Risk of having External Users in Active Directory?

Taha 80 Reputation points
2023-12-20T08:06:12.0133333+00:00

Hello Experts,

We have external users (Vendors, implementation partners, etc.) access our company application.

The way we provide them access is by onboarding them on our Active directory and authenticating them with our Identity provider. I would like to know what are the risks of having external users in our active directory, and should we have a different OU for them or altogether a different Active directory.

Thanks,

Windows for business Windows Client for IT Pros Directory services Active Directory
{count} votes

Accepted answer
  1. Andreas Baumgarten 123.4K Reputation points MVP Volunteer Moderator
    2023-12-20T08:42:03.9433333+00:00

    Hi @Taha ,

    based on your provided information I don't see a reason to setup a separated Active Directory just for the external users.

    Most of our customers are organizing the external users in their on-premises AD in dedicated OUs.

    This way the external users are really easy to identify and managed.

    A challenge managing external users in your own AD, it doesn't matter if in your central AD or an additional AD, is to manage the user accounts if a user left the external organization. Over time this might cause orphaned user accounts in your AD.

    One way to get this managed could be to monitor the last login date of external users. If a user's last login was x days before, for instance 180 days, deactivate the user, after additional 180 days delete the external user. Just an example.


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

    Regards

    Andreas Baumgarten

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.