DA Form 7789, the Army’s Privileged Access Agreement and Acknowledgement of Responsibilities, is the document you sign before receiving administrative-level permissions on Department of Defense information systems such as NIPRNet or SIPRNet. It functions as your written acknowledgment of the rules governing privileged access and as a record that you meet the qualifications set by Army Regulation 25-2.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity If your duties involve modifying user permissions, changing system configurations, or accessing security logs, this form applies to you.
Where to Download the Form
The current version of DA Form 7789 lives on the Army Publishing Directorate site at armypubs.army.mil. Search for “7789” and download the PDF-fillable version.2Army Publishing Directorate. Army Publishing Directorate Save the file to your computer before you open it. Filling it out inside a web browser tends to break the signature fields, and the built-in PDF viewers in Windows and macOS will not process CAC-based digital signatures. Use Adobe Reader, and set it as your default PDF application.3MilitaryCAC. MilitaryCAC eSign Software Download Link and Install Page
Information to Gather Before You Start
The form ties elevated permissions to a named person, a named organization, and a named system. Have this in hand before you open it:
- Your full name, rank or grade, and DoD Identification Number.
- Your unit designation and the office symbol for the requesting organization.
- The specific information system you need privileged access to. Generic requests won’t clear review.
- Your current security clearance level, which must be at least equal to the classification of information processed by the system you’ll be managing.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity
- The exact date you last completed the annual Cyber Awareness Challenge. If it falls outside the last twelve months, expect a rejection until you retake it.4Cyber Exchange. Cyber Awareness Challenge
- Any professional certifications required for your work role under the DoD Cyberspace Workforce Qualification and Management Program.
Certifications: What Counts Now
AR 25-2 requires privileged users to obtain the appropriate certifications within six months of appointment and keep them current.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity The regulation still references the older DoD 8570.01-M, but that manual has been canceled and replaced by DoDM 8140.03, which took effect in February 2023.5Department of Defense Chief Information Officer. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program Under the new framework, qualifications are organized by cyberspace work role and proficiency level rather than the old IAT and IAM categories. The qualification matrices for each work role are published on the DoD Cyber Exchange. If you’re not sure which certifications apply to your position, check with your Information System Security Manager before you submit. Missing or expired certifications are one of the most common reasons the form comes back.
What Signing the Form Commits You To
DA Form 7789 puts a set of behavioral requirements in writing that go beyond what ordinary users face. AR 25-2 defines privileged users as individuals authorized to perform security-relevant functions that ordinary users cannot, and the form is the Army’s mechanism for holding you to that standard.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity
By signing, you consent to DoD monitoring, interception, and search of all activity on government systems.6Joint Base Elmendorf-Richardson. Notice and Consent – DoD Requires Compliance to Log On to Internet You agree not to install unauthorized software, not to connect unapproved hardware such as personal USB drives, and never to share your privileged credentials. Shared accounts break audit trails and make it impossible to attribute actions to a specific person. You also agree to report suspicious activity or security incidents through your chain of command.
Authentication rules apply too. Privileged users must use PKI credentials issued through the Army PKI registration authority for privileged access to NIPRNet, SIPRNet, DREN, and secure DREN systems, with alternative multi-factor authentication allowed only when specifically authorized by the Army CIO/G-6.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity You cannot use the same workstation profile for administrative work and general user activity.
Because these requirements flow from Army regulation, violating them can trigger charges under Article 92 of the Uniform Code of Military Justice, failure to obey a lawful order or regulation, which carries punishment as a court-martial may direct.7Office of the Law Revision Counsel. 10 USC 892 – Art. 92. Failure to Obey Order or Regulation Misuse of privileged access, even without malicious intent, can also result in permanent revocation of your security clearance and loss of privileged user status.
Signing with Your CAC
The form can be signed physically or digitally, and most organizations process it digitally with a Common Access Card.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity Open the saved PDF in Adobe Reader, click the pink ribbon icon in the signature field, and select your signing certificate when prompted. If you get an error about the Cryptographic Service Provider, try the alternate certificate. Switch from DOD CA to DOD EMAIL CA, or the reverse.3MilitaryCAC. MilitaryCAC eSign Software Download Link and Install Page
Who Signs After You
Once you sign, the form moves through a short approval chain:
- Your direct supervisor signs to confirm you have a valid mission requirement for privileged access and have completed the required background checks and training.
- The Information Assurance Manager, or a designated security official, performs a technical review to verify that the documentation complies with current DoD security directives before elevated permissions are granted in the system.
If either reviewer finds a gap, expired Cyber Awareness training, a missing certification, a clearance that doesn’t match the system’s classification level, the form comes back to you. The most common rejections are administrative misses: an outdated training date, an incorrect system name, or a lapsed certification the applicant didn’t notice.
After Approval and the AVS Change
Once fully signed, the form is archived in the organization’s security files. In the past, completed forms were also uploaded to the Army Training and Certification Tracking System (ATCTS). As of May 2025, the Army replaced ATCTS with the Account Validation System (AVS), which eliminates the need to manually route paper and PDF forms for network access requests.8The United States Army. Army Training and Certification Tracking System Sunsetting May 1, Replaced by Streamlined Account Validation System Check with your local security office for current guidance on whether DA Form 7789 is still processed as a standalone PDF at your installation or has been folded into the AVS workflow.
Keeping Access from Lapsing
Privileged access is not a one-time approval. Commanders and supervisors are responsible for monitoring privileged users to ensure they continue to meet the requirements in AR 25-2.1Kansas Adjutant General’s Department. Army Regulation 25-2 – Army Cybersecurity Your access can be revoked if your documentation falls out of compliance, such as an expired certification or lapsed Cyber Awareness training; if your duties no longer require elevated access; or if your command notifies the security office that privileged access is no longer needed, for instance during a PCS move or a change in duty assignment.
Keep your certifications current, retake the Cyber Awareness Challenge before it expires, and make sure your user profile documentation stays accurate. The easiest way to lose privileged access is not a security violation. It’s letting a training certificate lapse and having nobody catch it until the next annual review.