Remove administrative and privileged access
Manage role assignments and deprovisioning in DigiCert® Account Manager. When reviewing access, consider what those roles allow users to do in DigiCert® Trust Lifecycle Manager.
On termination or role change, remove the user's Trust Lifecycle Manager roles in Account Manager first.
Remove the user's business unit assignments in Trust Lifecycle Manager.
Reassign any certificate of ownership held by the departing user so that expiry notifications continue to reach a valid owner.
Disable any service users, agents, or sensors that the user provisioned and that are no longer required.
Rotate any shared credentials the user had access to, including connector credentials, API credentials, and enrollment secrets.
Confirm the removal in the audit log.
Perform a full recertification of privileged roles at least as often as your FedRAMP access review cycle requires. These roles include TLM admin, Manager, Recovery manager, and Certificate profile manager.