Standards Group:
YALE-MSS-9: Authentication and Authorization
YALE-MSS-9.10: Use administrative and service accounts for their assigned function only
Low Risk Endpoint
Required
Moderate Risk Endpoint
Required
High Risk Endpoint
Required
Low Risk Server
Required
Moderate Risk Server
Required
High Risk Server
Required
Low Risk Mobile Device
Required
Moderate Risk Mobile Device
Required
High Risk Mobile Device
Required
Low Risk Network Printer
Required
Moderate Risk Network Printer
Required
High Risk Network Printer
Required
Details
Administrative accounts hold elevated privileges and service accounts often perform functions not accessible to standard users.
An administrative or service account must not be used when a standard user account can perform the assigned function in question.
Adjustment of privileged account permissions must be performed by the provisioner of the account and never the user of the account or a third-party.