Admin Systems Management
Privileged Certifier Account Authorization - S-1 Procedural Page
Authorize MCTFS certifiers and UD-MIPS Certifier roles through NIS approver groups, with privileged access agreement, training, and monthly audit.
T&R Event Details
- Event Code
- 0102-GENA-1015
- Source Policy
- MCO 5239.2B
- MOS Performing
- 0102, 0111, 0170
- Grades
- SSgt, GySgt
- Sustainment Interval
- 12 months
- Evaluation-Coded
- No
- Readiness-Coded
- No
Performance Steps (T&R)
- Validate the candidate's grade and date of rank against the certifier threshold
- Confirm completion of certifier-specific training
- Sign the privileged access agreement and draw the NCPASS token
- Submit the MCTFS certifier SAAR through AutoSAAR to MISSA
- Activate the certifier account
- Test certifier function on a sample diary line
- Document authorization in a Page 11 entry
- Audit the certifier list each month against the diary log
- Reauthorize certifiers annually through training renewal
- Suspend certifier access on misconduct or pending investigation
Role and responsibility
The S-1 officer (0102) signs every privileged certifier authorization. The S-1 chief (0111 SSgt or higher) supervises certifier training and audits the certifier list monthly. The unit security manager validates the certifier's privileged access agreement against the cybersecurity baseline. The IPAC certifier coordinator runs parallel authorization for installation-tied certifier roles.
Source documents flow from grade and date-of-rank verification, certifier-specific training certificates, signed privileged access agreements, and the unit certifier roster. The MCTFS certifier SAAR routes through AutoSAAR to MISSA for validation, then TSO Mainframe Security provisions the role. UD-MIPS Certifier roles route through Naval Identity Services (NIS) Information Owner approver groups. Outputs include the activation confirmation, the certifier roster entry, the Page 11 documenting authorization, and the OMPF Field Folder systems tab entry.
MCAAT inspects the certifier roster against the privileged access agreement file, the monthly audit signature, and the diary certification log. A certifier signing diary lines without a current privileged access agreement triggers a finding under MCO 5239.2BMCO 5239.2B. Authorize before activate, audit monthly.
Trigger events
- 0111 reaches SSgt with sufficient date of rank for certifier role.
- Billet change moves a Marine into a certifier-required position.
- Outgoing certifier detaches and the unit needs a replacement.
- Annual certifier reauthorization window opens.
- Misconduct event requires certifier suspension.
- New certifier-specific training release requires recertification.
- Audit identifies an unauthorized certifier on the roster.
Processing workflow
- Validate grade and date of rank. Confirm the candidate holds SSgt or higher with sufficient DoR per the local certifier policy and MCO 5239.2BMCO 5239.2B Chapter 4. The S-1 chief validates.
- Confirm certifier-specific training. Verify completion of MCTFS certifier training, UD-MIPS certifier training, and current annual cyber awareness training per DOD 8500.01EDOD 8500.01E.
- Sign the privileged access agreement. The candidate signs the privileged access agreement acknowledging certifier responsibilities. The unit security manager countersigns per MCO 5239.2BMCO 5239.2B. IT Level I privileged users also draw an NCPASS token for multifactor authentication, held with the agreement by the ISSM or ISSO per MCTFS FoS Access Policy and Procedures 8.0MCTFS FoS Access Policy and Procedures 8.0.
- Submit the MCTFS certifier SAAR. Route the certifier SAAR through AutoSAAR to MISSA with the privileged access agreement on file. Route UD-MIPS Certifier role requests through NIS to the Information Owner approver group.
- Activate the certifier account. MISSA validates the MCTFS certifier SAAR and TSO provisions the role. NIS approves the UD-MIPS Certifier role. Confirm activation per system.
- Test certifier function. Submit a sample diary line and certify it in a training environment when available. Validate the certified line posts correctly per MCTFSPRIUMMCTFSPRIUM.
- Document authorization. Cut a Page 11 entry recording certifier authorization, training completion, and privileged access agreement date per MCO P1070.12KMCO P1070.12K Chapter 6.
- Audit the certifier list monthly. Pull the diary certification log and reconcile against the certifier roster. The S-1 chief signs the audit per MCO 5239.2BMCO 5239.2B.
- Reauthorize annually. Run certifier-specific training renewal and refresh the privileged access agreement at the annual cycle.
- Suspend on misconduct. The S-1 officer suspends certifier access on any pending investigation affecting record integrity per MCO P1070.12KMCO P1070.12K.
NIS approver groups and proxy
NIS ties Information Owner approver group membership to specific platform permissions.
- UD-MIPS approvers. Certifier Commander (COM) and Certifier Account Provisioner (IPAC Director or IPAC Deputy).
- DTMS approvers. Commanding Officer, Disbursing Officer, or IPAC Director.
- Proxy and delegation. The Certifier Account Provisioner role in UD-MIPS holds the delegation and proxy function for the platform.
- MISSO Manager access. Requests to add MISSO Managers route through NIS to MISSA based on application and jurisdiction. After implementation these groups do not tie to application permissions, so a new MISSO COM requests MISSO Manager access separately.
Systems of record and forms
Systems
- MCTFS. Holds the certifier role and certified diary lines. Certifier access submits through AutoSAAR to MISSA, provisioned by TSO.
- UD-MIPS. Cuts and certifies diary lines requiring certifier signature. Certifier roles route through NIS.
- AutoSAAR. Carries the MCTFS certifier SAAR to MISSA.
- Diary certification log. Local log of certified lines per certifier.
Forms
- DD Form 2875 (SAAR). Submission for the MCTFS certifier role through AutoSAAR.
- Privileged Access Agreement. Required for every certifier.
- NCPASS Token. Required for IT Level I privileged users, held with the agreement by the ISSM or ISSO.
- MCTFS Certifier Training Certificate. Required for activation.
- UD-MIPS Certifier Training Certificate. Required for activation.
- Cyber Awareness Training Certificate. Required annually.
- Unit Certifier Roster. Local register of authorized certifiers.
- DD Form 577 Appointment and Termination Record. Current 577 policy stays in effect. NIS holds no document uploads, so units maintain certifier and disbursing 577s externally for DTMS. The self-contained 577 process for UD-MIPS stays unchanged.
- NAVMC 118 (11) Administrative Remarks. Page 11 documenting certifier authorization.
Common pitfalls
- Certifier signing diary lines without a current privileged access agreement. MCAAT writes the finding. Sign the agreement before activation per MCO 5239.2BMCO 5239.2B.
- Certifier-specific training expired. The certifier signs without current credentials. Run renewal at the annual cycle.
- Certifier suspended on misconduct, but role not removed in MCTFS. The certifier retains technical access. Submit the removal to MISSA at suspension per MCO 5239.2BMCO 5239.2B.
- Monthly certifier audit skipped. Stale certifier authorizations sit on the roster. Pull the diary log and reconcile each month.
- Privileged access agreement filed without the security manager signature. The agreement does not stand on review. Capture both signatures at signing per MCO 5239.2BMCO 5239.2B.
Decision points
- Grade and DoR threshold exception. The unit lacks a SSgt with sufficient DoR. The S-1 officer routes a written exception through the commander before MISSA validates per MCO 5239.2BMCO 5239.2B.
- Certifier suspension scope. The certifier is under preliminary inquiry, command-directed inquiry, or judicial action. The S-1 officer suspends at the level matching the inquiry severity per MCO P1070.12KMCO P1070.12K.
- Reactivation after suspension. The investigation closes without adverse finding. The S-1 officer reactivates with a fresh privileged access agreement and refreshed training.
Authority
This sub-page sits under MCTFS FoS Access Policy and Procedures 8.0MCTFS FoS Access Policy and Procedures 8.0, which sets the AutoSAAR process, privileged access controls, and the NCPASS token requirement. MCO 5239.2BMCO 5239.2B Marine Corps Cybersecurity Program sets the privileged access agreement requirement for certifier roles. MCO 5000.14DMCO 5000.14D MCAP enclosure 6 establishes support-office roles. DOD 8500.01EDOD 8500.01E Cybersecurity sets DoD-level privileged access controls. NAVMC 3500.3ENAVMC 3500.3E T-R event 0102-GENA-1015 covers administrator role assignment and removal. MCTFSPRIUMMCTFSPRIUM defines certifier function within UD-MIPS diary submission.
Related references
- MCTFS FoS Access Policy and Procedures 8.0. AutoSAAR process, levels of privilege, and NCPASS token requirement.
- MCO 5239.2B Marine Corps Cybersecurity Program. Privileged access agreement requirement.
- MCO 5000.14D Marine Corps Administrative Procedures. MISSA and support-office roles.
- DOD 8500.01E Cybersecurity. DoD-level privileged access controls.
- MCTFSPRIUM. Certifier function within UD-MIPS.
- MCO P1070.12K Individual Records Administration Manual. Page 11 documenting certifier authorization.
- NAVMC 3500.3E Manpower and Administration T-R Manual. Event 0102-GENA-1015 administrator role rules.
Same topic, other roles
References
- MCO 5239.2B Marine Corps Cybersecurity Program
- MCO 5000.14D Marine Corps Administrative Procedures
- DOD 8500.01E Cybersecurity
- MCTFSPRIUM Marine Corps Total Force System Personnel Reporting Instructions Users Manual
- MCO P1070.12K Individual Records Administration Manual
- NAVMC 3500.3E Manpower and Administration T-R Manual
- MCTFS FoS Access Policy and Procedures 8.0
- Naval Identity Services (NIS) FAQs UDMIPS and DTMS, 13 March 2026
Related Pages
- Admin
Account Provisioning and SAAR-N Processing - S-1 Procedural Page
same topic - same function - MCO 5239.2B - same T&R event - 7 shared references
- Admin
Admin Systems Management - S-1 Procedural Page
same topic - same function - same T&R event - 8 shared references
- Admin
Account Closure at Detach - S-1 Procedural Page
same topic - same function - same T&R event - 7 shared references
- Admin
New System Release Onboarding - S-1 Procedural Page
same topic - same function - same T&R event - 7 shared references
- Admin
MOL Administrator Permissions Management - S-1 Procedural Page
same topic - same function - same T&R event - 6 shared references