non-privileged account
163579·updated Sep 1, 2026A managed access credential (user account or role) whose authorization scope is restricted to ordinary, non-administrative tasks — that is, it carries only the permissions required for routine work and is explicitly excluded from security functions such as administering accounts, modifying audit configurations, managing cryptographic keys, or changing access authorizations. Standards such as NIST SP 800-53 AC-6(2) require users who also hold privileged accounts to switch to non-privileged accounts when performing nonsecurity functions, because operating continuously from a privileged account needlessly expands the attack surface. The concept extends to roles under role-based access control, where a change of role can provide the same boundary as a change between a privileged and non-privileged account. In practice, controls across NIST SP 800-53, SP 800-171, and CMMC all use the term as the complement of "privileged account" to enforce least privilege: users must use non-privileged accounts or roles when accessing nonsecurity functions, and are prevented from executing privileged functions from those accounts.
Source
use non-the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- AC-6(2): Non-Privileged Access For Nonsecurity Functions - CSF Tools
- 3.1.6: Use non-privileged accounts or roles when accessing nonsecurity functions - CSF Tools
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
An access credential (account or role) granted to a user or process that carries only the permissions necessary for ordinary, non-administrative work—explicitly excluding elevated rights such as system administration, security-function execution, or root access. It is the contrasting class to a privileged account within the least-privilege model: unlike privileged accounts, non-privileged accounts do not have elevated privileges, meaning they do not have access to privileged systems and data. In practice, standards mandate that even users who *also* hold privileged accounts must use non-privileged accounts or roles when accessing nonsecurity functions, and conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user's primary, non-privileged account (CIS Controls). The concept extends to roles as well as accounts: the inclusion of roles addresses situations where organizations implement access control policies such as role-based access control and where a change of role provides the same degree of assurance in the change of access authorizations for both the user and all processes acting on behalf of the user as would be provided
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- non-privileged accounts
- possessive
- non-privileged account's
- pluralpossessive
- non-privileged accounts'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 4 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A managed access credential (user account or role) whose authorization scope is restricted to ordinary, non-administrative tasks — that is, it carries only the permissions required for routine work and is explicitly excluded from security functions such as administering accounts, modifying audit configurations, managing cryptographic keys, or changing access authorizations. Standards such as NIST SP 800-53 AC-6(2) require users who also hold privileged accounts to switch to non-privileged accounts when performing nonsecurity functions, because operating continuously from a privileged account needlessly expands the attack surface. The concept extends to roles under role-based access control, where a change of role can provide the same boundary as a change between a privileged and non-privileged account. In practice, controls across NIST SP 800-53, SP 800-171, and CMMC all use the term as the complement of "privileged account" to enforce least privilege: users must use non-privileged accounts or roles when accessing nonsecurity functions, and are prevented from executing privileged functions from those accounts.DR-088 backfill from the noun definition column