About Anonymous Guest and Vendor Accounts
- Available to: Faculty and Staff
- Where to use: computers
- Cost: Free
Anonymous Guest Accounts
General Requirements
-
Must have sufficient justification for why anonymous Guest Account is needed
-
ISO Authorization
-
Network Operations Microsoft Team Lead Authorization
-
Written acceptance of the Customer Acceptance terms
Customer Acceptance
-
Account will be locked to only log on to specific machines (if possible).
-
Account password will need to be reset every 8 days.
-
Sponsors should be encouraged to change it after every use.
-
Sponsors should be told it changes every 7 days, the 8th day is to allow for passwords set one Monday won't expire in the middle of the day the following one.
-
Account will be deleted after 60 days of inactivity.
-
Account cannot self-change password, password can only be set by account sponsor(s).
Request
-
Upon receipt of request, ensure approvals are met:
-
ISO must authorize.
-
Customer must agree to the restrictions in the Customer Acceptance area via email.
-
Team lead must authorize.
-
Request must be logged through Cherwell.
-
Proceed to account creation.
Vendors
Requirements
Vendor accounts can be created with the following requirements.
-
When WebEx or other remote help options are not feasible
-
The following requirements should be communicated to the requestor
-
Each account must have a sponsor who is responsible for the account
-
The sponsor and the account will be able to change the password
-
The password will expire every 30 days
-
The password must be a minimum of 15 characters in length
-
The password must meet complexity requirements
-
The account will be deleted 180 days after the last password change (continuing to reset the password will keep the account alive indefinitely)
-
Account will be locked to specific machines
-
VPN use of the accounts will be permitted to specific machines
-
All requests must be reviewed and approved by Information Security
-
If the requester still requests a vendor account, the request should be forwarded to the Info Security Team
-
The Info Security Team will communicate with the requestor
-
The Info Security Team will send the approval/denial to the Windows Team
-
The Windows Team will send the request to Windows Support to get it into a Cherwell ticket
-
If approved, the Windows Team will setup the account and communicate the information to the requester
-
Close out the Cherwell ticket
Initial
When someone requests a vendor account, faculty and staff can email them these requirements. Please make sure to tell vendors they should reply stating that they agree with these requirements.
-
Each account must have a sponsor who is responsible for the account
-
The sponsor and the account will be able to change the password
-
The password will expire every 30 days
-
The password must be a minimum of 15 characters in length
-
The password must meet complexity requirements
-
The account will be deleted 180 days after the last password change
-
Account will be locked to specific machines
-
VPN use of the accounts will be permitted to specific machines
-
All requests must be reviewed and approved by Info Security
When the reply is received, forward it to IT Security. Let them know that a vendor account is being requested and they sponsor has agree with the requirements. Ask them to let us know when they approve/deny the request.
Renewal
If a vendor account is requested to be reactivated, they must go through the vetting process again and must get approval from Information Security.