Non-privileged Account Use
Practice statement
Use non-privileged accounts or roles when accessing nonsecurity functions.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.6.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
nonsecurity functions are identified; and
1 example covers this
- [b]
users are required to use non-privileged accounts or roles when accessing nonsecurity functions.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.6Non-privileged Account Use
Use non-privileged accounts or roles when accessing nonsecurity functions.
[a]
nonsecurity functions are identified; and[b]
users are required to use non-privileged accounts or roles when accessing nonsecurity functions.
Day-to-day work on standard accounts; elevate only for admin tasks
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses both Non-privileged Account Use objectives.
Standard accounts. Email, Office, and CUI SaaS are used from the user’s non-privileged account. Local admin rights are removed from standard endpoints via MDM; developers get a separate elevated account that is not mailbox-enabled.
Security functions. Server and IdP administration happen only after switching to a privileged account on a PAW. The standard account cannot RDP to servers or open the IdP admin blade.
Maintenance. Monthly scan for reintroduced local admins. Privileged account inventory reviewed quarterly.
Accepted gap. Two lab instruments require a shared local login for the vendor. Those hosts are VLAN-isolated, no CUI at rest, and the password is dual-custody.
What the evidence looks like
- MDM profile removing local admin from standard users
- Network / CA policy blocking standard accounts from server RDP
- Privileged account inventory
- Lab instrument exception with VLAN evidence
Environment
Hybrid workforce; Windows endpoints; cloud IdP; PAW for server admins.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.