Week 6
Audit User and Group Management Practices in Active Directory
Client Background
The client's helpdesk has flagged inconsistent naming conventions and unclear group ownership across their directory. Review user account provisioning practices, group structure, and ownership to identify administrative hygiene issues.
Business Environment
Brightline Manufacturing (900 employees) runs a flat on-prem Active Directory built during a fast-growth phase and never restructured. A twelve-person IT team handles provisioning manually with no formal joiner-mover-leaver process, and a recent acquisition added a second domain that hasn't been integrated.
Security Incident
No incident; the engagement is a preventive audit. The driver was a failed SOX IT audit citing 'inconsistent account governance,' plus helpdesk reports that two departing employees' accounts remained active for 30+ days, raising separation-of-duties and least-privilege concerns before the next audit cycle.
Scope
Active Directory / Microsoft Entra ID user accounts and group management practices.
Objectives
- Review user account naming and attribute standards
- Evaluate group types and nesting structure
- Assess group ownership and membership review cadence
- Identify duplicate, unused, or orphaned groups
Required Deliverables