Home › Active Directory users and groups › Step 1

User accounts in Active Directory

Step 1 of 9 in Active Directory users and groups · video 7:29

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

This lesson explains what a user account is in Active Directory Domain Services (AD DS) and why every person who needs network access should have one of their own. A domain user account is a directory object holding the sign-in name, password, group memberships and other settings; it is the identity the domain authenticates when someone signs in to a computer or reaches shared folders, printers and directory objects. Local accounts, kept in each computer's Security Accounts Manager (SAM) database, are mentioned but left aside. The video lists the tools for creating accounts: Active Directory Users and Computers, Active Directory Administrative Center, Windows PowerShell and the older dsadd command. It then walks through a sensible creation routine: agree a naming convention, enter the user details, set an initial password and account options, add the account to groups on a least-privilege basis, and review everything before creating it. Shared accounts are discouraged because they destroy accountability.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Where are local user accounts stored, as opposed to AD DS domain accounts?

In the Security Accounts Manager (SAM) database of each individual computer. They only allow sign-in and access to resources on that one machine, whereas domain accounts live in AD DS and are authenticated by domain controllers.

2. Why is it a bad idea to let several people share one user account?

Actions can no longer be traced to one person, so accountability is lost, and access cannot be granted or withdrawn per individual. Giving each person their own account and password makes auditing and permission management simpler.

3. You need to create 300 accounts from an HR spreadsheet. Which of the tools covered suits this best, and why?

Windows PowerShell, because it is a scripting language: you can read the list and create the accounts in a loop (for example with New-ADUser) instead of filling in a graphical form 300 times. The GUI tools suit occasional single accounts.

4. What does a consistent naming convention for logon names protect against in a large organisation?

Duplicate names: two people called John Smith still need different logon names, because a logon name must be unique in the domain. A fixed pattern (for example first name, last name and perhaps an employee ID) also makes accounts easier to find and keeps working as the organisation grows.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Users Accounts and Properties

4.5★ · 7,846 students on Udemy

See the course on Udemy
← About this pathNext: Configuring user account attributes →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.