Back to category

Week 6

Audit User and Group Management Practices in Active Directory

Beginner
IAM Engineer
CIS Controls
User and Group Management
Active Directory

Client Background

The client's helpdesk has flagged inconsistent naming conventions and unclear group ownership across their directory. Review user account provisioning practices, group structure, and ownership to identify administrative hygiene issues.

Business Environment

Brightline Manufacturing (900 employees) runs a flat on-prem Active Directory built during a fast-growth phase and never restructured. A twelve-person IT team handles provisioning manually with no formal joiner-mover-leaver process, and a recent acquisition added a second domain that hasn't been integrated.

Security Incident

No incident; the engagement is a preventive audit. The driver was a failed SOX IT audit citing 'inconsistent account governance,' plus helpdesk reports that two departing employees' accounts remained active for 30+ days, raising separation-of-duties and least-privilege concerns before the next audit cycle.

Scope

Active Directory / Microsoft Entra ID user accounts and group management practices.

Objectives

  • Review user account naming and attribute standards
  • Evaluate group types and nesting structure
  • Assess group ownership and membership review cadence
  • Identify duplicate, unused, or orphaned groups

Required Deliverables

User and Group Management Assessment Report
2 hrs estimated