Услуга · System administration

Active Directory setup

From about twenty people, managing access by hand becomes torture. A domain removes that in one stroke: one password for all systems, settings distributed centrally, and a departing employee disabled with a single action rather than a tour of fifteen programs.

One sign-on
into all systems
Settings
distributed centrally
Care
disabled in a minute
Trail
people actions are visible

What the work includes

What is useful is not the directory itself but the procedures built around it: how people are onboarded, transferred, offboarded and granted rights.

Discuss the scope

Controllers

We deploy with redundancy and bring up name resolution and a common time source.

Structure

People are arranged by department rather than dumped into one long list.

Workstation settings

Centrally: screen locking, network drives, printers, permissions and restrictions.

Access groups

Rights go to a group, not a person. Otherwise in a couple of years the structure becomes unreadable.

Password requirements

Sensible ones: too strict and notes appear on monitors, too lax and passwords get guessed.

Procedures

What is done on joining, transfer and leaving, point by point and with named owners.

How it goes

Deploying from scratch for a company of up to a hundred workstations takes one and a half to two weeks, including joining the machines.

01

Design

How the departments will look, which groups are needed, in what order the machines are added.

02

Deployment

Controllers, supporting services, base settings.

03

Joining

We onboard workstations department by department with a check after each step.

04

Handover

Documentation, training for your administrator, ready-made HR procedures.

A single domain controller means the whole company stops when it fails. People simply cannot log into their computers, and nothing works at all. A second controller in a virtual environment costs next to nothing and deploys in an hour; without it any routine maintenance turns into a risk.

Questions and answers

The benchmark is fifteen to twenty workstations. Below that, manual management is still tolerable. Above it, every change has to be repeated on every machine, settings drift apart, and nobody knows what is where any more.

To groups only. Access granted to an individual becomes impossible to explain a year later: it is unclear where it came from or whether it can be removed. A group membership is visible at a glance and its purpose is clear from the name.

The account is disabled, not deleted. Deleting it takes away the rights to files the person owned, and restoring them afterwards is painful. Mail passes to the manager, the equipment comes back, access is revoked the same day.

We will deploy a domain

Write how many workstations you have and whether a domain exists now. We will propose a structure and a joining order with no downtime.