non-privileged user
A category of system account or role whose authorization scope is bounded to ordinary, task-specific functions and explicitly excludes security-relevant or administrative operations such as establishing accounts, configuring access controls, performing system integrity checks, or circumventing protective mechanisms. As defined in NIST SP 800-171, non-privileged users are individuals that do not possess appropriate authorizations — that is, they lack the elevated trust granted to privileged users. A privileged user, by contrast, is one "authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform" (NIST SP 800-53 Rev. 5 / CNSSI 4009-2022), so a non-privileged user occupies the complementary set. In practice, the field uses the expression to enforce the principle of least privilege: non-privileged user accounts must be used by default and elevated to root or administrator only when necessary, so that routine and daily activities are performed under non-privileged accounts, with Administrator/Root reserved for specific administrative actions. Controls such as NIST SP 800-53 AC-6 and NIST SP 800-171 3.1.7 operationalize th
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- non-privileged usersnonprivileged users
- possessive
- non-privileged user'snonprivileged user's
- pluralpossessive
- non-privileged users'nonprivileged users'