Hands-On LabBeginner

Windows Active Directory Fundamentals - Users, Groups, and Group Policy

Create OUs, users, and security groups in Active Directory, then configure Group Policy Objects to enforce security settings.

60 minEstimated time
5Guided steps
AutoVerification
IsolatedSandbox
Windows Active Directory Fundamentals - Users, Groups, and Group Policy

Lab overview

Active Directory Domain Services (AD DS) is the foundation of identity and access management in Windows enterprise networks. It provides a centralized, hierarchical directory that stores information about users, computers, groups, and other objects - enabling administrators to control authentication, enforce security policies, and delegate administrative responsibilities across an organization. Nearly every Windows Server environment in production relies on AD DS, making it one of the most critical skills for system administrators and security professionals.

Group Policy extends Active Directory's management capabilities by allowing administrators to define and enforce configuration settings across the domain. Through Group Policy Objects (GPOs) linked to Organizational Units (OUs), administrators can control password requirements, account lockout thresholds, software deployment, and hundreds of other security-relevant settings from a single location. In this lab, you will connect to a pre-configured Windows Server Domain Controller via PowerShell, create Organizational Units to structure the directory, provision users and security groups, and configure Group Policy Objects that enforce password and account lockout policies - all core skills for managing an enterprise Active Directory environment.

Objectives

Upon completion of this beginner level lab, you will be able to:

  • Create Organizational Units (OUs) to establish a logical directory structure for departments
  • Provision Active Directory user accounts with proper attributes and OU placement using PowerShell
  • Create and manage security groups with appropriate group scopes (Global, Domain Local)
  • Add users to security groups and verify group membership
  • Create and configure a Group Policy Object (GPO) that enforces password and account lockout policies
  • Link GPOs to Organizational Units and verify policy application with gpresult

Who is this lab for?

This lab is designed for:

  • IT administrators and cybersecurity students learning Windows Active Directory management
  • Students pursuing CISA certifications who need hands-on directory services experience
  • System administration learners who want practical GPO configuration skills

Basic familiarity with Windows Server and PowerShell command-line concepts is recommended.

Verified against your live environment

An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.

[CHECK] validation_activelive
Inspecting deployed resources...
Verifying configuration state...
✓ Step requirements satisfied

More labs like this

Related reading

PremiumIncluded in Premium
Duration
60 min
Steps
5

Environment

Browser Code IDELive Cloud Environment

Every lab includes

  • Real environment, pre-credentialed
  • Automated checks on every step
  • Isolated sandbox, auto cleanup
  • AI-recommended next steps

Lab curriculum

  1. 01

    Logging into Azure CLI

  2. 02

    Connect to the Domain Controller via Remote PowerShell

    1 automated check

  3. 03

    Create Organizational Units for Directory Structure

    1 automated check

  4. 04

    Provision Users and Security Groups in Active Directory

    1 automated check

  5. 05

    Configure Group Policy for Password and Lockout Settings

    1 automated check

Skills validated

Privileged Identity Management

Not the lab you were looking for?

Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.

Explore the catalog