PEAS  /  Case study

Infrastructure case study

Centralised identity & access with Active Directory.

How we replaced insecure local accounts with a single, policy-driven identity platform — built on Windows Server 2022, segmented on Proxmox, and verified end to end from a domain-joined client.

Domain
peas.local
Platform
Windows Server 2022 · Proxmox VE
Departments
IT · Finance · Management
Status
Deployed & tested

The challenge

From scattered local accounts to one source of truth.

Before this project, every workstation used its own local accounts. Onboarding and offboarding was manual, passwords were inconsistent, and there was no central way to control who could access which files.

We designed and deployed a Microsoft Active Directory environment that centralises authentication, organises users by department, enforces a strong password and lockout policy, and restricts file access on a strict least-privilege basis — all built and tested in a virtualised lab on Proxmox VE.

Domain controllerPEAS-DC01 · 10.10.20.10
Server rolesAD DS · DNS · File & Storage
ClientPEAS-WIN10 · domain-joined
Identity modelOUs · security groups · GPO
Password policy12 chars · lockout at 5

How it was built

Five stages, from bare server to tested platform.

  1. Promote the domain controller

    Installed Windows Server 2022, assigned a static IP, and promoted it to a domain controller — creating the peas.local forest with integrated DNS.

  2. Model the organisation

    Built Organisational Units per department, with user accounts and Global security groups, and added each user to their department group.

  3. Secure the resources

    Created departmental file shares with least-privilege share and NTFS permissions, so each group reaches only its own folder.

  4. Enforce policy

    Applied Group Policy: 12-character minimum passwords with complexity, and account lockout after 5 failed attempts.

  5. Join & verify

    Domain-joined a Windows 10 client and verified the entire configuration from a real user's perspective.

Promoting Windows Server to a domain controller
Domain controller promotion — creating the peas.local forest with DNS and Global Catalog.
Active Directory Users and Computers showing OUs, group and user
Active Directory structure — departmental OUs, a security group and a user account.
Department file shares on the domain controller
Departmental file shares — separate, permissioned storage for each department.

Verification

Proven from a domain-joined client.

Every control was tested from the Windows 10 client, signed in as the domain user peas\it.user1.

TestResult
Domain login & membershipPASS — authenticated to peas.local, member of IT_Group
File-share access controlPASS — IT accessible; Finance & Management denied
Password & lockout policyPASS — 12-char minimum, lockout at 5 attempts
Group Policy appliedPASS — Default Domain Policy received from the DC
File share access control: IT allowed, Finance and Management denied
Least-privilege access in action — the IT user opens the IT share, but is denied Finance and Management.
Domain password and lockout policy
Password & lockout policy — 12-character minimum and account lockout enforced domain-wide.
Group Policy result showing Default Domain Policy applied
Group Policy confirmed — the client receives the Default Domain Policy from PEAS-DC01.

Technologies & skills

What this project demonstrates.

Windows Server 2022Active Directory (AD DS)DNS Organisational UnitsSecurity groupsGroup Policy (GPO) NTFS & share permissionsLeast-privilege access Windows 10 domain joinProxmox VENetwork troubleshooting

Secure identity, designed in from day one.

This is the same foundation PEAS builds for every client — centralised, monitored and recoverable.

Talk to our team →