User management is the daily task of every administrator. Here are exercises worth doing in the Lab you set up.
Exercises
- Create an OU named Students with 5 users inside it.
- Create a Security group named Lab-Admins and add one user to it.
- Disable one user and verify they can't log in.
- Find all users who haven't logged in for over 90 days.
# Create new user
New-ADUser -Name "Dana Levi" -SamAccountName dlevi `
-Path "OU=Students,DC=lab,DC=local" `
-AccountPassword (Read-Host -AsSecureString "Password") -Enabled $true
# Add to group
Add-ADGroupMember -Identity "Lab-Admins" -Members dlevipowershellArchitecture and Theory — Under the Hood
Scalable user management is performed only via PowerShell or Identity Management (MIM/Entra Connect). GUI is suitable for point fixes — not for mass creation.
- New-ADUser requires a unique SamAccountName (up to 20 characters) and a unique UserPrincipalName in the entire forest.
- User is created disabled (Enabled=$false) until Set-ADAccountPassword + Enable-ADAccount.
- Groups: Global (domain users), Local (permissions), Universal (inter-domain). AGDLP model.
Practical Configuration (PowerShell / GUI)
# Bulk creation from CSV file
Import-Csv .\new-hires.csv | ForEach-Object {
$pwd = ConvertTo-SecureString $_.TempPwd -AsPlainText -Force
New-ADUser -Name "$($_.First) $($_.Last)" -SamAccountName $_.Sam \
-UserPrincipalName "$($_.Sam)@corp.local" -GivenName $_.First -Surname $_.Last \
-Path 'OU=Users,OU=IT,DC=corp,DC=local' -AccountPassword $pwd -Enabled $true \
-ChangePasswordAtLogon $true
Add-ADGroupMember -Identity $_.Group -Members $_.Sam
}
# Reset password + Unlock account
Set-ADAccountPassword j.smith -Reset -NewPassword (Read-Host -AsSecureString)
Unlock-ADAccount j.smithpowershellReal-world scenarios in an organization
- Automated Onboarding from HR (Workday/Priority) → PowerShell + Scheduled Task.
- Offboarding: Immediate disablement, transfer to Disabled OU, removal from sensitive groups.
- Service password rotation via gMSA instead of a fixed password.
Diagnosis and Troubleshooting
- 'The account is not authorized' — Check group membership, PSO, and logon hours.
- User repeatedly locked out → Account Lockout Status Tool + Event 4740 on the PDCe.
- Duplicate UPN → 'Duplicate UPN' — Check in the forest with Get-ADUser -Filter on UPN.
Glossary and quick command line
- AGDLP — Account → Global → Local → Permission.
- gMSA — Service account with automatically rotating password.
- PSO — Fine-Grained Password Policy for a specific group.