iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Enforce least privilege by giving each AI agent a distinct identity, only the tools and functions its task needs, and credentials limited to the required resources and actions. Put authorization checks in the downstream service or a trusted policy layer on every call—not in the model’s instructions—and require human approval for consequential actions.
What least privilege means for an AI agent
An agent’s effective authority is the combined reach of its identity, selectable tools, exposed tool functions, credentials, and the resources those credentials can access. A narrowly named tool is not least-privileged if the credential behind it can read unrelated data or make unrestricted changes. OWASP groups common risks as excessive functionality, excessive permissions, and excessive autonomy in its LLM06:2025 Excessive Agency guidance.
Apply restrictions across that whole chain. Removing an unnecessary tool does not compensate for an overbroad credential, and a scoped credential does not make an unrestricted tool interface safe. Also review permissions together: Microsoft warns that several individually narrow roles can combine into broad effective access in its least-privilege guidance for AI agents.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Choose the identity for the job
Decide whether the agent is acting on behalf of a signed-in user or running a background workflow. The choice determines whose permissions the downstream service should enforce; it should not be made merely for implementation convenience.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Access pattern | Use when | Scope and accountability |
|---|---|---|
| Delegated user access | The agent acts on a signed-in user’s data, and the downstream service should enforce that user’s access. | Keep the delegated permissions aligned with the task and the user’s authority. See Microsoft’s access-pattern guidance. |
| Application-only access | A background automation has no signed-in user and needs to act as an application. | Grant only the permissions required for the workflow and limit access to the relevant resources and operations. Where supported, managed identities can avoid handling stored secrets for service-to-service access. See Microsoft’s access-pattern guidance. |
An agent-specific identity can make actions easier to attribute and access easier to govern through its lifecycle; it is an implementation pattern, not a universal platform requirement. For either pattern, assess expiry, revocation, auditability, resource scope, and the consequences of each permitted action. Do not let a collection of grants across services quietly exceed what the workflow needs.
Reduce what the agent can do before it runs
- Write down the task and required resources. Specify the data, tenant, and operations the workflow needs. Treat everything outside that boundary as unnecessary by default.
- Remove unneeded tools. An agent should not be offered tools merely because they are available elsewhere in the application.
- Narrow retained tools to specific functions. Replace broad capabilities—such as arbitrary shell execution—with constrained operations that expose only the required actions and inputs.
- Scope the external identity and credentials. Restrict them to the needed resources, fields, tenants, and operations. Review the effective access across all connected systems, not just each grant in isolation.
- Revisit access when the workflow changes. Remove permissions that are no longer needed and provide a way to revoke access promptly.
This is a design-time reduction in capability; it does not replace authorization at runtime.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Authorize every tool call outside the model
The model may choose a function and supply its arguments, but it must not be the authority that decides whether the action is allowed. Microsoft’s Agent Safety guidance puts the risk plainly: “The AI can call any function you provide as a tool and choose the arguments.” OWASP likewise says to “Implement authorization in downstream systems rather than relying on an LLM to decide if an action is allowed or not” in its Excessive Agency guidance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
For each call, a downstream API or trusted policy enforcement point should check the acting identity, the resource, the requested operation, and the applicable user or workflow authorization. Reject a request that falls outside the policy even if the model has been prompted not to make it. Keep the authorization check in place after any approval step; approval does not expand the agent’s underlying grant.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Separate low-risk work from consequential actions
Do not bundle read-only or draft capabilities with actions that create external side effects. A useful design is to let the agent retrieve information or prepare a proposed change, while a separate operation performs the send, submit, update, delete, or permission change. This makes the boundary visible in the tool interface and gives policy checks a clear action to evaluate.
Require explicit human approval for high-impact, broad-impact, or hard-to-reverse actions. Present the actual target and proposed change for approval, rather than a vague description of what the agent intends to do. After approval, re-check authorization at the downstream service and execute only the approved operation. Microsoft’s access-pattern guidance and Agent Safety guidance support controls around agent access and actions; the approval threshold should reflect the consequences of the particular workflow.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Validate arguments and treat retrieved content as untrusted
Model-generated arguments, retrieved documents, emails, and tool results are inputs—not trusted instructions or policy. Indirect prompt injection can put hostile directions in content the agent later reads, attempting to steer a permitted tool toward an unintended action. Input validation can reduce this risk, but only an independent authorization boundary can prevent an unauthorized operation.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches- Check arguments against allow-lists, expected types, and valid ranges.
- Restrict paths and resource identifiers to those the workflow is permitted to use.
- Use parameterized queries rather than building queries from model-supplied strings.
- Keep retrieved content separate from system instructions, and do not treat instructions found in external content as authorization.
- Reject malformed or out-of-scope requests instead of trying to repair them into broader actions.
These safeguards complement per-action authorization; none makes it safe to give the agent a credential with unnecessary reach. See Microsoft’s Agent Safety guidance and OWASP’s Excessive Agency guidance.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Make actions attributable, reviewable, and revocable
Record enough context to reconstruct what happened: the agent identity, the user or workflow that authorized the action, the tool and scope involved, the requested operation, and whether policy and approval checks succeeded. Monitor tool activity for unexpected patterns, review grants as tasks change, and ensure operators can revoke access. Step or rate limits can help limit damage or surface abnormal behavior, but they are not substitutes for narrow permissions and runtime authorization. OWASP’s mitigations and Microsoft’s least-privilege guidance address monitoring and access governance.
Responsibility does not disappear when an agent uses a hosted model or platform. Microsoft’s AI agent shared responsibility model says responsibilities vary by deployment, while customers remain accountable for areas including agent identity and credential scope, action authorization, data, oversight, and governance.
What remains unsettled
Some workflows cannot predict every action an agent may need in advance, and authorization may need to respond to changing context. NIST NCCoE’s February 2026 paper, Accelerating the Adoption of Software and AI Agent Identity and Authorization, raises questions about these challenges, including how to bind agent actions to human authorization and verifiable audit records. It is a concept paper soliciting input, not a finalized standard or settled implementation rule. Until common approaches are established, keep authorization explicit, narrow, and independently enforceable for each action.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

