migrate
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
AD.CBP.DHS.GOV
|
||||
**Default Guest Account**
|
||||
"Guest/ xGuest" is disabled
|
||||
|
||||
**Auditing/Alerting**
|
||||
Changes to the Account (i.e. Enabled) generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff
|
||||
|
||||
**Default Admin Account**
|
||||
Renamed From “Administrator” to “RGMSWODNIW”
|
||||
The Account, by its nature cannot be disabled, it is in essence THE Admin Account for the Domain
|
||||
This is to prevent any potential lockout from the Domain. The account will always enable itself shortly after its disabled
|
||||
The Account is only used under the rarest of circumstances by Tier-0 Staff and Activity is monitored
|
||||
|
||||
|
||||
- The password is only known\accessible to WSG Tier-0 staff
|
||||
- The password is maintained in the WSG ADEX Password Database under “Protected Mode”
|
||||
- Only members of the Tier-0 Security Group “AD\ SG-WSG-ADEX-PWD-DB-Protected” have access to the password
|
||||
- Only WSG Tier-0 Staff, “Domain Admins”, have the ability to change the password
|
||||
- The Password is updated and changed every 6 months, and after each use for an enterprise process
|
||||
|
||||
|
||||
**Auditing/Alerting**
|
||||
|
||||
- Any Membership changes to the Tier-0 Security group “SG-WSG-ADEX-PWD-DB-Protected” generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff and CDS ISSOs
|
||||
- Changes to the Account (i.e. Password change ) generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff and CDS ISSOs
|
||||
- The Account is flagged in Microsoft ATA (Advanced Threat Analytics) to Alert the CBP SOC and WSG Tier-0 staff if this account is used to Authenticate to the Domain
|
||||
Reference in New Issue
Block a user