SDL Least-Privilege Token Rotation Causing Service Instability Concerns
Secure Design Phase Scope The Microsoft Security Development Lifecycle (SDL) requires applying the Principle of Least Privilege during the Design phase, using threat modeling to identify trust boundaries and reduce the attack surface. A documented element of this approach is replacing static credentials with short-lived tokens, automated rotation, and a mana