Accounts in Austin Active Directory
Overview
There are two types of accounts in the Austin Active Directory:
EID-based accounts which are synced from the uTexas Identity Manager (TIM)
Department User and Department Service accounts which are managed in the Department User Tools
EID-Based Accounts
Which EID-based accounts exist in the Austin Active Directory?
All person EIDs have an EID-based account in the Austin Active Directory provided the EID has not met the conditions for it to be removed.
Will EID-based accounts be a member of Domain Users or Domain Guests?
All EID-based accounts will be a member of either the Domain Users group or the Domain Guests group and will have this group set as the Primary Group on the user object. When an EID-based account has one of the required affiliations or entitlements, its Primary Group will be Domain Users. When an EID-based account no longer has any of the required affiliations or entitlements, its Primary Group will be Domain Guests. An EID-based account that is a member of the Domain Guests group will not be able to authenticate to Windows and Mac computers joined to the domain unless overriden by a department via Group Policy. Linux computers joined to the domain must take additional steps to block members of the Domain Guests group from authenticating.
Which EID-based accounts are enabled in the Austin Active Directory?
An EID-based account is enabled when the following conditions are true:
The EID has the Active logon status in the EID system
The EID is not required to change their password
Any EID-based account that does not meet the conditions above will be disabled.
Are EID-based accounts removed from the Austin Active Directory?
EID-based accounts are removed from Austin Active Directory when all of the following conditions are true:
The EID does not have the Active logon status in the EID system
EIDs that are inactive for 15 months will lose the Active logon status
The account has been disabled in the Austin Active Directory for at least 15 months
Accounts that were never enabled will be retained for 15 months after the EID was created
The account has Domain Guests as the Primary Group
Accounts in the Domain Users group via an affiliation or entitlement are not removed
The account does not have an mailbox in Microsoft 365
The combination of the EID inactivity timer and the independent Austin Active Directory timer results in EID-based accounts being removed from the Ausdtin Active Directory after 30 months (2.5 years) of inactivity provided that all conditions have been met. An EID-based account will not be removed from the Austin Active Directory if any of the required conditions are not met.
Which affiliations and entitlements grant an EID-based account membership in the Domain Users group?
The following lists define the affiliations and entitlements that grant membership in the Domain Users group in the Austin Active Directory. An EID-based acount with an affiliation or an entitlement from either list below will be a member of the Domain Users group in the Austin Active Directory.
Affiliations |
|---|
Current Faculty |
Future Faculty |
Current Staff |
Future Staff |
Current Student |
Future Student |
University Affiliate |
University Extension Participant |
Official Visitor |
Entitlements |
|---|
AAD |
EML |
LLC |
LLT |
LLV |
LLG |
LLS |
CWU |
OLL |
Department User and Service Accounts
Department OU owners can create Department User and Service accounts on the Department User Tools.
Refer to the Department User Tools documentation for more information on the creation and management of Department accounts.