Learn / Labs / Tools
Identity & Access
Active Directory, authentication, authorization, service accounts, permissions, access paths, and identity-related operational troubleshooting.
01
Learn
Understand Identity & Access
Technical guides that explain the concepts, architecture, decisions, and durable operator patterns.
Comparing Identity Validation Paths Across DNS, LDAP, Kerberos, and SMBDecide whether an identity or Windows access failure should be validated from DNS, LDAP, Kerberos, or SMB first.Identity Evidence-First Comparison Between Good and Broken PathsCompare a working identity or protocol path against the failing one before you change AD, DNS, trust, or service settings.Planning Identity and Windows Protocol Troubleshooting Without GuessingIsolate identity and Windows protocol failures by mapping the failing boundary before changing DNS, AD, SMB, or auth settings.
02
Labs
Practice Identity & Access
Hands-on labs that turn the concepts into working systems and repeatable environments.
A hands-on lab has not been assigned to this path yet.
03
Tools
Operate Identity & Access
Free operator tools for checks, scripts, evidence, reporting, and practical infrastructure work.
AD stale computer cleanup reportA read-only Active Directory stale computer report for last logon, OU, operating system, enabled state, and cleanup planning.All-DC lastLogon collector and stale-user evidence reportCollect non-replicated lastLogon values from every writable domain controller, calculate the newest observed logon per account, and export evidence suitable for stale-user or stale-computer cleanup decisions without relying on replicated lastLogonTimestamp alone.Inactive AD user disable review workflowTwo-phase review checklist for identifying inactive AD user accounts, validating inactivity evidence, applying exclusions, capturing approval, and preparing rollback details before any disable action.Local administrator group audit across Windows endpointsA read-only local administrator audit that records privileged group membership across Windows endpoints for review.Service account retirement evidence workflowCombine configuration discovery with runtime authentication evidence, SPN/Kerberos review, owner approval, an observation window, and explicit DISABLE / HOLD / ROLLBACK criteria before retiring a domain service account.Service account usage finderA read-only configuration-discovery pass for service-account assignments in Windows services, scheduled tasks, and IIS application pools, designed as the first step of—not a substitute for—the full retirement evidence workflow.SMB working-user vs failing-user access comparisonCompare a working and failing user's identity, token, Kerberos, share ACL, NTFS ACL, inheritance, and effective-access path to identify the first authorization delta before changing permissions.
