← Technician · Practitioner
Lesson 1 of 412 min

Active Directory basics

Users, groups, OUs, and the difference between local and domain accounts.

Organizational directory structure on a laptop screen
Photo by Christina Morillo on Pexels

Active Directory (AD (Active Directory)) is Microsoft's on-prem directory service. It holds user accounts, computer accounts, and groups, organized into Organizational Units (OUs).

A domain user can log into any joined PC (Personal Computer). A local user only exists on one machine. Most password-reset tickets are AD users — use Active Directory Users and Computers (ADUC (Active Directory Users and Computers)).

Diagram · Active Directory hierarchy
corp.localOU: SalesusrusrusrOU: FinanceusrusrusrOU: ITusrusrusr

Groups grant permissions in bulk. Never assign permissions directly to a user — put the user in a group and grant the group.

Key takeaways

Areas to show initiative · +15 XP each

Next: Microsoft 365 from the help-desk seat →