DEFERRED RESIGNATION PROGRAM (DRP) PERSONNEL IDENTITY  CREDENTIAL AND MARINE CORPS ENTERPRISE NETWORK (MCEN) ACCOUNT  MANAGEMENT GUIDANCE


https://www.marines.mil/News/Messages/Messages-Display/Article/4172133/deferred-resignation-program-drp-personnel-identity-credential-and-marine-corps/

R 011840Z MAY 25 MARADMIN 210/25 MSGID/GENADMIN/CMC DCI IC4 WASHINGTON DC// SUBJ/DEFERRED RESIGNATION PROGRAM (DRP) PERSONNEL IDENTITY  CREDENTIAL AND MARINE CORPS ENTERPRISE NETWORK (MCEN) ACCOUNT  MANAGEMENT GUIDANCE// REF/A/DOC/DOD PR/-/23 JAN 2014// REF/B//DOC/HQMC DC I IC4-ICC/ECSM 013/08 AUG 2018// REF/C/DOC/DOD CIO/-/19 JUL 2022// REF/D/DOC/HQMC DC I IC4-ICC/2024-1216-SVC/26 AUG 2024// NARR/REF A IS DOD INSTRUCTION 1000.13, "IDENTIFICATION (ID) CARDS  FOR MEMBERS OF THE UNIFORMED SERVICES, THEIR DEPENDENTS, AND OTHER  ELIGIBLE INDIVIDUALS". REF B IS ENTERPRISE CYBERSECURITY MANUAL  (ECSM) 013 PUBLIC KEY INFRASTRUCTURE. REF C IS DOD INSTRUCTION  8510.01, RISK MANAGEMENT FRAMEWORK (RMF) FOR DOD SYSTEMS. REF D IS  HQMC DCI IC4/ICC CY MEMORANDUM - UPDATE TO EXTENSION ATTRIBUTE 12  IMPLEMENTATION CRITERIA.REF D IS MARINE CORPS ORDER 5239.2B,  CYBERSECURITY.//  POC/WILLIAM J. BUSH/CIV/HQMC DC I IC4 ICC CY/TEL (COMM):  703-693-3490/EMAIL: [email protected]// POC/DANIEL R. NORTON/CIV/HQMC DC I IC4 ICC CY/TEL(COMM):  703-784-6075/EMAIL: [email protected]// POC/CHRISTINE HESEMANN/CIV/HQMC DC I IC4 ICC CY/TEL(COMM):  703-693-3490/EMAIL: [email protected]// GENTEXT/REMARKS/1. Purpose: This message outlines the process for  handling government-issued Personal Identity Verification (PIV)  compliance ID cards (Common Access Cards - CAC), logical access  tokens (DOD-issued Public Key Infrastructure (PKI) certificates),  and other multi-factor authentication tokens provided to personnel  in both the original and Department of Defense (DOD) reopened  versions of the Deferred Resignation Program (DRP). This process  includes the deactivation and return of these credentials to ensure  compliance with federal regulations and maintain access to  government benefits and resources during the personnel’s transition  period. Additionally, this message provides guidance on managing  Marine Corps Enterprise Network (MCEN) access and accounts (both  MCEN-N (unclassified) and MCEN-S (classified)) for civilian  personnel in the DRP. 2. Situation 2.a. Background. The DRP allows eligible personnel to resign from  service while maintaining their affiliation with the Department of  Defense (DoD) until their official end-of-service date or 30  September 2025, whichever comes first. During this transition  period, personnel retain their DoD affiliation, including access to  certain benefits and privileges. However, all personnel in this  program must adhere to DoD regulations, including those governing  the management of government-issued credentials. 2.b. As DRP-approved Marine Corps civilians transition out of  government service, all associated authorized and privileged logical  access, including access to the Marine Corps Enterprise Network  (MCEN) and related user accounts, must be revoked. Failure to  promptly disable and remove these accounts poses cybersecurity risks  and incurs unnecessary financial costs. 3. Action 3.a. Personal Identity Verification (PIV) compliance ID cards  (Common Access Cards - CAC). 3.b. DRP Personnel will retain their CAC as a DOD affiliate for  identity proofing for benefits per reference (a) until their  official end of service or 30 September 2025, whichever occurs  first.  3.c. At end of service, DRP personnel are responsible to return the  CAC to nearest RAPIDS site in person or via mail. RAPIDS site  information may be found at Identity Card Office Online (IDCO)  https:(slash)(slash)idco.dmdc.osd.mil/idco. 3.d. During the delayed resignation period, all management of the  CAC, to include re-issuance and replacement, will follow the policy  outlined in reference (a).  3.e. Marine Corps Logical Access Tokens and Multi-functional  Authentication (MFA) Devices. 3.f. DRP Personnel will surrender at checkout of command all Service  issued logical access only (non-CAC) credentials including, but not  limited, to Alternate Logon Tokens (AltToken), NIPRNET Enterprise  Alternate Logon System (NEATS) Tokens, SIPRNET Tokens (SIPRToken)  and Yubikeys in accordance with reference (b). 3.g. At the end of the service, DRP personnel retain any  authentication credentials associated with non-civilian personnel  categories, such as DSLogon, which are used for logical access only. 3.h. Marine Corps Enterprise Network (MCEN) Access and Accounts  (MCEN-N and MCEN-S): 3.i. In accordance with reference (c), no later than 24 hours after  completing DRP out-processing from associated Marine Corps Commands,  or immediately for personnel who have already departed, all Marine  Corps Commands and organizations must take the following actions for  civilian personnel under their authority who are approved for the  DRP and departing active service: 3.j. Account Disablement Request. For each civilian employee  departing under the DRP, the owning Marine Corps Commands and  organizations will submit a separate MCEN-N Remedy Change User  Service Request for each NIPRNet and SIPRNet authorized and  privileged user account. The employee’s DRP Final Separation  Agreement must be uploaded to the user’s Remedy People Record  alongside the service request for auditing purposes. 3.k. Account Disablement. Using the justification reason of "EAS  (End of Active Service)," set the EAS value to the date when the  employee begins Administrative Leave, as specified in the DRP Final  Separation Agreement. 3.l. Extension Attribute 12 (EA12) Designator Assignment. Modify the  user’s Active Directory Extension Attribute 12 (EA12) to "Designator  1" (Legal/Medical/FOIA Hold), in accordance with reference (d). 3.m. Account Expiration Set the account expiration date to the final  date of service (for example, 30 September 2025, or an alternate  retirement date). 3.n. Account Detail Entry. In the service request’s “Provide  Additional Details” block, enter the following note: “DRP employee— disable the associated user account on the EAS date. Do not  deprovision or delete until the final separation date, as indicated  in the account expiration date block of this request. This  annotation supersedes the IC4 Waiver requirement specified in HQMC  DCI IC4/ICC CY Memorandum: Update to Extension Attribute 12  Implementation Criteria.” 4. All questions should be directed to the designated points of  contact listed in this MARADMIN. 5. Release authorized by Lieutenant General M. G. Carter,  Headquarters Marine Corps, Deputy Commandant for Information.//