Skip to content
ControlVerdict
AC.L2-3.1.6addresses
AC.L2-3.1.6Non-privileged Account Use
Use non-privileged accounts or roles when accessing nonsecurity functions.
  • [a]

    nonsecurity functions are identified; and
  • [b]

    users are required to use non-privileged accounts or roles when accessing nonsecurity functions.

View full control

Day-to-day work on standard accounts; elevate only for admin tasks

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Non-privileged Account Use objectives.

Standard accounts. Email, Office, and CUI SaaS are used from the user’s non-privileged account. Local admin rights are removed from standard endpoints via MDM; developers get a separate elevated account that is not mailbox-enabled.

Security functions. Server and IdP administration happen only after switching to a privileged account on a PAW. The standard account cannot RDP to servers or open the IdP admin blade.

Maintenance. Monthly scan for reintroduced local admins. Privileged account inventory reviewed quarterly.

Accepted gap. Two lab instruments require a shared local login for the vendor. Those hosts are VLAN-isolated, no CUI at rest, and the password is dual-custody.

What the evidence looks like

  • MDM profile removing local admin from standard users
  • Network / CA policy blocking standard accounts from server RDP
  • Privileged account inventory
  • Lab instrument exception with VLAN evidence

Environment

Hybrid workforce; Windows endpoints; cloud IdP; PAW for server admins.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.