non-privileged account
A managed access credential (user account or role) whose authorization scope is restricted to ordinary, non-administrative tasks — that is, it carries only the permissions required for routine work and is explicitly excluded from security functions such as administering accounts, modifying audit configurations, managing cryptographic keys, or changing access authorizations. Standards such as NIST SP 800-53 AC-6(2) require users who also hold privileged accounts to switch to non-privileged accounts when performing nonsecurity functions, because operating continuously from a privileged account needlessly expands the attack surface. The concept extends to roles under role-based access control, where a change of role can provide the same boundary as a change between a privileged and non-privileged account. In practice, controls across NIST SP 800-53, SP 800-171, and CMMC all use the term as the complement of "privileged account" to enforce least privilege: users must use non-privileged accounts or roles when accessing nonsecurity functions, and are prevented from executing privileged functions from those accounts.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 4 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A managed access credential (user account or role) whose authorization scope is restricted to ordinary, non-administrative tasks — that is, it carries only the permissions required for routine work and is explicitly excluded from security functions such as administering accounts, modifying audit configurations, managing cryptographic keys, or changing access authorizations. Standards such as NIST SP 800-53 AC-6(2) require users who also hold privileged accounts to switch to non-privileged accounts when performing nonsecurity functions, because operating continuously from a privileged account needlessly expands the attack surface. The concept extends to roles under role-based access control, where a change of role can provide the same boundary as a change between a privileged and non-privileged account. In practice, controls across NIST SP 800-53, SP 800-171, and CMMC all use the term as the complement of "privileged account" to enforce least privilege: users must use non-privileged accounts or roles when accessing nonsecurity functions, and are prevented from executing privileged functions from those accounts.DR-088 backfill from the noun definition column