The elimination of high-privilege access addresses a critical vulnerability that attackers have long exploited.




