SEC GUY / EXPERIENCE BUILDER / PROJECT 01

Build identity. Prove control.

Create an isolated Active Directory lab, automate test accounts, apply least-privilege policy, and document exactly what you validated.

01 / PLANDefine the scope and success criteria
02 / BUILDImplement in an authorized environment
03 / PROVEShow tests, decisions, and tradeoffs
PROJECT BRIEF

A small directory with a defensible story.

This is a local learning environment—not a production domain and not a credential or badge program. Use virtual machines you control, synthetic identities, and a private network. Never put real passwords or account data in a public repository.

ARCHITECTURE

One domain. Clear boundaries.

Build a Windows Server evaluation VM as a domain controller, one test client, an Employees OU, and separate standard-user and admin roles. Document the virtual network, recovery snapshot, and where privileged accounts are used.

SECURITY DECISIONS

Least privilege by design.

Create a handful of synthetic users, group-based access, and one test GPO. Use a unique lab secret entered interactively; do not paste a shared password into scripts or screenshots.

BUILD PLAN

Four phases. Four proofs.

01

Isolate

Create the VMs on a private virtual network and record CPU, RAM, and recovery snapshots.

02

Configure

Install AD DS, create a lab domain and OU, then separate admin and standard accounts.

03

Automate

Use PowerShell to create synthetic users from a small CSV; prompt for a lab password securely.

04

Validate

Test sign-in and policy as a standard user, then document a negative test and cleanup.

ACCEPTANCE CHECKLIST

What the reviewer should see.

  • Topology diagram and lab-only scope
  • Sanitized PowerShell script; no embedded secret
  • OU, groups, and synthetic users visible
  • Before/after evidence for one GPO
  • Standard-user and admin test results
  • Recovery and teardown notes

Portfolio package

Publish a README with the goal, architecture, key decisions, redacted screenshots, tests, and limitations. Include the script, but omit passwords, private identifiers, and VM images.

Interview prompt

Why did you assign access through groups? How did you prove the GPO affected only the intended users? What would change for production identity governance?

Honest scope: Windows Server evaluation terms, VirtualBox support, and hardware needs can change. Check vendor documentation before installing. Sec Guy does not promise validation, a credential, a badge, or a 24-hour review for this project.
YOUR NEXT CONVERSATION

Explain the access decision.

Present what you built, what failed, how you verified it, and what you would improve.

Practice the interview