Skip to content
ControlVerdict
AC.L2-3.1.6CMMC Level 2Level 2

Non-privileged Account Use

Practice statement

Use non-privileged accounts or roles when accessing nonsecurity functions.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.6.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    nonsecurity functions are identified; and

    1 example covers this

  2. [b]

    users are required to use non-privileged accounts or roles when accessing nonsecurity functions.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.6Non-privileged Account Use
    Use non-privileged accounts or roles when accessing nonsecurity functions.
    • [a]

      nonsecurity functions are identified; and
    • [b]

      users are required to use non-privileged accounts or roles when accessing nonsecurity functions.

    Day-to-day work on standard accounts; elevate only for admin tasks

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Non-privileged Account Use objectives.

    Standard accounts. Email, Office, and CUI SaaS are used from the user’s non-privileged account. Local admin rights are removed from standard endpoints via MDM; developers get a separate elevated account that is not mailbox-enabled.

    Security functions. Server and IdP administration happen only after switching to a privileged account on a PAW. The standard account cannot RDP to servers or open the IdP admin blade.

    Maintenance. Monthly scan for reintroduced local admins. Privileged account inventory reviewed quarterly.

    Accepted gap. Two lab instruments require a shared local login for the vendor. Those hosts are VLAN-isolated, no CUI at rest, and the password is dual-custody.

    What the evidence looks like

    • MDM profile removing local admin from standard users
    • Network / CA policy blocking standard accounts from server RDP
    • Privileged account inventory
    • Lab instrument exception with VLAN evidence

    Environment

    Hybrid workforce; Windows endpoints; cloud IdP; PAW for server admins.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.