The Principle of Least Privilege in Microservices: A Systematic Mapping Study

While Microservice Architectures (MSAs) offer enhanced scalability and maintenance, they introduce significant complexity for access control and, specifically, the rigorous enforcement of the Principle of Least Privilege (PoLP). This lack of clear privilege boundaries is a major security vulnerability in microservice-based systems. To address this gap, this study conducts a systematic mapping study to provide a comprehensive guide and taxonomy on implementing PoLP in MSA. We identify and categorize existing mechanisms, best practices, and the technical and non-technical challenges encountered during implementation. The systematic search identified 25 primary studies, revealing a significant contribution from journal venues, particularly Computers & Security. Key findings detail the top technical challenges, including performance overhead, fragile container isolation, and authentication/authorization gaps inherent in service-to-service communication. Proposed mechanisms are categorized into four groups: policy and access control, code and configuration hardening, runtime/kernel-level methods, and general frameworks. Similarly, organizational challenges are grouped by people/culture, tooling/architecture, process/governance, and resource/expertise. This study provides a valuable roadmap and taxonomy for diverse security stakeholders. The identified research gaps—concerning AI integration, DevSecOps adoption, education, and dynamic analysis—underscore the need to shift from the currently predominantly theoretical approaches towards practical, experimental research to advance the real-world application of PoLP.

Paper

Full text

PDF

The Principle of Least Privilege in Microservices: A Systematic Mapping Study

Semantic Scholar · 2026

Abstract

While Microservice Architectures (MSAs) offer enhanced scalability and maintenance, they introduce significant complexity for access control and, specifically, the rigorous enforcement of the Principle of Least Privilege (PoLP). This lack of clear privilege boundaries is a major security vulnerability in microservice-based systems. To address this gap, this study conducts a systematic mapping study to provide a comprehensive guide and taxonomy on implementing PoLP in MSA. We identify and categorize existing mechanisms, best practices, and the technical and non-technical challenges encountered during implementation. The systematic search identified 25 primary studies, revealing a significant contribution from journal venues, particularly Computers & Security. Key findings detail the top technical challenges, including performance overhead, fragile container isolation, and authentication/authorization gaps inherent in service-to-service communication. Proposed mechanisms are categorized into four groups: policy and access control, code and configuration hardening, runtime/kernel-level methods, and general frameworks. Similarly, organizational challenges are grouped by people/culture, tooling/architecture, process/governance, and resource/expertise. This study provides a valuable roadmap and taxonomy for diverse security stakeholders. The identified research gaps—concerning AI integration, DevSecOps adoption, education, and dynamic analysis—underscore the need to shift from the currently predominantly theoretical approaches towards practical, experimental research to advance the real-world application of PoLP.

Similar papers

© 2026 NYSGPT2525 LLC