Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Types of Accounts and their Uses

...

This account will be tied to an individual user and that user will be responsible for keeping the account secure. For more details on privileged accounts and their use please refer to the Privileged Access Standard/wiki/spaces/uaiam/pages/52347250.  

The password for this account must follow the Network Password Requirements and cannot be the same as your personal account.  If available, the account and password should be stored in the University Controlled Password Manager.  

...

A vendor account can be requested for a vendor only after a contract is in place.  The account will follow the naming convention as established in the Privileged Access Standard/wiki/spaces/uaiam/pages/52347250 and is limited to non-privileged user activities such as using the University VPN. These accounts will be created and maintained in the OU Generic in Active Directory, and in People for 389.

...

If the vendor will be doing work that requires privileged access, they will be required to use a vendor administrative account using the established Privileged Access Standard/wiki/spaces/uaiam/pages/52347250.  The account should only be used for the purpose it was created for and will be stored in the OU Admin and can only be acted on by Domain Admins.

...

Service accounts will be created and follow the naming conventions as established in the Privileged Access Standard/wiki/spaces/uaiam/pages/52347250.  

When possible, password must be unique with a minimum length of 20 characters.

...

Service accounts will be created and follow the naming conventions as established in the Privileged Access Standard/wiki/spaces/uaiam/pages/52347250.  

Password must be unique with a minimum length must be 20 characters.

...

These accounts are intended for use to access such things as wikis, file shares , and research computing.  They are created and maintained in the OU Generic in Active Directory and in the People OU for 389. 

...

Type of AccountUsed to gain
Privileged Access
Password StoragePasswordUsed to authenticate a service or
application for Directory Services
NetID AccountNoUser's discretion to keep the password private and securePersonalNo
Administrative AccountYesEnterprise Password Management solutionPersonalNo
Vendor AccountNoUser's discretion to keep the password private and securePersonalNo
Privileged Vendor AccountYesEnterprise Password Management solutionPersonalNo
Service AccountYesEnterprise Password Management solutionnon-PersonalYes
Departmental AccountNoUser's discretion to keep the password private and securenon-PersonalNo
Generic AccountNoUser's discretion to keep the password private and securePersonalNo
Event Access AccountNoUser's discretion to keep the password private and securenon-PersonalNo

...