← Custodia
Practice 2 of 15·FAR 52.204-21(b)(1)(ii)·ACAccess Control

AC.L1-b.1.ii

Limit what authorized users can do

Authorizing someone to log in is not the same as authorizing them to do everything. Limit each user to the transactions and functions their job actually requires — admin actions for admins, read-only for reviewers, no FCI access for unrelated roles.

Official text

Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

FAR 52.204-21(b)(1)(ii), CMMC Level 1 v2.13 Assessment Guide

What evidence satisfies this

Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:

  • A role list: e.g. owner = admin, PM = full FCI read/write, bookkeeper = invoices only, shop floor = drawings read-only.
  • Microsoft 365 / Google admin showing which users hold the Global Admin / Super Admin role (should be 1–2 people, not everyone).
  • Folder permissions distinguishing read-only vs read/write on the FCI folder.
  • On the ERP / quoting / accounting system: per-user permissions (not everyone is admin).
  • A documented "least privilege" rule of thumb the team understands and follows.

Common ways small shops fail this

  • Every user is a Global Admin in M365 / Google because "it's easier."
  • Everyone has read/write on the FCI folder, nobody has read-only.
  • Daily work done from the same admin account used for tenant management.
  • The bookkeeper has access to engineering drawings they don't need.
  • Shared logins to the shop PC that have local admin rights.

How to fix it in a weekend

  1. 1Inventory every system in scope (M365, ERP, file server, accounting). For each, list the roles you actually need.
  2. 2Demote everyone from admin who doesn't need it. Two named admins is plenty for a small shop.
  3. 3Set folder permissions to read-only for users who only consume FCI (e.g. shop floor reading drawings).
  4. 4Have admins do daily work from a regular user account and only switch to admin when needed.
  5. 5Add the least-privilege rule to your one-pager so a new hire knows the convention.

FAQ

Is "least privilege" required at Level 1?+

The exact phrase isn't in FAR 52.204-21, but the practical effect of (b)(1)(ii) is the same: limit users to the transactions and functions they're authorized to execute. Saying "everyone is admin because it's easier" is the textbook way to fail this practice.

Related references

Doing all 15 yourself? Use the checklist.

Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.

Open the checklist →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)