migrate
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
**CDS Privileged access**
|
||||
|
||||
New Privileged User provisioning process
|
||||
-M accounts are provisioned by the TSD following the Privileged User Account request
|
||||
The Account provisioning does not grant Privileged access, just creates the account
|
||||
Privilege Access to CDS Roles are below
|
||||
|
||||
-0 Accounts are provisioned as\if needed by WSG via a Windows Privileged Access Request in Service Now
|
||||
Approved by Gov Lead (Mike Mcfetridge)
|
||||
Approved by CDS ISSO
|
||||
|
||||
**Tier-0 CDS Privileged Access**
|
||||
**Domain Admin**
|
||||
Restricted to Tier-0 independent Accounts (hashid-0)
|
||||
Only WSG members have Tier-0 Accounts
|
||||
Persistent 5 members Allowed-Restricted to 5 WSG Senior Staff
|
||||
WSG staff are added\removed on a weekly basis for 24/7 On Call support
|
||||
|
||||
Persistent membership is obtained through a ServiceNow Privileged access request
|
||||
Approved by Gov Lead (Mike Mcfetridge)
|
||||
Approved by CDS ISSO
|
||||
|
||||
|
||||
**Enterprise Admin**
|
||||
No persistent members- Only Tier-0 Accounts permitted
|
||||
Tier-0 Accounts added\removed as needed to perform Tasks on business need
|
||||
Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
|
||||
|
||||
**Schema Admin**
|
||||
No persistent members- Only Tier-0 Accounts permitted
|
||||
Tier-0 Accounts added\removed as needed to perform tasks on business need
|
||||
Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
|
||||
|
||||
**Tier-1 CDS Privileged Access**
|
||||
**SG-DomainCtrl-ReadOnly**
|
||||
Restricted to Windows Service Group Employees
|
||||
**SG-WSG-ADMIN**
|
||||
Restricted to Windows Service Group Members)
|
||||
|
||||
Requested via Sailpoint [https://cbpidentity.cbp.dhs.gov/](https://cbpidentity.cbp.dhs.gov/)
|
||||
Approval process is done via Email through sailpoint notifications
|
||||
User Supervisor Approves
|
||||
CDS Tier-O Approvers in EDMED_WSG_PROD_APP-APPROVER (5 WSG Senior Staff)
|
||||
|
||||
**Terminations**
|
||||
Off Boarding and Termination of Access is done by the CSD\IDM Team via Sailpoint Separation process
|
||||
Upon Separation, Sailpoint disables Active Directory User Objects and have all Group roles removed from the account privileged account
|
||||
See CSD\IDM for more information
|
||||
|
||||
|
||||
**Account deletions**
|
||||
Active Directory has an automated process that deletes accounts after 90 days of inactivity
|
||||
Reference in New Issue
Block a user