home/thesaurus/non-privileged user

non-privileged user

nounverified·updated Sep 1, 2026

A category of system account or role whose authorization scope is bounded to ordinary, task-specific functions and explicitly excludes security-relevant or administrative operations such as establishing accounts, configuring access controls, performing system integrity checks, or circumventing protective mechanisms. As defined in NIST SP 800-171, non-privileged users are individuals that do not possess appropriate authorizations — that is, they lack the elevated trust granted to privileged users. A privileged user, by contrast, is one "authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform" (NIST SP 800-53 Rev. 5 / CNSSI 4009-2022), so a non-privileged user occupies the complementary set. In practice, the field uses the expression to enforce the principle of least privilege: non-privileged user accounts must be used by default and elevated to root or administrator only when necessary, so that routine and daily activities are performed under non-privileged accounts, with Administrator/Root reserved for specific administrative actions. Controls such as NIST SP 800-53 AC-6 and NIST SP 800-171 3.1.7 operationalize th

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.