Skip to main content

Secure configuration guide for account management

Use this guide to securely configure, operate, and remove administrative and privileged access to your DigiCert ONE FedRAMP account.

DigiCert enforces required FedRAMP controls within the FedRAMP deployment. Administrators remain responsible for selecting sign-in methods, managing users, assigning least-privilege roles, protecting credentials, reviewing activity, and removing access when it is no longer needed.

For step-by-step instructions, see Quick links for account management.

Important

FedRAMP certification status

DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.

In this guide

The following sections explain how DigiCert ONE manages administrative access and how to securely access, configure, operate, and decommission users with administrative or privileged roles.

Section

What it covers

Account Manager controls

The identity, access, authentication, role, credential, and platform audit capabilities managed through Account Manager.

Standard and service users

The two DigiCert ONE user types and when each is appropriate.

Critical Account Manager roles and permissions

Role separation, permissions, least privilege, combined roles, and custom roles.

FedRAMP administrative account terminology

How FedRAMP terms such as top-level administrative account and privileged account map to DigiCert ONE users and roles.

DigiCert and customer security responsibilities

Which security controls DigiCert enforces and which configurations your organization manages.

Access users with top-level administrative permissions

Initial provisioning, two-factor authentication enrollment, individual administrator credentials, and account recovery.

Configure sign-in methods

Secure configuration considerations for account-wide sign-in methods.

Manage service users and API credentials

Secure access and credential management for applications and integrations.

Review platform activity and access

Platform audit logs and periodic reviews of users, roles, permissions, and credentials.

Decommission users with administrative or privileged roles

Removing roles, revoking credentials, transferring responsibilities, and disabling or deleting users.

Secure configuration history

Version and release history for secure configuration recommendations.