Can machinists share one login on the shop floor PC under CMMC?

Machinists won't type a password at the kiosk, and management agrees. A shared login still fails the requirement. Here are the fast sign-in options that pass, and the floor rules for phones, travelers and visitors.

One login per machinist. Badge tap or phone approval. No photos, not no phones. Building as the container. Working guide.
In this guide

Updated September 30, 2026

An IT admin at a machine shop put the problem on r/sysadmin better than we could. The machinists pull programs and clock in and out of jobs on one PC by the machines, and "management thinks it's too much of an inconvenience" for each of them to sign in and out. So everyone uses the one account that's always logged in.

No. If that PC can open a controlled drawing or program, every person who uses it needs their own sign-in. The good news is that signing in doesn't have to mean typing a username and password twenty times a shift. A badge tap or a phone approval works. And a lot of what happens on the floor, like paper travelers, phones in pockets and the delivery driver at the dock, needs a posted rule rather than new technology.

Some terms first. CUI (controlled unclassified information) is the drawings, models and specs the government marks as sensitive. CMMC Level 2 is the Pentagon's check that suppliers holding CUI meet 110 security requirements. You post a score to the DoD's SPRS site that starts at 110 and loses points for each requirement you miss. Fall under 88 and you can't claim a passing status at all.

What the rules ask for

Three requirements sit behind that "no." In plain words, with the requirement numbers your IT person will want:

  • Every person using a system has their own identity, rather than a shared "SHOP1" account (3.5.1, worth 5 points).
  • The system checks that the person really is who they say they are before letting them in (3.5.2, 5 points).
  • Every action can be traced back to the one person who did it, so they can be held accountable (3.3.2, 3 points).

The wording comes from NIST SP 800-171, and the point values from the DoD Assessment Methodology. A shared floor login fails the first and the third outright, so one PC costs you 8 points.

Two more details decide which sign-in you need. A second login factor is required for anyone reaching a system over the network, meaning a file share, the ERP or Microsoft 365. It's not required for someone signing in at the keyboard to a PC that holds nothing (3.5.3). Most floor PCs open drawings from a server, so plan on two factors. And the screen has to lock after a period of inactivity that you choose and write down (3.1.10). Ten minutes suits a floor PC. Nobody wants to wait through 30 seconds of sign-in because the lock kicked in mid-setup.

If the shop floor computer can't reach any CUI at all, none of this applies to it. If all it runs is a time clock and the schedule board, leave it alone. The question is only ever what the PC can open.

The options

Here's how the sign-in methods compare for a PC shared by one or two shifts.

Option What the machinist does Second factor? The catch Our verdict
Typed username and password, with Windows fast user switching Types credentials, signs out when done No, unless you add one Slow. Nobody signs out, so the next person works under the last person's name. Fine for 3 to 5 users who rarely switch.
Windows Hello for Business (fingerprint or face) Touches a reader or looks at the camera Yes. Microsoft counts Hello for Business as two factors. A limit of 10 enrolled people per PC (Microsoft). Gloves, oil and cut fingers defeat fingerprint readers. Good for a cell with 10 or fewer operators.
Web sign-in with Microsoft Authenticator Picks Web sign-in, approves on their phone Yes Windows 11 22H2 or later, joined directly to Microsoft Entra rather than an on-site domain, and online. There's no offline sign-in (Microsoft). It also needs a work phone app on a personal phone. Our default if you're on Microsoft 365 and Intune.
NFC security key (a FIDO2 key tapped on a reader) Taps the key, enters a PIN Yes Needs an NFC reader on each PC, and people lose keys (Microsoft). Good for more than 10 users, and Microsoft's own recommendation there.
Badge tap-and-go (Imprivata and similar) Taps the door badge plus a PIN at the start of shift, then just the badge at any PC Yes, badge plus PIN Priced by quote only (Imprivata). "Obscenely expensive," as one r/sysadmin commenter put it. Worth it at 100+ floor users across many terminals.

For the IT person: Web sign-in is enabled in Intune under Settings catalog → Authentication → Enable Web Sign In, and it works on Windows Pro. To wipe each person's profile when they sign out, add Intune's Shared PC mode, which allows one person signed in at a time and can delete accounts immediately after sign-out (Microsoft). Set its Guest account option to Domain. A guest account needs no credentials, the exact thing you're trying to remove.

The shop in that r/sysadmin thread tried fingerprints first and hit the 10-person limit. They didn't want tokens to lose, so they chose RFID readers, because "they already need badges to get in the doors." That's a sound call for a shop that size. Just know that most door badges are simple proximity cards. Getting one to log into Windows takes add-on software, which is what you're paying Imprivata or a competitor for.

The kiosk that doesn't need any of this

There's a cheaper pattern, and plenty of shops can use it. Some floor PCs only run the ERP or MES (the software that tracks jobs), and that software has its own login for each person. In that case, lock the Windows side down to that one app as a kiosk. The kiosk account can't open file shares, a browser or the drawing folder. Each machinist then signs into the app with their own name, and the app's own log records who did what. Test it by signing in as the kiosk and trying to open the drawing share. If the share opens, the pattern fails and you're back to the table above.

The screen everyone can see

Leave the big-screen schedule board as it is. A shared, read-only display that shows job numbers, due dates and machine status holds no CUI, so it's out of scope.

The line is the drawing. A screen that displays the part print to anyone walking by, with nobody signed in, is CUI on an unauthenticated system. Keep drawings on paper at the machine, or on a PC someone has signed into.

Phones

A no-photos rule is enough. You don't need to confiscate phones. On an r/CMMC thread about exactly this, the top answer was simply: "Policy that says no photos/videos in the area will work." We agree. No CMMC requirement bans phones on a shop floor. The risk is the camera, and a written rule plus signs handle it. A phone becomes an in-scope device only when it connects to your systems to open CUI, for example a personal phone with Outlook syncing a mailbox that receives drawings. That's a separate decision, covered in BYOD and remote work. The phone in a machinist's back pocket doesn't count.

Travelers, visitors and the truck at the dock

Paper counts. The requirement to physically control and securely store media covers "paper and digital" (3.8.1, 3 points). That still doesn't mean locking every traveler in a drawer between operations.

The approach shops defend successfully treats the building as the container. Everyone with unescorted access to the floor has taken CUI training, the doors are controlled, and CUI stays inside. Paper moves freely inside that container. At the end of the shift, or when the job leaves the floor, travelers go into a closed cabinet or a covered folder. One r/CMMC commenter reported passing a C3PAO certification with a store-at-end-of-day rule and cover sheets. That was an office, but the logic carries to a shop. The free DoD CUI course from CDSE covers the training (CDSE).

What breaks the container is people without that access. Visitor rules carry a trap. Escorting visitors (3.10.3), keeping a physical access log (3.10.4) and controlling keys and badges (3.10.5) are worth only 1 point each. They are also on the short list of requirements that can never go on a fix-it plan for conditional status (32 CFR 170.21). Miss one and you have no conditional status to fall back on.

  • Truck drivers and couriers stay at the dock. Mark a line on the floor. Anything on the route from the dock door to the shipping bench, including travelers, prints and ITAR parts, gets covered.
  • Customer tours get an escort, a sign-in, and a quick walk ahead of the group to flip travelers face down. If a visitor is a foreign person and the part is ITAR, letting them look at the drawing is a "release" of technical data under export law (22 CFR 120.56). Keep ITAR jobs off the tour. More on ITAR registration.
  • Machine builder and repair techs sign in and stay escorted. The remote-support side of their visit is in the old-controls guide.

The card to post

Print this and put one by the time clock and one on each shared terminal. Every line maps to a requirement above, and an assessor will ask a machinist at least one of them.

Shop floor rules: controlled jobs

  1. Sign in as yourself. Tap your badge or approve on your phone. Never work under someone else's name.
  2. Walking away? Lock the screen (Windows key + L). It locks itself after 10 minutes.
  3. No photos or video on the floor. Phones stay in your pocket near controlled jobs.
  4. Travelers stay with the job. At end of shift, they go in the cell cabinet.
  5. Scrap prints go in the locked shred bin, never the trash.
  6. Visitors are escorted and signed in. Drivers stay at the dock line.
  7. Tour coming through? Flip travelers face down.
  8. USB sticks: only the numbered cell sticks, only at the machines.
  9. See something off? Tell [name] at [extension] the same shift.

Common questions

Can the lead just sign in at 6 a.m. and leave it logged in all shift? No. Everything done under the lead's name is then attributed to the lead, which fails traceability. It also means the lead answers for any mistake on that PC for the whole shift.

What about the operators who share one machine's control panel? The CNC control itself is a Specialized Asset. The rule doesn't assess it against the login requirements. The sign-in obligation lands on the PC that feeds it programs.

Mock assessment

Know which floor PCs can open a drawing.

Garde1 builds your scope from where CUI lives and who touches it, records your visitor handling and hard-copy storage for each office, and scores all 110 requirements in a mock assessment, so the shared-login gap shows up with its point value before an assessor finds it.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE