Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Types of Accounts and there Uses

...

Service accounts are accounts that are designated for use for a particular service or application.  A service account will be created for each function for a particular service or application, and must only be used for that purpose. The account must abide by the rules of least privilege as described by NIST.  These accounts will be created and maintained in the Generic OU in Active Directory and can only be acted on by Identity and Access Management. In 389 these accounts are to be stored in the OU People can only be acted on by ITS personalpersonnel.

Service accounts will be created and follow the naming conventions as established in the Privileged Access Standard.  

...

Type of AccountUsed to gain
Privileged Access
Password StoragePasswordUsed to authenticate a service or
application for Directory Services
Netid AccountNoUser's discretion to keep the password private and securePersonalNo
Administrative AccountYesEnterprise Password Management solutionPersonalNo
Vendor AccountNoUser's discretion to keep the password private and securePersonalNo
Privileged Vendor AccountYesEnterprise Password Management solutionPersonalNo
Service AccountYesEnterprise Password Management solutionnon-PersonalYes
Departmental AccountNoUser's discretion to keep the password private and securenon-PersonalNo
Generic AccountNoUser's discretion to keep the password private and securePersonalNo
Event Access AccountNoUser's discretion to keep the password private and securenon-PersonalNo

...