Learn / Labs / Tools

Identity & Access

Active Directory, authentication, authorization, service accounts, permissions, access paths, and identity-related operational troubleshooting.

3 guides0 labs7 tools0 capability mapsBrowse all topic paths
01

Learn

Understand Identity & Access

Technical guides that explain the concepts, architecture, decisions, and durable operator patterns.

02

Labs

Practice Identity & Access

Hands-on labs that turn the concepts into working systems and repeatable environments.

A hands-on lab has not been assigned to this path yet.

03

Tools

Operate Identity & Access

Free operator tools for checks, scripts, evidence, reporting, and practical infrastructure work.

AD stale computer cleanup reportA read-only Active Directory stale computer report for last logon, OU, operating system, enabled state, and cleanup planning.ScriptActive Directory and IdentityRead-onlyAll-DC lastLogon collector and stale-user evidence reportCollect non-replicated lastLogon values from every writable domain controller, calculate the newest observed logon per account, and export evidence suitable for stale-user or stale-computer cleanup decisions without relying on replicated lastLogonTimestamp alone.ScriptActive Directory and IdentityRead-onlyInactive AD user disable review workflowTwo-phase review checklist for identifying inactive AD user accounts, validating inactivity evidence, applying exclusions, capturing approval, and preparing rollback details before any disable action.ChecklistActive Directory and IdentityChanges system stateLocal administrator group audit across Windows endpointsA read-only local administrator audit that records privileged group membership across Windows endpoints for review.ScriptActive Directory and IdentityRead-onlyService account retirement evidence workflowCombine configuration discovery with runtime authentication evidence, SPN/Kerberos review, owner approval, an observation window, and explicit DISABLE / HOLD / ROLLBACK criteria before retiring a domain service account.ChecklistActive Directory and IdentityChanges system stateService account usage finderA read-only configuration-discovery pass for service-account assignments in Windows services, scheduled tasks, and IIS application pools, designed as the first step of—not a substitute for—the full retirement evidence workflow.ScriptActive Directory and IdentityRead-onlySMB working-user vs failing-user access comparisonCompare a working and failing user's identity, token, Kerberos, share ACL, NTFS ACL, inheritance, and effective-access path to identify the first authorization delta before changing permissions.ChecklistActive Directory and IdentityRead-only