User Access Management in Active Directory Domain Services (AD DS)

Comprehensive Documentation (2026 Edition)

1. Introduction

Purpose

User Access Management (UAM) in Microsoft Active Directory Domain Services (AD DS) is the process of managing user identities, authentication, authorization, and permissions within an organization’s network. It ensures that only authorized users can access corporate resources while maintaining security, compliance, and operational efficiency.

Objectives

  • Centralized identity management
  • Secure authentication
  • Controlled authorization
  • Principle of Least Privilege (PoLP)
  • Regulatory compliance
  • Simplified administration
  • Automated provisioning and de-provisioning

2. Active Directory Architecture

                        Active Directory Forest
                                 │
                     ┌───────────┴───────────┐
                     │                       │
                 Domain A               Domain B
                     │                       │
            Organizational Units (OU)
                     │
        ┌────────────┼─────────────┐
        │            │             │
     Users       Computers      Groups
        │
 Authentication & Authorization

3. User Lifecycle Management

User Access Management follows the complete employee lifecycle.

StageDescription
JoinerNew employee onboarding
MoverDepartment or role changes
LeaverEmployee termination
ContractorTemporary access
GuestLimited external access

4. User Provisioning Process

HR Creates Employee Record
          │
          ▼
Identity Request
          │
          ▼
Manager Approval
          │
          ▼
AD Account Creation
          │
          ▼
Password Generation
          │
          ▼
Group Membership Assignment
          │
          ▼
Mailbox Creation
          │
          ▼
Application Access
          │
          ▼
User Notification

5. User Account Creation

Mandatory Attributes

AttributeDescription
First NameGiven Name
Last NameSurname
Display NameVisible Name
Username (sAMAccountName)Login Name
UPNUser Principal Name
EmailCorporate Email
DepartmentHR Department
Job TitleDesignation
ManagerReporting Manager
Employee IDHR Identifier

Example Naming Standards

ObjectExample
Usernamejsmith
Emailjohn.smith@company.com
Display NameJohn Smith
UPNjohn.smith@company.com

6. Organizational Unit (OU) Structure

Company
│
├── Executive
├── HR
├── Finance
├── IT
│      ├── Servers
│      ├── Workstations
│      └── Users
├── Sales
├── Marketing
└── Contractors

7. Authentication Process

User Login
     │
Enter Username
Password
     │
     ▼
Domain Controller
     │
Password Verification
     │
     ▼
Kerberos Authentication
     │
Ticket Granting Ticket (TGT)
     │
Service Ticket
     │
Access Granted

8. Authorization Process

Authentication answers:

Who are you?

Authorization answers:

What are you allowed to access?

User
 │
 ▼
Group Membership
 │
 ▼
ACL Evaluation
 │
 ▼
Resource Permission
 │
 ▼
Allow / Deny

9. Security Groups

Types

TypePurpose
Security GroupPermission Assignment
Distribution GroupEmail Distribution

Scope

ScopeUsage
Domain LocalResource Permissions
GlobalUsers
UniversalMultiple Domains

10. Group-Based Access Control

Instead of assigning permissions directly to users:

User
 │
 ▼
Global Group
 │
 ▼
Domain Local Group
 │
 ▼
Folder Permission

Example:

John

↓

GG_HR_Users

↓

DL_HR_Folder_RW

↓

HR Shared Folder

11. Role-Based Access Control (RBAC)

RolePermissions
HR StaffHR Files
FinanceAccounting
IT SupportWorkstations
Server AdminServers
Database AdminSQL Servers
HelpdeskPassword Reset

12. Access Control Lists (ACL)

Every AD object contains:

  • Owner
  • Permissions
  • Audit Entries
  • Inheritance

Example

Shared Folder

ACL

John
Read

HR Group
Modify

Finance
Read

Everyone
No Access

13. Password Policy

Typical enterprise settings:

SettingRecommendation
Minimum Length14–16 characters
Password History24 passwords
Maximum Age90 days (or longer if using strong passphrases and MFA)
Lockout Threshold5 attempts
Lockout Duration15 minutes
ComplexityEnabled

14. Multi-Factor Authentication (MFA)

Recommended factors include:

  • Password
  • Smart Card
  • Authenticator App
  • Biometrics
  • Hardware Security Key (FIDO2)
Password

+

Authenticator App

↓

Access Granted

15. Delegation of Administration

Instead of granting Domain Admin rights:

IT Manager

│

Helpdesk Team

│

Reset Password

Unlock Account

Create User

No Domain Admin Rights

16. User Account Maintenance

Common administrative tasks:

  • Reset Password
  • Unlock Account
  • Rename User
  • Disable Account
  • Enable Account
  • Move OU
  • Update Manager
  • Change Department
  • Update Phone Number
  • Modify Group Membership

17. Offboarding Process

Employee Leaves

↓

HR Notification

↓

Disable Account

↓

Remove Group Membership

↓

Block VPN

↓

Disable Email

↓

Archive Mailbox

↓

Transfer Ownership

↓

Delete Account (Retention Policy)

18. Privileged Access Management (PAM)

Privileged accounts should include:

  • Domain Admins
  • Enterprise Admins
  • Schema Admins
  • Server Administrators
  • Backup Operators
  • Account Operators

Best practices:

  • Separate admin and user accounts.
  • Use just-in-time (JIT) elevation where possible.
  • Require MFA for privileged access.
  • Review memberships regularly.

19. Auditing and Monitoring

Enable auditing for:

ActivityAudit
Logon SuccessYes
Logon FailureYes
User CreationYes
User DeletionYes
Group ChangesYes
Password ChangesYes
Privilege UseYes
Account LockoutsYes

Common Windows Security Event IDs:

Event IDDescription
4624Successful logon
4625Failed logon
4720User account created
4722User account enabled
4725User account disabled
4726User account deleted
4728Added to security-enabled global group
4729Removed from security-enabled global group
4738User account changed
4740Account locked out
4768Kerberos TGT requested
4769Kerberos service ticket requested

20. User Access Review Process

Periodic reviews should verify:

  • Active users
  • Dormant accounts
  • Disabled accounts
  • Privileged users
  • Shared accounts
  • Service accounts
  • Contractor accounts
  • External users
  • Group memberships

Recommended frequency:

  • Monthly: Privileged accounts
  • Quarterly: Department access
  • Annually: Full access certification

21. Best Practices

  1. Apply the Principle of Least Privilege (PoLP).
  2. Use Role-Based Access Control (RBAC).
  3. Grant permissions to groups rather than individual users.
  4. Use dedicated administrative accounts.
  5. Enable MFA for privileged and remote access.
  6. Disable inactive accounts promptly.
  7. Audit access regularly.
  8. Standardize OU and naming conventions.
  9. Document all access requests and approvals.
  10. Implement automated provisioning and de-provisioning with an Identity Governance solution where appropriate.

22. End-to-End User Access Management Workflow

HR Creates Employee
        │
        ▼
Identity Request Submitted
        │
        ▼
Manager Approval
        │
        ▼
Create AD User Account
        │
        ▼
Assign Organizational Unit (OU)
        │
        ▼
Add Security Groups
        │
        ▼
Apply Group Policies (GPO)
        │
        ▼
Provision Email & Applications
        │
        ▼
Enable MFA
        │
        ▼
User Authenticates (Kerberos)
        │
        ▼
Authorization via Groups & ACLs
        │
        ▼
Access to Corporate Resources
        │
        ▼
Continuous Auditing & Access Reviews
        │
        ▼
Role Changes (Mover)
        │
        ▼
Update Groups & Permissions
        │
        ▼
Employee Exit (Leaver)
        │
        ▼
Disable Account → Remove Access → Archive → Delete per Retention Policy

This documentation provides a structured foundation for implementing and maintaining secure user access management in Active Directory Domain Services, aligning identity lifecycle management, authentication, authorization, auditing, and governance with enterprise security best practices.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top