Files
Compose-Files/Backups/Miker/.trash/Configuration CDS Privileged access Process (WSG) 2.md
2026-07-20 09:23:17 -04:00

3.9 KiB

CDS Privileged access
 
New Privileged User provisioning process
-M accounts are provisioned by the TSD following the Privileged User Account request
               The Account provisioning does not grant Privileged access, just creates the account
               Privilege Access to CDS Roles are below
 
-0 Accounts are provisioned as\if needed by WSG via a Windows Privileged Access Request in Service Now
                              Approved by Gov Lead (Mike Mcfetridge)
                              Approved by CDS ISSO
 
Tier-0 CDS Privileged Access
               Domain Admin
                              Restricted to Tier-0 independent Accounts (hashid-0)
                                             Only WSG members have Tier-0 Accounts
                              Persistent 5 members Allowed-Restricted to 5 WSG Senior Staff
                              WSG staff are added\removed on a weekly basis for 24/7 On Call support
                             
                              Persistent membership is obtained through a ServiceNow Privileged access request
                              Approved by Gov Lead (Mike Mcfetridge)
                              Approved by CDS ISSO
 
 
               Enterprise Admin
                              No persistent members- Only Tier-0 Accounts permitted
                              Tier-0 Accounts added\removed as needed to perform Tasks on business need
                              Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
                                                           
               Schema Admin
                              No persistent members- Only Tier-0 Accounts permitted
                              Tier-0 Accounts added\removed as needed to perform tasks on business need
                              Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
 
Tier-1 CDS Privileged Access
               SG-DomainCtrl-ReadOnly
                              Restricted to Windows Service Group Employees
               SG-WSG-ADMIN 
                              Restricted to Windows Service Group Members)
              
               Requested via Sailpoint https://cbpidentity.cbp.dhs.gov/
               Approval process is done via Email through sailpoint notifications
                              User Supervisor Approves
                              CDS Tier-O Approvers in EDMED_WSG_PROD_APP-APPROVER (5 WSG Senior Staff)
 
Terminations
            Off Boarding and Termination of Access is done by the CSD\IDM Team via Sailpoint Separation process
               Upon Separation, Sailpoint disables Active Directory User Objects and have all Group roles removed from the account privileged account
               See CSD\IDM for more information
 
 
Account deletions
               Active Directory has an automated process that deletes accounts after 90 days of inactivity