Files
Compose-Files/Backups/Miker/.trash/Information Default Domain Accounts.md
2026-07-20 09:23:17 -04:00

26 lines
1.6 KiB
Markdown
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
AD.CBP.DHS.GOV
**Default Guest Account**
"Guest/ xGuest" is disabled
**Auditing/Alerting**
Changes to the Account (i.e. Enabled) generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff
**Default Admin Account**
Renamed From “Administrator” to “RGMSWODNIW”
The Account, by its nature cannot be disabled, it is in essence THE Admin Account for the Domain
This is to prevent any potential lockout from the Domain. The account will always enable itself shortly after its disabled
The Account is only used under the rarest of circumstances by Tier-0 Staff and Activity is monitored
 
- The password is only known\accessible to WSG Tier-0 staff
- The password is maintained in the WSG ADEX Password Database under “Protected Mode”
- Only members of the Tier-0 Security Group “AD\ SG-WSG-ADEX-PWD-DB-Protected” have access to the password
- Only WSG Tier-0 Staff, “Domain Admins”, have the ability to change the password
- The Password is updated and changed every 6 months, and after each use for an enterprise process
 
**Auditing/Alerting**
- Any Membership changes to the Tier-0 Security group “SG-WSG-ADEX-PWD-DB-Protected” generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff and CDS ISSOs
- Changes to the Account (i.e. Password change ) generates an alert by Quest Change Auditor, and is immediately emailed internally to WSG Tier-0 Staff and CDS ISSOs
- The Account is flagged in Microsoft ATA (Advanced Threat Analytics) to Alert the CBP SOC and WSG Tier-0 staff if this account is used to Authenticate to the Domain