Files
Compose-Files/Backups/Miker/.trash/Procedure -D Developer Privileged Access to Workstations.md
T
2026-07-20 09:23:17 -04:00

4.0 KiB
Raw Blame History

WSG has a limited support role in Developer -D Accounts for Workstation Privileged Access and the implementation process
"-D" was designed, planned and configured by FSD
Escalation to WSG should only occur when trouble shooting steps indicate there is specific issues with Active Directory.
 
Below is an overview of the Configuration, Provisioning and Troubleshooting recommendation
 
Overview of -D Accounts Admin Access on Workstations
 
Configuration
FSD\DMG CREATES 2 GROUPS IN LOCATION
ad.cbp.dhs.gov/AccessControl/Groups Security/Developer Group Accounts (-D)/
SG-[SITE CODE]-Developer
SG-[SITE CODE]-Developers-PCs
 
FSD\DMG creates a Group Policy for the target Site Code And Linked to the Target SITE OU
GPO Name:[SITE-CODE]-WRKST-ADMIN-D
The group policy is configured:
A Security filter assigned to the SG-[SITE CODE]-Developers-PCs group
Computer Setting:
Restricted Group Policy for local Administrator to include "SG-[SITECODE]Developers" Group
Linked to the Target SITE OU, ensuring precedence is correct so it is the last Group Policy applied
 
Provisioning
Users request a -D account through Service Now "UAR Privileged (-M, -D) Account Request"
Service Catalog - Service Portal (servicenowservices.com)

Upon Approval, the TSD provisions the -D account , placing the account in the correct Site SG-[SITE CODE]-Developers group in which the Users workstation exists
The Users target Workstation is placed in the correct SG-[SITE CODE]-Developers-PCs in which the Users workstation exists
The User -D Account tab , “Log On To…” must have the target workstation added to the “Log On To…” Logon Workstations configuration item
 
 
Trouble shooting steps with escalation hierarchy
 
(TSD)
Verify
The User is in the correct SG-[SITE CODE]-Developers group
The Users Workstation is in the correct SG-[SITE CODE]-Developers-PCs group       
The User -D Account tab , “Log On To…” has the target workstation added to the “Log On To…” Logon Workstations configuration item
The User Workstation object is located in the correct OU to receive the correct Group Policy

TSD can and should handle "Disabled by CBP System Security 4/12/2024 inactive 30 days". Simply unlock the account and delete/clear the description. As this is most commonly caused by not verifying/not using Zscaler.
 
(FSD )
The Workstations must be receiving the Group Policy
  
Verify the Workstation is receiving the[SITE-CODE]-WRKST-ADMIN-D group policy
The Workstation object must be located in the correct OU to receive the correct Group Policy

Failure of Polices applying to a single Client indicates a client issue which should be resolved by FSD
 
Logon to the Target workstation and run CMD as an Administrator
At the command prompt run
GPRESULT /SCOPE COMPUTER /Z
 
Review results, 
The [SITE-CODE]-WRKST-ADMIN-D group policy should be under  "Applied Group Policy Objects"
If Seen, and the user still does not have Admin permissions, they are not in the correct SG-[SITE CODE]-Developers
 
If the  Applied Group Policy Objects is found under  "The following GPOs were not applied because they were filtered out"
The Workstation is not in the correct SG-[SITE CODE]-Developers-PCs
 
More Verbose error checking ,at the Elevated command prompt run GPRESULT /H C:\TEMP\GPRESULTS.HTML
Review the HTML file for any client errors, resolve the client errors
 
If the [SITE-CODE]-WRKST-ADMIN-D group policy is not seen at all, the Policy is most likely not configured correctly or does not exist
 
               HTML report indicates GPO corruption -Escalate to DMG
 
(DMG)
The Group Policy must be configured correctly and linked to the correct OUs
 
(WSG)
Group Policies are failing to get applied to an the Entire Site.