惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hacker News: Ask HN
Hacker News: Ask HN
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
量子位
博客园_首页
Vercel News
Vercel News
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Forbes - Security
Forbes - Security
IT之家
IT之家
N
News and Events Feed by Topic
S
Security Affairs
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Webroot Blog
Webroot Blog
Recorded Future
Recorded Future
L
LangChain Blog
Y
Y Combinator Blog
AI
AI
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
Know Your Adversary
Know Your Adversary
AWS News Blog
AWS News Blog
Help Net Security
Help Net Security
Cyberwarzone
Cyberwarzone
L
Lohrmann on Cybersecurity
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google Online Security Blog
Google Online Security Blog
V2EX - 技术
V2EX - 技术
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
PCI Perspectives
PCI Perspectives
I
Intezer
T
Tenable Blog
G
Google Developers Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
Troy Hunt's Blog
L
LINUX DO - 最新话题
云风的 BLOG
云风的 BLOG
C
CXSECURITY Database RSS Feed - CXSecurity.com
有赞技术团队
有赞技术团队
O
OpenAI News
P
Proofpoint News Feed
TaoSecurity Blog
TaoSecurity Blog
C
Check Point Blog
Last Week in AI
Last Week in AI
S
Schneier on Security
Simon Willison's Weblog
Simon Willison's Weblog
Blog — PlanetScale
Blog — PlanetScale

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
How to Create An Active Directory - A Hands-on Guide.
David Omokho · 2026-05-19 · via DEV Community

Setting up an Active Directory domain from scratch is one of the most valuable hands-on projects a Windows sysadmin can have in their portfolio. In this guide, you will build a fully functional simulated enterprise environment — complete with a Domain Controller, Group Policy, DNS, DHCP, and domain-joined workstation.

Skill level: Intermediate
What you need: 2 Windows VMs with at least 4 GB RAM each

Key Concepts

Before touching a single command, here is the mental model you need.

Concept What it is
Active Directory Domain Services (AD DS) Microsoft's directory service. Stores information about every user, computer, and resource on a network, and controls who can access what.
Domain Controller (DC) The server running AD DS. It authenticates logins, enforces policies, and is the authority for the entire domain.
Organisational Units (OUs) Folders inside AD. You group users and computers into OUs so different policies can be applied to different departments cleanly.
Group Policy Objects (GPOs) Rules linked to OUs that control security settings, drive mappings, restrictions, and more — applied automatically to every machine in scope.
DNS AD DS relies entirely on DNS to locate the Domain Controller. Without correct DNS, domain joins fail and logins fail.
DHCP Automatically assigns IP addresses and can push the correct DNS server address to every device on the network.

How they fit together: AD DS is the database, the Domain Controller hosts it, OUs organise the records inside it, and GPOs are the rules attached to those records. DNS is the glue that lets every machine find the DC in the first place.


Lab Architecture

[Proxmox Host]
   ├── DC01  —  Windows Server 2022  —  192.168.100.27  (Domain Controller)
   └── WS01  —  Windows 11           —  192.168.100.28  (Domain Member)

Gateway: 192.168.100.1
Domain:  contoso.local

Enter fullscreen mode Exit fullscreen mode

VM Specs

VM OS Role RAM Disk IP
DC01 Windows Server 2022 (Desktop Experience) Domain Controller 4 GB 60 GB 192.168.100.27 (static)
WS01 Windows 10 or 11 Client workstation 4 GB 60 GB 192.168.100.28

Phase 1 — Install & Configure DC01

Boot DC01 from the Windows Server 2022 ISO. Select Windows Server 2022 Standard (Desktop Experience) when prompted. Complete the installation and set a strong Administrator password.

Set a static IP address

A Domain Controller must always be reachable at the same IP. Dynamic addresses will break DNS and domain joins. Open PowerShell as Administrator:

# Set static IP
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress "192.168.100.27" `
 -PrefixLength 24 -DefaultGateway "192.168.100.1"


### Rename the computer
Rename-Computer -NewName "DC01" -Restart

Enter fullscreen mode Exit fullscreen mode

The VM reboots. Log back in as Administrator before continuing.


Phase 2 — Promote DC01 to Domain Controller

Install the AD DS and DNS roles

Install-WindowsFeature -Name AD-Domain-Services, DNS -IncludeManagementTools

Enter fullscreen mode Exit fullscreen mode

⚠️ Common mistake: Install-WindowsFeature only exists on Windows Server. If you see "term not recognised", you are running this on the wrong machine — confirm you are on DC01 running Server 2022, not your Windows 10/11 workstation.

Promote to Domain Controller

This command creates a new forest and domain called contoso.local. DC01 reboots automatically when complete.

Install-ADDSForest `
 -DomainName "contoso.local" `
 -DomainNetBiosName "CONTOSO" `
 -SafeModeAdministratorPassword (ConvertTo-SecureString "P@ssw0rd123!" -AsPlainText -Force) `
 -InstallDns `
 -Force

Enter fullscreen mode Exit fullscreen mode

After the reboot, log in as CONTOSO\Administrator. The login screen now shows the domain name — promotion was successful.

Connect via RDP from from your machine

First, go into the DC01 and enable remote desktop.

Next, if you are managing DC01 from a Linux machine using xfreerdp:

xfreerdp /v:192.168.100.27 /u:Administrator /d:CONTOSO /p:'YourPassword' /cert:ignore /dynamic-resolution /clipboard

Enter fullscreen mode Exit fullscreen mode

Alternatively, you could connect using a GUI RDP client like Remmina (On Linux) or Remote Desktop. Remember that "domain" is CONTOSO


Phase 3 — Build the OU Structure

Organisational Units are the filing system of Active Directory. A well-designed OU structure makes GPO targeting clean and mirrors how real enterprises are organised.

contoso.local
└── Contoso Corp
   ├── IT
   ├── HR
   ├── Finance
   ├── Sales
   ├── Servers
   ├── Service Accounts
   └── _Admin

Enter fullscreen mode Exit fullscreen mode

$domain = "DC=contoso,DC=local"

# Top-level OU
New-ADOrganizationalUnit -Name "Contoso Corp" -Path $domain

$base = "OU=Contoso Corp,$domain"

# Department OUs
foreach ($ou in @("IT","HR","Finance","Sales","Servers","Service Accounts","_Admin")) {
   New-ADOrganizationalUnit -Name $ou -Path $base
}

Enter fullscreen mode Exit fullscreen mode

✅ The _Admin OU uses an underscore prefix so it sorts to the top alphabetically — a common real-world convention for keeping privileged accounts visually separated from standard department OUs.


Phase 4 — Create Users & Groups

Rather than creating users manually through the GUI, use PowerShell (exactly how sysadmins handle bulk provisioning in production).

Create security groups

$groups = @("IT-Team","HR-Team","Finance-Team","Sales-Team")
foreach ($g in $groups) {
   New-ADGroup -Name $g -GroupScope Global -GroupCategory Security `
     -Path "OU=IT,OU=Contoso Corp,DC=contoso,DC=local"
}

Enter fullscreen mode Exit fullscreen mode

Bulk-create users

$domain = "DC=contoso,DC=local"

$users = @(
   @{First="Alice"; Last="Johnson"; Dept="IT";      OU="IT"},
   @{First="Bob";   Last="Smith";   Dept="HR";      OU="HR"},
   @{First="Carol"; Last="Davis";   Dept="Finance";  OU="Finance"},
   @{First="Dan";   Last="Lee";     Dept="Sales";    OU="Sales"}
)

foreach ($u in $users) {
   $username  = ($u.First[0] + $u.Last).ToLower()
   $upn       = "$username@contoso.local"
   $ouPath    = "OU=$($u.OU),OU=Contoso Corp,$domain"
   $password  = ConvertTo-SecureString "Welcome1!" -AsPlainText -Force

   New-ADUser `
       -GivenName       $u.First `
       -Surname         $u.Last `
       -Name            "$($u.First) $($u.Last)" `
       -SamAccountName  $username `
       -UserPrincipalName $upn `
       -Department      $u.Dept `
       -Path            $ouPath `
       -AccountPassword $password `
       -Enabled         $true `
       -PasswordNeverExpires $false `
       -ChangePasswordAtLogon $false
}

Enter fullscreen mode Exit fullscreen mode

⚠️ RDP gotcha: Setting -ChangePasswordAtLogon $true blocks RDP logins entirely — the protocol cannot prompt for a password change mid-connection. Keep it $false for lab use. In production, set it to $true so users choose their own password on first login.


Phase 5 — Configure Group Policy Objects (GPOs)

Group Policy Objects (GPOs) are rules you create and link to Organisational Units. Every user and computer inside that OU automatically receives and enforces those rules — no manual configuration needed on each machine. You manage GPOs through the Group Policy Management Console (GPMC), which was installed alongside AD DS earlier.

Open GPMC from DC01 via: Server Manager → Tools → Group Policy Management


GPO 1 — Security Baseline (linked to Contoso Corp)

This GPO applies to every user and computer under the Contoso Corp OU — think of it as your organisation-wide minimum security standard.

First, create and link the GPO via PowerShell:

New-GPO -Name "Security Baseline"
New-GPLink -Name "Security Baseline" -Target "OU=Contoso Corp,DC=contoso,DC=local"

Enter fullscreen mode Exit fullscreen mode

Then configure the settings inside GPMC.

To find it, in the left panel, expand:
Forest: contoso.local → Domains → contoso.local → Group Policy Objects
You should see Security Baseline listed there.

Right-click Security Baseline → Edit to open the Group Policy Management Editor, then follow each path below:

  • Enforce UAC (User Account Control) UAC is a Windows security feature that prevents unauthorised changes to the system by prompting for administrator approval. Enforcing it via GPO ensures users cannot disable it locally.

Computer Configuration → Policies → Windows Settings → Security Settings → Local Policies → Security Options

Set "User Account Control: Run all administrators in Admin Approval Mode"Enabled

  • Minimum Password Length

Enforces that no account in the domain can have a password shorter than 12 characters.

Computer Configuration → Policies → Windows Settings → Security Settings → Account Policies → Password Policy

Set "Minimum password length"12 characters

  • Account Lockout Policy

Locks an account after repeated failed login attempts, protecting against brute-force attacks. After 15 minutes the account unlocks automatically.

Computer Configuration → Policies → Windows Settings → Security Settings → Account Policies → Account Lockout Policy

Set "Account lockout threshold"5 invalid logon attempts
Set "Account lockout duration"15 minutes
Set "Reset account lockout counter after"15 minutes


GPO 2 — Workstation Lockdown (linked to non-IT OUs)

This GPO restricts what standard users can do on their workstations. You will link it to HR, Finance, and Sales — but not IT, since your IT team needs unrestricted access to manage systems.

First, create and link the GPO to each non-IT department OU:

New-GPO -Name "Workstation Lockdown"

# Link to each non-IT OU
foreach ($ou in @("HR","Finance","Sales")) {
   New-GPLink -Name "Workstation Lockdown" `
     -Target "OU=$ou,OU=Contoso Corp,DC=contoso,DC=local"
}

Enter fullscreen mode Exit fullscreen mode

Then in GPMC, right-click Workstation Lockdown → Edit

Workstation lockdown

... then configure the following:


  • Disable Access to Control Panel and PC Settings

Prevents standard users from changing system settings, uninstalling software, or modifying network configuration — common restrictions in managed enterprise environments.

User Configuration → Policies → Administrative Templates → Control Panel (Click on it)

Double-click "Prohibit access to Control Panel and PC Settings" → Set to Enabled → Click OK


  • Prevent Access to Command Prompt

The Command Prompt (cmd.exe) can be used to bypass desktop restrictions. Disabling it for non-IT users reduces the risk of accidental or deliberate system changes.

User Configuration → Policies → Administrative Templates → System

Double-click "Prevent access to the command prompt" → Set to Enabled

When prompted "Disable the command prompt script processing also?" → Select No (selecting Yes would also break logon scripts, which you don't want)

Click OK


  • Remove Run Dialog from Start Menu

The Run dialog (Win + R) gives users a quick way to launch programs and access network paths, which can be used to circumvent other restrictions. Removing it closes that gap.

User Configuration → Policies → Administrative Templates → Start Menu and Taskbar

Double-click "Remove Run menu from Start Menu" → Set to Enabled → Click OK


Verify the GPO is linked correctly

foreach ($ou in @("HR","Finance","Sales")) {
   Write-Host "`n--- $ou ---"
   Get-GPInheritance -Target "OU=$ou,OU=Contoso Corp,DC=contoso,DC=local" |
     Select-Object -ExpandProperty GpoLinks
}

Enter fullscreen mode Exit fullscreen mode

You should see Workstation Lockdown listed under each of the three OUs.


GPO 3 — IT Drive Mapping (linked to IT OU)

First create the share on DC01:

New-Item -Path "C:\Shares\ITShare" -ItemType Directory
New-SmbShare -Name "ITShare" -Path "C:\Shares\ITShare" `
 -FullAccess "CONTOSO\IT-Team" -ReadAccess "CONTOSO\Domain Users"

Enter fullscreen mode Exit fullscreen mode

Next, Create the Drive Map in GPMC manually...
This part is done entirely through the GUI. In GPMC, right-click Workstation Lockdown (or whichever GPO is linked to the IT OU) → Edit, then navigate to:

User Configuration → Preferences → Windows Settings → Drive Maps
IT FIle Share
Right-click in the right-hand pane → New → Mapped Drive


Then in GPMC: User Configuration → Preferences → Windows Settings → Drive Maps → map \\DC01\ITShare to Z: for the IT OU.


Phase 6 — Join WS01 to the Domain

On WS01, first point DNS at DC01. Without this, WS01 cannot resolve contoso.local and the domain join will fail.

Step 1: Open Network Settings → Change adapter options → IPv4 Properties. Set Preferred DNS to 192.168.100.27.

Step 2: Join the domain — run this on WS01 as Administrator:

Add-Computer -DomainName "contoso.local" `
 -Credential (Get-Credential) `
 -OUPath "OU=IT,OU=Contoso Corp,DC=contoso,DC=local" `
 -Restart

Enter fullscreen mode Exit fullscreen mode

Step 2.5: Allow ajohnson to use RDP
Domain users are not automatically allowed to RDP into machines — you need to add them to the local Remote Desktop Users group on WS01:

powershellAdd-LocalGroupMember -Group "Remote Desktop Users" -Member "CONTOSO\ajohnson"

Enter fullscreen mode Exit fullscreen mode

Or to allow all domain users to RDP into WS01:

powershellAdd-LocalGroupMember -Group "Remote Desktop Users" -Member "CONTOSO\Domain Users"

Enter fullscreen mode Exit fullscreen mode

Step 3: RDP into WS01 from Linux as a domain user:

xfreerdp /v:192.168.100.28 /u:ajohnson /d:CONTOSO /p:'Welcome1!' /cert:ignore /dynamic-resolution /clipboard

Enter fullscreen mode Exit fullscreen mode

Step 4: Verify GPOs applied correctly:

# Quick summary in terminal
gpresult /r

# Full HTML report
gpresult /h "C:\Users\ajohnson\Documents\gp-report.html"

Enter fullscreen mode Exit fullscreen mode


Bonus — DNS & DHCP

Verify and extend DNS

Do the the following in DC01...

# View all DNS zones
Get-DnsServerZone

# View A records in contoso.local
Get-DnsServerResourceRecord -ZoneName "contoso.local" -RRType A

# Add a custom record for a simulated intranet server
Add-DnsServerResourceRecordA -ZoneName "contoso.local" `
 -Name "intranet" -IPv4Address "192.168.100.29"

Enter fullscreen mode Exit fullscreen mode

Install and configure DHCP

Install-WindowsFeature DHCP -IncludeManagementTools

Add-DhcpServerv4Scope -Name "CorpLAN" `
 -StartRange "192.168.100.100" -EndRange "192.168.100.199" `
 -SubnetMask "255.255.255.0"

Set-DhcpServerv4OptionValue -ScopeId "192.168.100.0" `
 -DnsServer "192.168.100.27" -Router "192.168.100.1"

Add-DhcpServerInDC -DnsName "dc01.contoso.local"

Enter fullscreen mode Exit fullscreen mode

IT FIle Share

AD Users


Skills This Project Demonstrates

  • Active Directory DS — forest/domain deployment, OU structure design
  • Group Policy — security baseline, account lockout, drive map preferences
  • DNS & DHCP — zone management, custom records, scope configuration
  • PowerShell automation — bulk user/group creation, role installation
  • Windows networking — static IPs, domain join, name resolution
  • Security fundamentals — password policy, account lockout, UAC enforcement

Wrapping Up

You now have a fully functional enterprise-grade Active Directory environment running in your lab — a Domain Controller, a domain-joined workstation, a structured OU hierarchy, enforced Group Policy, DNS, and DHCP, all provisioned largely through PowerShell.

Want to extend this? Here are possible next steps:

  • Add a second domain controller and explore AD replication — understanding how DCs sync is essential knowledge for any enterprise environment
  • Set up RSAT on WS01 and practice managing the domain entirely from the workstation, the way most administrators actually work day-to-day
  • Simulate a user offboarding workflow — disable the account, move it to a dedicated Disabled OU, strip group memberships, and document the process as a runbook
  • Explore fine-grained password policies — apply stricter password requirements to the _Admin OU without affecting standard users
  • Break something on purpose — delete a GPO link, misconfigure DNS, corrupt a user account — and practice diagnosing and recovering from it. Troubleshooting under pressure is a skill, and the only way to build it is to practise it in a safe environment

Found this useful? Drop a comment below or connect with me — I am always happy to talk through home lab setups and sysadmin career questions.

-> See the GitHub Repo
-> Connect with me On LinkedIn