NIST 800-171 Controls · Access Control
AC.2.006 — Use Non-Privileged Accounts for Non-Security Functions
Use non-privileged accounts or roles when accessing non-security functions.
What AC.2.006 means in plain English
Even your IT person (or you, as the owner) should not use their admin account for everyday tasks like checking email, browsing the web, or opening documents. Admin-level accounts are powerful — if someone tricks your admin account into running malware, it gets admin access to everything. Use a regular account for everyday work and only switch to admin when you truly need to.
The assessment question
“Does anyone with administrative or elevated privileges have a separate standard user account that they use for day-to-day activities like reading email and browsing the web, rather than using their admin account for everything?”
How to implement AC.2.006
- Create a second, standard (non-admin) Windows account for the IT administrator or owner that they use for all normal daily activity: email, web browsing, document editing.
- Reserve the admin account strictly for IT tasks: installing software, configuring settings, managing user accounts. Log out of admin and into the standard account as soon as the IT task is complete.
- In Microsoft 365, assign Global Admin rights to a break-glass admin account that is not used for daily email. The daily Microsoft 365 account should have a standard user license.
- Use Windows User Account Control (UAC) set to "Always Notify" (highest setting) so any attempt to run admin-level tasks from a standard account requires explicit admin approval.
- Document this requirement in your Access Control Policy: "Privileged accounts shall not be used for non-administrative activities."
Evidence your assessor will ask for
- Screenshot showing separate admin and standard accounts exist for IT administrator(s)
- Written procedure describing when admin accounts may be used
- UAC configuration screenshot showing "Always Notify" or equivalent setting
- Microsoft 365 admin role assignment showing daily-use account is not Global Admin
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.006 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.