- How to create and manage user accounts
- How to add computers to your domain
- Best practices for organizing users and computers
- Basic security settings
- A working Windows Server domain (from 01_Setup_Lab_Environment.md)
- Logged in as a domain administrator
Think of user accounts like digital ID cards. Each user needs one to:
- Log into computers
- Access shared resources
- Send emails
- Use network services
OUs are like folders that help organize your users and computers.
-
Open Active Directory Users and Computers:
- Press
Windows + R - Type
dsa.msc - Press Enter
- Press
-
Create these OUs (right-click your domain → New → Organizational Unit):
IT HR Sales Interns
Let's create a user account for John in the IT department:
-
Right-click the IT OU → New → User
-
Fill in these fields:
First name: John Last name: Smith User logon name: john.smith -
Click Next
-
Set a password:
Password: P@ssw0rd123 Check: "User must change password at next logon" -
Click Finish
Right-click the user → Properties to set:
- Email address
- Phone number
- Department
- Manager
- Profile path
- Home directory
Computer accounts are like user accounts for machines. They help:
- Track which computers are in your domain
- Apply security policies
- Manage software updates
- On the client computer:
- Press
Windows + R - Type
sysdm.cpl - Press Enter
- Press
- Go to "Computer Name" tab
- Click "Change"
- Select "Domain"
- Enter your domain name:
lab.local - Enter domain admin credentials when prompted
- Restart the computer
- In Active Directory Users and Computers:
- Right-click the appropriate OU
- New → Computer
- Enter computer name (e.g.,
CL-JOHN-PC) - Click OK
-
Open Group Policy Management:
- Press
Windows + R - Type
gpmc.msc - Press Enter
- Press
-
Navigate to: Default Domain Policy
-
Edit → Computer Configuration → Policies → Windows Settings → Security Settings → Account Policies → Password Policy
-
Set these recommended values:
Minimum password length: 12 Password complexity: Enabled Maximum password age: 90 days
-
In the same Group Policy:
- Account Lockout Policy
-
Set these values:
Account lockout threshold: 5 attempts Account lockout duration: 30 minutes Reset account lockout counter: 30 minutes
Here's a PowerShell script to create multiple users (save as Create-Users.ps1):
# Create IT Users
New-ADUser -Name "John Smith" -GivenName "John" -Surname "Smith" `
-SamAccountName "john.smith" -UserPrincipalName "john.smith@lab.local" `
-Path "OU=IT,DC=lab,DC=local" -AccountPassword (ConvertTo-SecureString "P@ssw0rd123" -AsPlainText -Force) `
-Enabled $true -ChangePasswordAtLogon $true
New-ADUser -Name "Sarah Johnson" -GivenName "Sarah" -Surname "Johnson" `
-SamAccountName "sarah.johnson" -UserPrincipalName "sarah.johnson@lab.local" `
-Path "OU=IT,DC=lab,DC=local" -AccountPassword (ConvertTo-SecureString "P@ssw0rd123" -AsPlainText -Force) `
-Enabled $true -ChangePasswordAtLogon $true- Right-click the user → Reset Password
- Enter new password
- Check "User must change password at next logon"
- Right-click the user → Disable Account
- Confirm the action
- Right-click the user → Move
- Select the target OU
- Click OK
- Check if account is enabled
- Verify password hasn't expired
- Check if account is locked
- Verify user is in correct OU
- Check network connectivity
- Verify DNS settings
- Ensure computer name is unique
- Check domain admin credentials
- Learn about managing groups in 03_AD_Groups_Management.md
- Understand Group Policy in 04_GPO_Creation_and_Linking.md
- Need help? Check 05_Troubleshooting.md