This commit is contained in:
Mike McFetridge
2026-07-20 09:23:17 -04:00
parent c1315882da
commit 72272e4006
3179 changed files with 562960 additions and 14 deletions
@@ -0,0 +1,26 @@
AD.CBP.DHS.GOV
**Default Guest Account**
"Guest/ xGuest" is disabled
**Auditing/Alerting**
Changes to the Account (i.e. Enabled) generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff
**Default Admin Account**
Renamed From “Administrator” to “RGMSWODNIW”
The Account, by its nature cannot be disabled, it is in essence THE Admin Account for the Domain
This is to prevent any potential lockout from the Domain. The account will always enable itself shortly after its disabled
The Account is only used under the rarest of circumstances by Tier-0 Staff and Activity is monitored
 
- The password is only known\accessible to WSG Tier-0 staff
- The password is maintained in the WSG ADEX Password Database under “Protected Mode”
- Only members of the Tier-0 Security Group “AD\ SG-WSG-ADEX-PWD-DB-Protected” have access to the password
- Only WSG Tier-0 Staff, “Domain Admins”, have the ability to change the password
- The Password is updated and changed every 6 months, and after each use for an enterprise process
 
**Auditing/Alerting**
- Any Membership changes to the Tier-0 Security group “SG-WSG-ADEX-PWD-DB-Protected” generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff and CDS ISSOs
- Changes to the Account (i.e. Password change ) generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff and CDS ISSOs
- The Account is flagged in Microsoft ATA (Advanced Threat Analytics) to Alert the CBP SOC and WSG Tier-0 staff if this account is used to Authenticate to the Domain