**CDS Privileged access**   New Privileged User provisioning process -M accounts are provisioned by the TSD following the Privileged User Account request                The Account provisioning does not grant Privileged access, just creates the account                Privilege Access to CDS Roles are below   -0 Accounts are provisioned as\if needed by WSG via a Windows Privileged Access Request in Service Now                               Approved by Gov Lead (Mike Mcfetridge)                               Approved by CDS ISSO   **Tier-0 CDS Privileged Access**                **Domain Admin**                               Restricted to Tier-0 independent Accounts (hashid-0)                                              Only WSG members have Tier-0 Accounts                               Persistent 5 members Allowed-Restricted to 5 WSG Senior Staff                               WSG staff are added\removed on a weekly basis for 24/7 On Call support                                                             Persistent membership is obtained through a ServiceNow Privileged access request                               Approved by Gov Lead (Mike Mcfetridge)                               Approved by CDS ISSO                    **Enterprise Admin**                               No persistent members- Only Tier-0 Accounts permitted                               Tier-0 Accounts added\removed as needed to perform Tasks on business need                               Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove                                                                            **Schema Admin**                               No persistent members- Only Tier-0 Accounts permitted                               Tier-0 Accounts added\removed as needed to perform tasks on business need                               Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove   **Tier-1 CDS Privileged Access**                **SG-DomainCtrl-ReadOnly**                               Restricted to Windows Service Group Employees                **SG-WSG-ADMIN**                                Restricted to Windows Service Group Members)                               Requested via Sailpoint [https://cbpidentity.cbp.dhs.gov/](https://cbpidentity.cbp.dhs.gov/)                Approval process is done via Email through sailpoint notifications                               User Supervisor Approves                               CDS Tier-O Approvers in EDMED_WSG_PROD_APP-APPROVER (5 WSG Senior Staff)   **Terminations**             Off Boarding and Termination of Access is done by the CSD\IDM Team via Sailpoint Separation process                Upon Separation, Sailpoint disables Active Directory User Objects and have all Group roles removed from the account privileged account                See CSD\IDM for more information     **Account deletions**                Active Directory has an automated process that deletes accounts after 90 days of inactivity