Files
Compose-Files/Backups/Miker/.trash/VPC Primary User Account Information.md
T
2026-07-20 09:23:17 -04:00

43 lines
5.8 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
**Summary****:**  This shared log-on solution, also referred to as the **Generic Vehicle Primary Client (GVPC) Log-on Solution**, has been engineered in response to a request from the CBP Passenger Systems Program Office (PSPO).  The solution is generally intended to promote faster lane-switching of CBP officers as lane assignments change during the course of the work shift, by allowing the officers to use a secure, shared log-on into the Windows desktop environment.  It eliminates the need to require officers to log out of Windows* when beginning or ending work at a particular vehicle primary inspection lane.  This should reduce the amount of non-productive time required by officers during a lane assignment change, and speed traveler processing through put.
 
_*The CBP Officers will still be required to log out of the VPC and other inspection applications while doing a lane assignment change. This is because the officers are required to use their individual application log-on credentials to access these applications, and these credentials must not be shared between officers._
 
 
_This Wiki doc highlights the WSG role in the process..Specifically how the GPO is applied to VPC Users_
 
_The full document can be found_ _https://cbpnetsecure.cbp.dhs.gov/sites/OIT/edme/edco/dco/osg/CBP_Documents/Documentation%20from%20Other%20Teams/VPC%20Generic%20User%20Logon%20Solution-drft-v2.docx_
_Design Highlights_
 
1. **The group policy object (GPO) VPC Primary** _(Active Directory object) is the core component of the solution.  This AD object is linked to the root of the CBP AD domain.  Security filtering is in place on this GPO which prevents it from being applied to any object that is not a member of the_ **SG-VPC-PRIMARY** _global security group.  The results of applying the GPO are primarily the lockdown of most non-application user functions in the Windows graphical user interface (GUI), such as file system browsing, command execution, user-level configuration changes.  No machine or application settings are changed through applying this GPO. The GPO has been linked to All Regional Production OU's_
3. **The VPC-Primary global security group SG-VPC-PRIMARY** _(Active Directory object) effectively controls which user accounts have the security controls enforced on them.  This is determined by user object membership in this group.  User account objects that are required to have the GVPC GPO settings applied to them will need to be made members of this global security group._
**The SG-VPC-PRIMARY** _group membership is automatically populated through an Active Directory Script that runs every 60 minutes. Shared logon accounts, when properly created and named, will automatically be made members._
_This Process ONLY works with Accounts that have the Prefix "VPC-"_
_FTO attempts to use a "PED-" prefix, (for Passenger Primary or other variations) will fail because the script only places VPC- accounts in the Security Group. A Security waiver is required to be obtained to add additional functionality._
 
_The Automation script maintained by the EDME/WSG group (Niel Razzano)_
                        **Hosting Server:                  Tnwg01a575**
                        **Script name:                      VPC-User.exe**
                        **Schedule:                           hourly**
             _If the Script appears to not be functioning, the TSC should be contacted, and supplied the VPC account name._
            _TSC can:_
_§_  _Manually modify the_ **SG-VPC-PRIMARY** _group_
_then_
_§_  _Should open a Remedy ticket, and placed in the WSG queue for the Script to be reviewed by WSG_
 
 
2. **Shared logon user account** _(Active Directory object) are created to provide a shared username and password combination that allows authorized personnel to log in to this account on CBP land border primary inspection workstations, and eliminate the need for them to use their own specific personal AD account.  This eliminates the need for CBP officers to spend time logging in / out of the Windows desktop environment during lane assignment changes.  This should reduce the lane inspection operations down time by several seconds or even a few minutes._ 
4. **GVPC shared user account naming standard**_:  These shared user accounts are identified by their use of the GVPC Shared Logon Solution naming standard: VPC-[Circuit site code].  One shared user account per site is permitted in this solution design; multiple shared accounts at one site will violate the naming standard.  As each site has a unique site code designation, no possibility of duplicate shared user account names exists._
_To determine the correct name for the VPC account, identify the Microsoft AD Root Organizational Unit of the Site. In the example below, the VPC account would be_
_VPC-ANR001A_
  
6. **Workstation restriction** _(implemented within Active Directory as a configured property of the shared user account object).  The shared user accounts are to be configured to allow logon only from designated vehicle primary inspection lane workstations.  Other inspection workstation types, such as secondary inspection workstations or passenger / pedestrian inspection machines, are not to be configured for shared user access under this solution.  If attempts are made to log in to the shared user account from any unauthorized workstation, the attempt will fail and the attempt will be logged to the security log._
\> From \<[https://uconnect.cbpnet.cbp.dhs.gov/sites/OIT/edme/edco/dco/osg/WSG%20Wiki/VPC%20Primary%20User%20Account%20Information.aspx](https://uconnect.cbpnet.cbp.dhs.gov/sites/OIT/edme/edco/dco/osg/WSG%20Wiki/VPC%20Primary%20User%20Account%20Information.aspx)\>