home/glossary/non-privileged access

non-privileged access

nounverified·updated Sep 1, 2026

A category of system access in which the account, role, or session carries only standard user permissions and is explicitly excluded from administrative, security-function, or other elevated capabilities reserved for privileged users. It is distinguished from privileged access by the absence of authorizations to execute security-relevant operations such as modifying system configurations, managing accounts, or administering cryptographic functions. In practice, frameworks use it both as a classification of access type and as an operational requirement — mandating that even users who hold privileged accounts switch to non-privileged accounts or roles whenever they perform ordinary, non-security functions, thereby limiting the attack surface exposed during routine work.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Unknown72%llm-generatedmulti_axis_classifier_queued.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
non-privileged accesses
possessive
non-privileged access's
pluralpossessive
non-privileged accesses'