Introduction:
This guide provides a comprehensive step-by-step process for creating a user account in Active Directory (AD) and integrating the account with Microsoft 365. Proper user account setup ensures secure access to organizational resources and seamless synchronization between on-premises and cloud environments.
Process description:
The process involves creating a new user account in Active Directory, configuring essential properties, and ensuring synchronization with Microsoft 365. This allows users to securely access email, apps, and internal systems while being properly grouped for communication and resource access.
Prerequisites:
- Administrative access to domain controllers (e.g., WTVWDCPROD1 or WTVWDCPROD2)
- Access to Microsoft 365 Admin Center
- Knowledge of the user's role, department, and manager
- Group membership requirements for Allstaff and Zendesk
Gathering materials/resources:
- User’s full name, job title, department, and manager (New hire ticket will have this info)
- Username format (Frist initial, last name, e.g., jdoe)
- Access credentials for both Active Directory and Microsoft 365 Admin
- Available Microsoft 365 licenses
- List of group memberships for similar roles
Step-by-step instructions:
1. Open the ADUC Tool
- Log in to WTVWDCPROD1 or WTVWDCPROD2.
- Open Active Directory Users and Computers.
2. Navigate to the Organizational Unit (OU)
- In the left-hand pane, expand cprsonline.com, then expand CPRS, and click CPRS-Employees.
- Locate and select the appropriate Organizational Unit (OU) for the new user account.
3. Create a New User
- Right-click the selected OU, go to New, and choose User.
- The New Object - User wizard will open.
4. Enter User Information
- First Name: Enter the user’s first name.
- Last Name: Enter the user’s last name.
- Full Name: Automatically populated but editable.
- User Logon Name: Enter the username (e.g., jdoe). Select @cprs-inc.com from the dropdown.
5. Set the Password
- Specify a password (e.g., Password1). This is a temporary password that must be updated later in Microsoft 365 Admin.
- The account will sync to Azure AD after completion. You will need to reset password in Azure AD and update it in Active Directory. This will be the temp password you will send the user.
- Options:
- User must change password at next logon: Recommended for security.
- User cannot change password: Typically for service accounts.
- Password never expires: Rarely used, except for specific needs.
- Account is disabled: For accounts not immediately active.
6. Change the Password
- In AD: Right-click the username, then select Reset Password.
- In Microsoft 365 Admin:
- Search for the user in Active Users under Users.
- Click the user’s name, then select Reset Password.
Important: Always update the password in both AD and Microsoft 365 Admin. Failure to do so will prevent the user from logging in with the temporary password.
7. Complete the Wizard
- Review the details and click Finish.
8. Modify Additional Properties
- After creating the account, double-click the user to open the Properties dialog and configure the following:
- General Tab: Add a job title and email.
- Organization Tab: Specify the job title, department, company, and manager.
- For the manager, click Change and search for the manager’s name.
- Member Of Tab: Add the user to the required groups.
- To determine group memberships, mirror another user’s account.
- Click Apply and OK after making changes.
9. Configure Microsoft 365 Admin
- Wait 5–10 minutes for the AD account to sync with Microsoft 365 Admin.
- Search for the user in Microsoft 365 Admin and configure the following:
- Roles Tab: Assign administrative roles as needed.
- Licenses and Apps Tab:
- Assign the required license, such as Microsoft 365 Business Premium (for email and app access).
- If licenses are unavailable, email Convergence to request additional licenses.
- Click Save Changes.
10. Add the User to Allstaff Groups
- Allstaff and Allstaff_US Groups:
- Navigate to Teams and Groups > Active Teams and Groups.
- Search for Allstaff and select the group with allstaff@cprs-inc.com as the email.
- Click Members > View All and Manage Members > Add Members.
- Search for and add the user.
- Repeat the steps for Allstaff_US if the user is based in the United States.
11. Add Zendesk Users:
- In the left pane, click Show All, at the bottom under Admin centers, click identity, another tab will open. Sign in using your credentials if prompt to do so. It will take you to Microsoft Entra Admin Center:
-
-
- Go to Groups > All Groups and search for Zendesk.
- Select Zendesk Users and click Members > Add Members.
- Search for and add the user.
-
-
Tips and best practices:
- Always mirror an existing user's group membership for similar roles
- Use strong, temporary passwords and require changes at first logon
- Double-check Microsoft 365 license availability in advance
Next steps:
- Notify the new user of their temporary credentials via secure email
- Ensure the user logs in and changes their password promptly
- Monitor synchronization and access issues post-creation
- Periodically review user account configurations and group memberships
Additional information:
- References: New Hire Ticket, New Hire Secure Email
Disclaimer:
This guide is intended for use by IT administrators familiar with Active Directory and Microsoft 365.
Comments
0 comments
Please sign in to leave a comment.