Comprehensive Documentation (2026 Edition)
1. Introduction
Purpose
User Access Management (UAM) in Microsoft Active Directory Domain Services (AD DS) is the process of managing user identities, authentication, authorization, and permissions within an organization’s network. It ensures that only authorized users can access corporate resources while maintaining security, compliance, and operational efficiency.
Objectives
- Centralized identity management
- Secure authentication
- Controlled authorization
- Principle of Least Privilege (PoLP)
- Regulatory compliance
- Simplified administration
- Automated provisioning and de-provisioning
2. Active Directory Architecture
Active Directory Forest
│
┌───────────┴───────────┐
│ │
Domain A Domain B
│ │
Organizational Units (OU)
│
┌────────────┼─────────────┐
│ │ │
Users Computers Groups
│
Authentication & Authorization
3. User Lifecycle Management
User Access Management follows the complete employee lifecycle.
| Stage | Description |
|---|---|
| Joiner | New employee onboarding |
| Mover | Department or role changes |
| Leaver | Employee termination |
| Contractor | Temporary access |
| Guest | Limited external access |
4. User Provisioning Process
HR Creates Employee Record
│
▼
Identity Request
│
▼
Manager Approval
│
▼
AD Account Creation
│
▼
Password Generation
│
▼
Group Membership Assignment
│
▼
Mailbox Creation
│
▼
Application Access
│
▼
User Notification
5. User Account Creation
Mandatory Attributes
| Attribute | Description |
|---|---|
| First Name | Given Name |
| Last Name | Surname |
| Display Name | Visible Name |
| Username (sAMAccountName) | Login Name |
| UPN | User Principal Name |
| Corporate Email | |
| Department | HR Department |
| Job Title | Designation |
| Manager | Reporting Manager |
| Employee ID | HR Identifier |
Example Naming Standards
| Object | Example |
|---|---|
| Username | jsmith |
| john.smith@company.com | |
| Display Name | John Smith |
| UPN | john.smith@company.com |
6. Organizational Unit (OU) Structure
Company
│
├── Executive
├── HR
├── Finance
├── IT
│ ├── Servers
│ ├── Workstations
│ └── Users
├── Sales
├── Marketing
└── Contractors
7. Authentication Process
User Login
│
Enter Username
Password
│
▼
Domain Controller
│
Password Verification
│
▼
Kerberos Authentication
│
Ticket Granting Ticket (TGT)
│
Service Ticket
│
Access Granted
8. Authorization Process
Authentication answers:
Who are you?
Authorization answers:
What are you allowed to access?
User
│
▼
Group Membership
│
▼
ACL Evaluation
│
▼
Resource Permission
│
▼
Allow / Deny
9. Security Groups
Types
| Type | Purpose |
|---|---|
| Security Group | Permission Assignment |
| Distribution Group | Email Distribution |
Scope
| Scope | Usage |
|---|---|
| Domain Local | Resource Permissions |
| Global | Users |
| Universal | Multiple Domains |
10. Group-Based Access Control
Instead of assigning permissions directly to users:
User
│
▼
Global Group
│
▼
Domain Local Group
│
▼
Folder Permission
Example:
John
↓
GG_HR_Users
↓
DL_HR_Folder_RW
↓
HR Shared Folder
11. Role-Based Access Control (RBAC)
| Role | Permissions |
|---|---|
| HR Staff | HR Files |
| Finance | Accounting |
| IT Support | Workstations |
| Server Admin | Servers |
| Database Admin | SQL Servers |
| Helpdesk | Password Reset |
12. Access Control Lists (ACL)
Every AD object contains:
- Owner
- Permissions
- Audit Entries
- Inheritance
Example
Shared Folder
ACL
John
Read
HR Group
Modify
Finance
Read
Everyone
No Access
13. Password Policy
Typical enterprise settings:
| Setting | Recommendation |
|---|---|
| Minimum Length | 14–16 characters |
| Password History | 24 passwords |
| Maximum Age | 90 days (or longer if using strong passphrases and MFA) |
| Lockout Threshold | 5 attempts |
| Lockout Duration | 15 minutes |
| Complexity | Enabled |
14. Multi-Factor Authentication (MFA)
Recommended factors include:
- Password
- Smart Card
- Authenticator App
- Biometrics
- Hardware Security Key (FIDO2)
Password
+
Authenticator App
↓
Access Granted
15. Delegation of Administration
Instead of granting Domain Admin rights:
IT Manager
│
Helpdesk Team
│
Reset Password
Unlock Account
Create User
No Domain Admin Rights
16. User Account Maintenance
Common administrative tasks:
- Reset Password
- Unlock Account
- Rename User
- Disable Account
- Enable Account
- Move OU
- Update Manager
- Change Department
- Update Phone Number
- Modify Group Membership
17. Offboarding Process
Employee Leaves
↓
HR Notification
↓
Disable Account
↓
Remove Group Membership
↓
Block VPN
↓
Disable Email
↓
Archive Mailbox
↓
Transfer Ownership
↓
Delete Account (Retention Policy)
18. Privileged Access Management (PAM)
Privileged accounts should include:
- Domain Admins
- Enterprise Admins
- Schema Admins
- Server Administrators
- Backup Operators
- Account Operators
Best practices:
- Separate admin and user accounts.
- Use just-in-time (JIT) elevation where possible.
- Require MFA for privileged access.
- Review memberships regularly.
19. Auditing and Monitoring
Enable auditing for:
| Activity | Audit |
|---|---|
| Logon Success | Yes |
| Logon Failure | Yes |
| User Creation | Yes |
| User Deletion | Yes |
| Group Changes | Yes |
| Password Changes | Yes |
| Privilege Use | Yes |
| Account Lockouts | Yes |
Common Windows Security Event IDs:
| Event ID | Description |
|---|---|
| 4624 | Successful logon |
| 4625 | Failed logon |
| 4720 | User account created |
| 4722 | User account enabled |
| 4725 | User account disabled |
| 4726 | User account deleted |
| 4728 | Added to security-enabled global group |
| 4729 | Removed from security-enabled global group |
| 4738 | User account changed |
| 4740 | Account locked out |
| 4768 | Kerberos TGT requested |
| 4769 | Kerberos service ticket requested |
20. User Access Review Process
Periodic reviews should verify:
- Active users
- Dormant accounts
- Disabled accounts
- Privileged users
- Shared accounts
- Service accounts
- Contractor accounts
- External users
- Group memberships
Recommended frequency:
- Monthly: Privileged accounts
- Quarterly: Department access
- Annually: Full access certification
21. Best Practices
- Apply the Principle of Least Privilege (PoLP).
- Use Role-Based Access Control (RBAC).
- Grant permissions to groups rather than individual users.
- Use dedicated administrative accounts.
- Enable MFA for privileged and remote access.
- Disable inactive accounts promptly.
- Audit access regularly.
- Standardize OU and naming conventions.
- Document all access requests and approvals.
- Implement automated provisioning and de-provisioning with an Identity Governance solution where appropriate.
22. End-to-End User Access Management Workflow
HR Creates Employee
│
▼
Identity Request Submitted
│
▼
Manager Approval
│
▼
Create AD User Account
│
▼
Assign Organizational Unit (OU)
│
▼
Add Security Groups
│
▼
Apply Group Policies (GPO)
│
▼
Provision Email & Applications
│
▼
Enable MFA
│
▼
User Authenticates (Kerberos)
│
▼
Authorization via Groups & ACLs
│
▼
Access to Corporate Resources
│
▼
Continuous Auditing & Access Reviews
│
▼
Role Changes (Mover)
│
▼
Update Groups & Permissions
│
▼
Employee Exit (Leaver)
│
▼
Disable Account → Remove Access → Archive → Delete per Retention Policy
This documentation provides a structured foundation for implementing and maintaining secure user access management in Active Directory Domain Services, aligning identity lifecycle management, authentication, authorization, auditing, and governance with enterprise security best practices.
