Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Types of Accounts and their Uses

All user accounts in Active Directory and 389 can only be created by ITS automatic provisioning infrastructure or by the Identity and Access Management Group.

...

When possible, password must be unique with a minimum length must be of 20 characters.

If available, the account and password must be stored in the approved University Controlled Password Manager.  

...

Departmental accounts will not be granted administrative privileges on any system and must not be used to authenticate services or applications to Active Directory or LDAP 389. 

...


Guest Access Account

A generic account is an account sponsored by an active University faculty or staff member and used to grant individual access.  These accounts, although may be used by an individual, do not guarantee any singular person is using the account.   

These accounts are intended for use to access such things as wikis, file shares , and research computing.  They are created and maintained in the OU Generic in Active Directory and in the People OU for 389. 

...

Type of AccountUsed to gain
Privileged Access
Password StoragePasswordUsed to authenticate a service or
application for Directory Services
NetID AccountNoUser's discretion to keep the password private and securePersonalNo
Administrative AccountYesEnterprise Password Management solutionPersonalNo
Vendor AccountNoUser's discretion to keep the password private and securePersonalNo
Privileged Vendor AccountYesEnterprise Password Management solutionPersonalNo
Service AccountYesEnterprise Password Management solutionnon-PersonalYes
Departmental AccountNoUser's discretion to keep the password private and securenon-PersonalNo
Generic AccountNoUser's discretion to keep the password private and securePersonalNo
Event Access AccountNoUser's discretion to keep the password private and securenon-PersonalNo

...