Windows Active Directory Fundamentals - Users, Groups, and Group Policy
Create OUs, users, and security groups in Active Directory, then configure Group Policy Objects to enforce security settings.

Lab overview
Active Directory Domain Services (AD DS) is the foundation of identity and access management in Windows enterprise networks. It provides a centralized, hierarchical directory that stores information about users, computers, groups, and other objects - enabling administrators to control authentication, enforce security policies, and delegate administrative responsibilities across an organization. Nearly every Windows Server environment in production relies on AD DS, making it one of the most critical skills for system administrators and security professionals.
Group Policy extends Active Directory's management capabilities by allowing administrators to define and enforce configuration settings across the domain. Through Group Policy Objects (GPOs) linked to Organizational Units (OUs), administrators can control password requirements, account lockout thresholds, software deployment, and hundreds of other security-relevant settings from a single location. In this lab, you will connect to a pre-configured Windows Server Domain Controller via PowerShell, create Organizational Units to structure the directory, provision users and security groups, and configure Group Policy Objects that enforce password and account lockout policies - all core skills for managing an enterprise Active Directory environment.
Objectives
Upon completion of this beginner level lab, you will be able to:
- Create Organizational Units (OUs) to establish a logical directory structure for departments
- Provision Active Directory user accounts with proper attributes and OU placement using PowerShell
- Create and manage security groups with appropriate group scopes (Global, Domain Local)
- Add users to security groups and verify group membership
- Create and configure a Group Policy Object (GPO) that enforces password and account lockout policies
- Link GPOs to Organizational Units and verify policy application with gpresult
Who is this lab for?
This lab is designed for:
- IT administrators and cybersecurity students learning Windows Active Directory management
- Students pursuing CISA certifications who need hands-on directory services experience
- System administration learners who want practical GPO configuration skills
Basic familiarity with Windows Server and PowerShell command-line concepts is recommended.
Verified against your live environment
An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.
More labs like this
Implement Network Security Groups (NSGs) and Application Security Groups (ASGs) in Azure
Secure Azure VMs using Network Security Groups and Application Security Groups. Create rules, control traffic flow, and implement least privilege access.
Managing Azure Blob Storage Operations with Azure CLI
Learn how to perform essential Azure Blob Storage operations using Azure CLI commands. Practice uploading, downloading, listing, and deleting blobs with batch operations.
Configure Azure Monitor Alerts and Action Groups for App Service
Create metric alerts, log search alerts, and action groups to monitor an Azure App Service and respond to threshold breaches.
Related reading
Environment
Every lab includes
- Real environment, pre-credentialed
- Automated checks on every step
- Isolated sandbox, auto cleanup
- AI-recommended next steps
Lab curriculum
- 01
Logging into Azure CLI
- 02
Connect to the Domain Controller via Remote PowerShell
1 automated check
- 03
Create Organizational Units for Directory Structure
1 automated check
- 04
Provision Users and Security Groups in Active Directory
1 automated check
- 05
Configure Group Policy for Password and Lockout Settings
1 automated check
Skills validated
Not the lab you were looking for?
Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.