Active Directory (On-Prem) Lab

Enterprise AD Management | Security Hardening | PowerShell Automation

Overview

This lab provides hands-on experience with managing and securing traditional on-premises Active Directory environments. It focuses on critical areas such as organizational design, DNS configuration, security hardening, user & group lifecycle management, delegated administration, automation with PowerShell, and backup & recovery procedures. These walkthroughs simulate real-world enterprise IAM and Windows infrastructure tasks.

📂 Lab Walkthroughs

AD Forest & Domain Architecture

Overview of AD forests, domains, trusts, and key design considerations.

View Walkthrough

DNS Configuration

Configure client systems to use domain DNS for proper join and resolution.

View Walkthrough

OU & GPO Management

Create and organize OUs and apply GPOs for centralized policy control.

View Walkthrough

User & Group Management

Lifecycle tasks, group scope/type, and membership management.

View Walkthrough

Delegation & Access Control

Delegate admin roles and securely manage permissions across OUs.

View Walkthrough

AD Security Hardening

Secure DCs, harden audit policy, and manage privileged accounts.

View Walkthrough

Authentication Protocols

Overview and configuration of AD authentication methods and protocols.

View Walkthrough

PowerShell for AD Management

Automate routine tasks with common AD cmdlets and scripts.

View Walkthrough

AD Backup & Recovery

Protect and restore AD using backup, tombstone, and recycle bin.

View Walkthrough

🛠️ Tools Used

Virtualization: VirtualBox (for running lab VMs)
AD Management: Active Directory Users and Computers (ADUC)
Group Policy: Group Policy Management Console (GPMC)
Scripting: PowerShell with AD module
Server OS: Windows Server 2016 / 2019 / 2022

🌐 Related Labs

AD-Entra-Hybrid-Lab – Sync and federate on-prem AD with Microsoft Entra ID.
Microsoft Entra ID Lab – Cloud-based identity and access management (MFA, SAML, OIDC, automation).