AC.L2-3.1.6Non-privileged Account Use
Use non-privileged accounts or roles when accessing nonsecurity functions.
[a]
nonsecurity functions are identified; and[b]
users are required to use non-privileged accounts or roles when accessing nonsecurity functions.
Day-to-day work on standard accounts; elevate only for admin tasks
Implementation
AO coverage. Addresses both Non-privileged Account Use objectives.
Standard accounts. Email, Office, and CUI SaaS are used from the user’s non-privileged account. Local admin rights are removed from standard endpoints via MDM; developers get a separate elevated account that is not mailbox-enabled.
Security functions. Server and IdP administration happen only after switching to a privileged account on a PAW. The standard account cannot RDP to servers or open the IdP admin blade.
Maintenance. Monthly scan for reintroduced local admins. Privileged account inventory reviewed quarterly.
Accepted gap. Two lab instruments require a shared local login for the vendor. Those hosts are VLAN-isolated, no CUI at rest, and the password is dual-custody.
What the evidence looks like
- MDM profile removing local admin from standard users
- Network / CA policy blocking standard accounts from server RDP
- Privileged account inventory
- Lab instrument exception with VLAN evidence
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.