Accounts in Austin Active Directory

Accounts in Austin Active Directory

Overview

There are two types of accounts in the Austin Active Directory:

  • EID-based accounts which are synced from the uTexas Identity Manager (TIM)

  • Department User and Department Service accounts which are managed in the Department User Tools

EID-Based Accounts

Which EID-based accounts exist in the Austin Active Directory?

All person EIDs have an EID-based account in the Austin Active Directory provided the EID has not met the conditions for it to be removed.

Will EID-based accounts be a member of Domain Users or Domain Guests?

All EID-based accounts will be a member of either the Domain Users group or the Domain Guests group and will have this group set as the Primary Group on the user object. When an EID-based account has one of the required affiliations or entitlements, its Primary Group will be Domain Users. When an EID-based account no longer has any of the required affiliations or entitlements, its Primary Group will be Domain Guests. An EID-based account that is a member of the Domain Guests group will not be able to authenticate to Windows and Mac computers joined to the domain unless overriden by a department via Group Policy. Linux computers joined to the domain must take additional steps to block members of the Domain Guests group from authenticating.

Which EID-based accounts are enabled in the Austin Active Directory?

An EID-based account is enabled when the following conditions are true:

  • The EID has the Active logon status in the EID system

  • The EID is not required to change their password

Any EID-based account that does not meet the conditions above will be disabled.

Are EID-based accounts removed from the Austin Active Directory?

EID-based accounts are removed from Austin Active Directory when all of the following conditions are true:

  • The EID does not have the Active logon status in the EID system

    • EIDs that are inactive for 15 months will lose the Active logon status

  • The account has been disabled in the Austin Active Directory for at least 15 months

    • Accounts that were never enabled will be retained for 15 months after the EID was created

  • The account has Domain Guests as the Primary Group

    • Accounts in the Domain Users group via an affiliation or entitlement are not removed

  • The account does not have an mailbox in Microsoft 365

The combination of the EID inactivity timer and the independent Austin Active Directory timer results in EID-based accounts being removed from the Ausdtin Active Directory after 30 months (2.5 years) of inactivity provided that all conditions have been met. An EID-based account will not be removed from the Austin Active Directory if any of the required conditions are not met.

Which affiliations and entitlements grant an EID-based account membership in the Domain Users group?

The following lists define the affiliations and entitlements that grant membership in the Domain Users group in the Austin Active Directory. An EID-based acount with an affiliation or an entitlement from either list below will be a member of the Domain Users group in the Austin Active Directory.

Affiliations

Affiliations

Current Faculty

Future Faculty

Current Staff

Future Staff

Current Student

Future Student

University Affiliate

University Extension Participant

Official Visitor

Entitlements

Entitlements

AAD

EML

LLC

LLT

LLV

LLG

LLS

CWU

OLL

 

Department User and Service Accounts

Department OU owners can create Department User and Service accounts on the Department User Tools.

Refer to the Department User Tools documentation for more information on the creation and management of Department accounts.