Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

How To Configure Access Controls With Active Directory: Page 2 of 6

For our Step by Step instructions, assume we want to create user accounts that belong to different departments in the organization, along with logon rules and access controls for such accounts. Users in different departments would get different access controls. In addition, we assume that AD is installed on our Windows 2000 server and that our server is the domain controller. If the AD is not installed, you can run the AD installation wizard by selecting Start/Run and entering Dcpromo.exe.

Marco Morana is an independent consultant specializing in the design and development of secure enterprise applications. Write to him at [email protected].

1 Configure Active Directory Create the directory structure and two top-level OUs: one for IT and one for the rest of the company. Access the AD "users and computers" MMC snap-in. Select the domain as root level. Right-click and select "New and Organizational Unit." Enter the object name. Click OK. Similarly, create a departments OU at the same root level of IT and create subdepartment OUs by selecting "Departments" as root level.