Skip to main content
AD Academy
Practice and Learning
Beginner15 minLast updated: Topic 2 of 2

Practice: Managing Users and Groups

Creating, modifying and disabling accounts in PowerShell.

Not read

What you will learn here

  • How to create users and groups
  • How to change and disable accounts
  • Basic PowerShell commands

Worth reading first:Building a Home Lab for AD

User management is the daily task of every administrator. Here are exercises worth doing in the Lab you set up.

Exercises

  • Create an OU named Students with 5 users inside it.
  • Create a Security group named Lab-Admins and add one user to it.
  • Disable one user and verify they can't log in.
  • Find all users who haven't logged in for over 90 days.
# Create new user
New-ADUser -Name "Dana Levi" -SamAccountName dlevi `
  -Path "OU=Students,DC=lab,DC=local" `
  -AccountPassword (Read-Host -AsSecureString "Password") -Enabled $true

# Add to group
Add-ADGroupMember -Identity "Lab-Admins" -Members dlevi
powershell
Architecture and Theory — Under the Hood

Scalable user management is performed only via PowerShell or Identity Management (MIM/Entra Connect). GUI is suitable for point fixes — not for mass creation.

  • New-ADUser requires a unique SamAccountName (up to 20 characters) and a unique UserPrincipalName in the entire forest.
  • User is created disabled (Enabled=$false) until Set-ADAccountPassword + Enable-ADAccount.
  • Groups: Global (domain users), Local (permissions), Universal (inter-domain). AGDLP model.
Practical Configuration (PowerShell / GUI)
# Bulk creation from CSV file
Import-Csv .\new-hires.csv | ForEach-Object {
  $pwd = ConvertTo-SecureString $_.TempPwd -AsPlainText -Force
  New-ADUser -Name "$($_.First) $($_.Last)" -SamAccountName $_.Sam \
    -UserPrincipalName "$($_.Sam)@corp.local" -GivenName $_.First -Surname $_.Last \
    -Path 'OU=Users,OU=IT,DC=corp,DC=local' -AccountPassword $pwd -Enabled $true \
    -ChangePasswordAtLogon $true
  Add-ADGroupMember -Identity $_.Group -Members $_.Sam
}

# Reset password + Unlock account
Set-ADAccountPassword j.smith -Reset -NewPassword (Read-Host -AsSecureString)
Unlock-ADAccount j.smith
powershell
Real-world scenarios in an organization
  • Automated Onboarding from HR (Workday/Priority) → PowerShell + Scheduled Task.
  • Offboarding: Immediate disablement, transfer to Disabled OU, removal from sensitive groups.
  • Service password rotation via gMSA instead of a fixed password.
Diagnosis and Troubleshooting
  • 'The account is not authorized' — Check group membership, PSO, and logon hours.
  • User repeatedly locked out → Account Lockout Status Tool + Event 4740 on the PDCe.
  • Duplicate UPN → 'Duplicate UPN' — Check in the forest with Get-ADUser -Filter on UPN.
Glossary and quick command line
  • AGDLP — Account → Global → Local → Permission.
  • gMSA — Service account with automatically rotating password.
  • PSO — Fine-Grained Password Policy for a specific group.

Check yourself

Which command adds a user to a group?

Was this page helpful?