52 lines
3.9 KiB
Markdown
52 lines
3.9 KiB
Markdown
**CDS Privileged access**
|
||
|
||
New Privileged User provisioning process
|
||
-M accounts are provisioned by the TSD following the Privileged User Account request
|
||
The Account provisioning does not grant Privileged access, just creates the account
|
||
Privilege Access to CDS Roles are below
|
||
|
||
-0 Accounts are provisioned as\if needed by WSG via a Windows Privileged Access Request in Service Now
|
||
Approved by Gov Lead (Mike Mcfetridge)
|
||
Approved by CDS ISSO
|
||
|
||
**Tier-0 CDS Privileged Access**
|
||
**Domain Admin**
|
||
Restricted to Tier-0 independent Accounts (hashid-0)
|
||
Only WSG members have Tier-0 Accounts
|
||
Persistent 5 members Allowed-Restricted to 5 WSG Senior Staff
|
||
WSG staff are added\removed on a weekly basis for 24/7 On Call support
|
||
|
||
Persistent membership is obtained through a ServiceNow Privileged access request
|
||
Approved by Gov Lead (Mike Mcfetridge)
|
||
Approved by CDS ISSO
|
||
|
||
|
||
**Enterprise Admin**
|
||
No persistent members- Only Tier-0 Accounts permitted
|
||
Tier-0 Accounts added\removed as needed to perform Tasks on business need
|
||
Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
|
||
|
||
**Schema Admin**
|
||
No persistent members- Only Tier-0 Accounts permitted
|
||
Tier-0 Accounts added\removed as needed to perform tasks on business need
|
||
Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
|
||
|
||
**Tier-1 CDS Privileged Access**
|
||
**SG-DomainCtrl-ReadOnly**
|
||
Restricted to Windows Service Group Employees
|
||
**SG-WSG-ADMIN**
|
||
Restricted to Windows Service Group Members)
|
||
|
||
Requested via Sailpoint [https://cbpidentity.cbp.dhs.gov/](https://cbpidentity.cbp.dhs.gov/)
|
||
Approval process is done via Email through sailpoint notifications
|
||
User Supervisor Approves
|
||
CDS Tier-O Approvers in EDMED_WSG_PROD_APP-APPROVER (5 WSG Senior Staff)
|
||
|
||
**Terminations**
|
||
Off Boarding and Termination of Access is done by the CSD\IDM Team via Sailpoint Separation process
|
||
Upon Separation, Sailpoint disables Active Directory User Objects and have all Group roles removed from the account privileged account
|
||
See CSD\IDM for more information
|
||
|
||
|
||
**Account deletions**
|
||
Active Directory has an automated process that deletes accounts after 90 days of inactivity |