home/glossary/non-privileged account

non-privileged account

nounid 163579·updated Sep 1, 2026
verified

A managed access credential (user account or role) whose authorization scope is restricted to ordinary, non-administrative tasks — that is, it carries only the permissions required for routine work and is explicitly excluded from security functions such as administering accounts, modifying audit configurations, managing cryptographic keys, or changing access authorizations. Standards such as NIST SP 800-53 AC-6(2) require users who also hold privileged accounts to switch to non-privileged accounts when performing nonsecurity functions, because operating continuously from a privileged account needlessly expands the attack surface. The concept extends to roles under role-based access control, where a change of role can provide the same boundary as a change between a privileged and non-privileged account. In practice, controls across NIST SP 800-53, SP 800-171, and CMMC all use the term as the complement of "privileged account" to enforce least privilege: users must use non-privileged accounts or roles when accessing nonsecurity functions, and are prevented from executing privileged functions from those accounts.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0204
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
use non-the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

An access credential (account or role) granted to a user or process that carries only the permissions necessary for ordinary, non-administrative work—explicitly excluding elevated rights such as system administration, security-function execution, or root access. It is the contrasting class to a privileged account within the least-privilege model: unlike privileged accounts, non-privileged accounts do not have elevated privileges, meaning they do not have access to privileged systems and data. In practice, standards mandate that even users who *also* hold privileged accounts must use non-privileged accounts or roles when accessing nonsecurity functions, and conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user's primary, non-privileged account (CIS Controls). The concept extends to roles as well as accounts: the inclusion of roles addresses situations where organizations implement access control policies such as role-based access control and where a change of role provides the same degree of assurance in the change of access authorizations for both the user and all processes acting on behalf of the user as would be provided

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems4 citations · 4 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.06.b03.01.06.b ¶ 103.05.03 ¶ 103.05.04 ¶ 1

Classifications

Entity Type

Identity95%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

plural
non-privileged accounts
possessive
non-privileged account's
pluralpossessive
non-privileged accounts'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 4 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A managed access credential (user account or role) whose authorization scope is restricted to ordinary, non-administrative tasks — that is, it carries only the permissions required for routine work and is explicitly excluded from security functions such as administering accounts, modifying audit configurations, managing cryptographic keys, or changing access authorizations. Standards such as NIST SP 800-53 AC-6(2) require users who also hold privileged accounts to switch to non-privileged accounts when performing nonsecurity functions, because operating continuously from a privileged account needlessly expands the attack surface. The concept extends to roles under role-based access control, where a change of role can provide the same boundary as a change between a privileged and non-privileged account. In practice, controls across NIST SP 800-53, SP 800-171, and CMMC all use the term as the complement of "privileged account" to enforce least privilege: users must use non-privileged accounts or roles when accessing nonsecurity functions, and are prevented from executing privileged functions from those accounts.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.