Files
Compose-Files/Backups/Miker/.trash/Configuration CDS Privileged access Process (WSG).md
T
2026-07-20 09:23:17 -04:00

52 lines
3.9 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
**CDS Privileged access**
 
New Privileged User provisioning process
-M accounts are provisioned by the TSD following the Privileged User Account request
               The Account provisioning does not grant Privileged access, just creates the account
               Privilege Access to CDS Roles are below
 
-0 Accounts are provisioned as\if needed by WSG via a Windows Privileged Access Request in Service Now
                              Approved by Gov Lead (Mike Mcfetridge)
                              Approved by CDS ISSO
 
**Tier-0 CDS Privileged Access**
               **Domain Admin**
                              Restricted to Tier-0 independent Accounts (hashid-0)
                                             Only WSG members have Tier-0 Accounts
                              Persistent 5 members Allowed-Restricted to 5 WSG Senior Staff
                              WSG staff are added\removed on a weekly basis for 24/7 On Call support
                             
                              Persistent membership is obtained through a ServiceNow Privileged access request
                              Approved by Gov Lead (Mike Mcfetridge)
                              Approved by CDS ISSO
 
 
               **Enterprise Admin**
                              No persistent members- Only Tier-0 Accounts permitted
                              Tier-0 Accounts added\removed as needed to perform Tasks on business need
                              Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
                                                           
               **Schema Admin**
                              No persistent members- Only Tier-0 Accounts permitted
                              Tier-0 Accounts added\removed as needed to perform tasks on business need
                              Only the 5 WSG Senior Staff members in Domain Admins have the ability to add\remove
 
**Tier-1 CDS Privileged Access**
               **SG-DomainCtrl-ReadOnly**
                              Restricted to Windows Service Group Employees
               **SG-WSG-ADMIN** 
                              Restricted to Windows Service Group Members)
              
               Requested via Sailpoint [https://cbpidentity.cbp.dhs.gov/](https://cbpidentity.cbp.dhs.gov/)
               Approval process is done via Email through sailpoint notifications
                              User Supervisor Approves
                              CDS Tier-O Approvers in EDMED_WSG_PROD_APP-APPROVER (5 WSG Senior Staff)
 
**Terminations**
            Off Boarding and Termination of Access is done by the CSD\IDM Team via Sailpoint Separation process
               Upon Separation, Sailpoint disables Active Directory User Objects and have all Group roles removed from the account privileged account
               See CSD\IDM for more information
 
 
**Account deletions**
               Active Directory has an automated process that deletes accounts after 90 days of inactivity