Tagged
active-directory
7 posts · all topics
Reconciling group membership without lockouts
Safe Active Directory reconciliation separates adds from removals, protects critical groups, previews every change, and requires exact approval before changes.
Designing an access matrix PowerShell can enforce
A useful PowerShell access matrix needs 8 required fields, stable role IDs, synthetic test fixtures, and preflight validation before directory changes.
Role-based access without an IGA platform
A 7-stage request, approval, mapping, enforcement, and reconciliation loop gave my small IT shop consistent role access without claiming full IGA coverage.
When to delete a former employee's account (and how)
A disabled account should not sit forever. My 90-day grace period, the pre-delete checklist, and the retention questions to answer before anything is gone.
Revoke access everywhere: the offboarding ghost hunt
Disabling the account is step one. Here are the 7 places a user's access hides, the inventory that finds them, and the stale-login report that catches misses.
Automating offboarding in a one-person IT shop
Onboarding gets the attention. The account you forget to disable is the real risk. Here's my one-person-shop offboarding flow, and the 3 steps I keep manual.
Automating new-hire onboarding in a one-person IT shop
How I replaced a manual, error-prone new-hire checklist with a web form and a PowerShell provisioning script, plus the gotchas that made me keep a human in the loop.