Active Directory Administration

User accounts, groups, and access across Windows Server 2008 R2 and 2019. Joiner, mover and leaver discipline with regular reviews. No ghost accounts.

The Work

I manage user accounts and groups across Active Directory on Windows Server 2008 R2 and 2019. These are the central identity systems feeding access to both network resources and Microsoft services. When someone joins, I create their account and set up the right group memberships. When they change roles, their access shifts with them. When they leave, I make sure everything gets revoked cleanly - no ghost accounts, no leftover permissions.

Why It Matters

Bad directory hygiene always surfaces at the worst time. Someone can’t log in on their first day. Or a departed employee still has access to shared drives. I work to prevent both. That means regular account reviews, solid onboarding checklists, and making sure permission changes actually stick when people move around.

The less glamorous part - and the critical part - is keeping documentation current. I maintain notes on what each group does so the next person can understand the structure without reverse-engineering it.

What I’ve Learned

Written checklists are gold during busy weeks. They save mistakes. And I’ve learned that documenting group strategy when you’re setting it up beats trying to figure it out later when something breaks.

Active DirectoryWindows Server 2019Windows Server 2008 R2User and Group Administration

🌍 Environment: UNDP and judiciary Windows Server environments

What this covers

  • Account & group management
  • Access reviews
  • No ghost accounts