Home › Active Directory users and groups › Step 2
Configuring user account attributes
Step 2 of 9 in Active Directory users and groups · video 5:52
What you will learn
- Where the attribute sections appear in Active Directory Administrative Center
- Restricting sign-in by logon hours, workstation list and expiry date
- Which account options suit service accounts, and why
- Why reversible password encryption should stay switched off
About this lesson
A user object carries far more than a name and password, and this lesson tours the attributes an administrator actually sets. Following the sections of the user Properties dialog in Active Directory Administrative Center, it starts with Account: the UPN and sAMAccountName logon names, logon hours, the list of computers a user may sign in to, account expiry for temporary staff such as interns, and the account options. These include forcing a password change at next sign-in, requiring a smart card, Password never expires and User cannot change password for service accounts, reversible encryption (needed only for CHAP or Digest authentication, and close to storing plain text), and trust for delegation. It then covers Organization, Member Of, Profile, Policy, Silo and Extensions. The attributes are defined by the AD DS schema, which Schema Admins can extend, as Exchange Server does. In Active Directory Users and Computers some tabs appear only after enabling Advanced Features.
Check yourself
1. You create accounts for interns who leave after one year. Which attribute stops the accounts being used after they go?
Account expires. Set the expiry date when you create the account; after that date nobody can sign in with it until an administrator changes the setting, so a forgotten account does not stay usable.
2. Why should Store password using reversible encryption normally stay disabled?
A password stored with reversible encryption can be recovered, which is practically the same as keeping it in plain text. Enable it only when a program genuinely needs it, such as CHAP through remote access or Digest authentication in IIS.
3. What happens to a user's password when you tick Smart card is required for interactive logon?
The password is reset to a long random value that nobody knows, and the account is flagged so that interactive sign-in must use a smart card. The user can no longer sign in at the console by typing a password.
4. Some property tabs of a user are missing in Active Directory Users and Computers. What should you check?
Whether Advanced Features is enabled in the View menu. Several property pages are hidden in the default view and appear only once that option is switched on.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.