Files
Compose-Files/Backups/Miker/.trash/Information CBP Active Directory Instances.md
T
2026-07-20 09:23:17 -04:00

38 lines
3.5 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
The purpose of this Wiki is to cover Active Directory management for non-mainstream domains.  It will not cover "how-to" manage them but instead will focus on how to access them so that they can be managed, as well as any significant details.  There are 4 basic Active Directory locations maintained by WSG, and the others are FYI.  We will only expand upon the 3rd and 4th entity as WSG provides primary support for them:
1. **Production AD** (AD.CBP.DHS.GOV):  This is where nearly all production users and applications reside. 
2. **PreProduction AD** (organizational unit "PreProduction" in Production AD): 
- The purpose of this location within prod is for systems destinted for production. 
- It is also commonly approved for development/testing activity where the non-prod system must interact with production.
3. **APP** ~~(APP.AD.CBP.DHS.GOV)~~
- ~~This is a production subordinate domain within Production AD.~~ 
- ~~It was implemented to satisfy a requirement for TASPO and has become TASPO's primary production location.~~ 
- ~~It is also the location of DHS employees who require access to CBP resources (e.g. ICE) like Sharepoint.~~
- ~~Access Instructions~~
- ~~Launch ADUC with elevated credentials~~
- ~~Right-click the upper-most part of the tree and select Change domain.  Type:  App.ad.cbp.dhs.gov~~
4. **SAT** (SAT.cbp.dhs.gov) 
- This domain is the location where testing activity is performed, where new builds are located when the request is "non-prod". 
- If a system is not being prepped for production, this is where it belongs. 
- Every sysetm in this domain must be referred to by the FQDN vs. the server Netbios name.  Example:  tnwg01a-v9999.SAT.CBP.DHS.GOV and not simply "tnwg01a-v9999". 
- Unlike the first 3 domains referenced, there are no Active Directory trust relationships established with this domain.  That means your AD credentials will not work.  We may change this since most of the work in this domain will be "please reset my password" or similar.  With a trust or syncronization, the user will use their AD password.
- Only a handful of WSG engineers have accounts here (as of this writing) but everyone should.
- Access Instructions
- Log / RDP into the system using SAT\yourUsername
- RDP to the SAT system(s) that you need to work with.  Or, if you need to add users/groups, you can connect to SAT domain controllers in the next bullet. 
- RDP into one of the SAT domain controllers:  TNVNWG001A0001.sat.cbp.dhs.gov, TNVNWG001A0002.sat.cbp.dhs.gov
5. **ATSPROD**:  This domain belongs to TASPO.  At one point it was to be retired but no timeline was established.  This domain trusts CBP AD (i.e. 1-way).  Since WSG does not offer primary support for this domain, TASPO engineers will reach out if necessary.
6. **ATSDEV**:  This domain belongs to TASPO and is supported entirely by TASPO. 
7. **DSA.DHS** (aka AppAuth):  This is DHS domain where all DHS services (like EaaS) are located.  
- From a memo dating back to mid-2014, we do or should have admin privlidges to the CBP OU. 
- Access Instructions (read-only)
1. Launch ADUC
2. Right-click the upper-most part of the tree and select Change domain.  Type:  DSA.DHS
\> From \<[https://uconnect.cbpnet.cbp.dhs.gov/sites/OIT/edme/edco/dco/osg/WSG%20Wiki/Active%20Directory%20Instances.aspx](https://uconnect.cbpnet.cbp.dhs.gov/sites/OIT/edme/edco/dco/osg/WSG%20Wiki/Active%20Directory%20Instances.aspx)\>