After the primary AD domain controller is configured, you must create AD domain users and groups on the AD domain controller. An administrator can centrally manage domain users and groups and allocate them to different users.
- A user can log in to a client host in the AD domain as a domain user and is authenticated by the primary AD domain controller.
- This section uses Windows Server 2008 R2 as an example to explain how to create AD domain users and groups on the AD domain controller.
- Log in to the Windows AD domain server. Choose Start > Administrative Tools > Active Directory Users and Computers.
The Active Directory Users and Computers page is displayed.
-
- In the Active Directory Users and Computers dialog box, right-click Users.
- Choose New > User.
- Enter the domain user information.
The user information includes First name, Last name, Initials, and User logon name. User logon name is used for AD domain login and authentication.
- Click Next after the user information is configured.
- Enter and confirm the user password. Deselect User must change password at next logon. Click Next.
- Click Finish after you confirm the user information. Return to the Active Directory Users and Computers dialog box. Create a user.
-
- In the Active Directory Users and Computers dialog box, right-click Users.
- Choose New > Group.
- Enter Group name.
- Set Group scope to Global.
- Set Group type to Security.
- Click OK.
Return to the Active Directory Users and Computers dialog box. Create a group.
- Add a user to a group.
- In the Active Directory Users and Computers dialog box, right-click a user to add to a group.
- Select Add to a group.
- In the Enter the object name to select text box, enter the name of the group to which the user is added.
- Click OK. A message is displayed, indicating that the operation succeeded.
- Click OK.