Lab — Manage Domain User Accounts

Security+ SY0-701 objectives: 4.6.1 Provisioning / de-provisioning user accounts · 4.6.8 Access controls (logon restriction)

Scenario

You are the identity administrator at Larkfield Freight Co. The domain larkfield.local runs on the domain controller LARK-DC01. Each department is an organizational unit (OU); user accounts live in their department's OU. A handful of personnel changes landed in your queue this morning. Work through them in Active Directory Users and Computers below, then answer the review questions and submit.

Finance · Priya Nadkarni — too many failed sign-ins; her account is locked. Unlock it, reset the password to Cedar!Ridge2026, and require a password change at next sign-in.

Finance · Devon Pike — left the company. Block sign-in without deleting the account.

Logistics-Eng · Talia Ostrowski — back from sabbatical; her account was disabled while she was away. Restore sign-in.

Logistics-Eng · Hana Kim — legally changed her surname to Vega. Update the account name, last name, and display name to Hana Vega, and change the user logon name and the pre-Windows 2000 logon name to hvega.

Dispatch OU — for everyone in the Dispatch OU (not the DispatchLeads OU), restrict sign-in so they can only log on to the workstation DSP-WS04.

Task checklist

    Active Directory Users and Computers — LARK-DC01.larkfield.local
    larkfield.local
    Console root
    larkfield.local
    Name
    Type
    Description
    Select an organizational unit

    Review questions

    Submit completed lab Use a pseudonym. No real names are stored by this lab.
    Score 0 / 14

    Self-contained practice lab · scoring is self-reported and inspectable in dev tools (formative use).
    © 2026 [Author]. Clean-room original. Microsoft product names used descriptively; not affiliated with Microsoft or any courseware vendor.