## TL;DR
Learn ten commands: find a user, check lockout and password expiry, list group memberships, unlock an account, test connectivity, and check a service. These cover the majority of AD-adjacent tickets without opening a GUI.

## The error
```text
(Training reference; no error.)
```

## Steps
1. Find a user: `Get-ADUser -Filter "Name -like '*smith*'" -Properties *`. Expected: user objects listed. The workhorse lookup.
2. Check lockout and password state: `Get-ADUser jsmith -Properties LockedOut, PasswordExpired, PasswordLastSet`. Expected: status shown. Faster than ADUC for a quick check.
3. List group memberships: `Get-ADPrincipalGroupMembership jsmith | Select Name`. Expected: groups listed. The first step of every access question.
4. Unlock an account: `Unlock-ADAccount -Identity jsmith`. Expected: unlocked. Pair with finding the lockout source.
5. Test connectivity: `Test-Connection hostname -Count 2` and `Test-NetConnection hostname -Port 443`. Expected: results. Faster than walking to the machine.
6. Check a service remotely: `Get-Service -ComputerName PC01 -Name spooler`. Expected: status. Restart with `Restart-Service` via Invoke-Command when needed.
7. Force Group Policy: `Invoke-Command -ComputerName PC01 { gpupdate /force }`. Expected: policy applied. The remote fix for "policy not applying".
8. Find stale computers: `Search-ADAccount -ComputersOnly -AccountInactive -TimeSpan 90`. Expected: list. Quarterly cleanup fuel.
9. Check disk space remotely: `Get-CimInstance Win32_LogicalDisk -ComputerName PC01`. Expected: free space shown. "My computer is slow" triage.
10. Keep a cheat sheet of these in the KB; practice on a test OU first. Expected: team fluent.

## When to use
- Daily AD and Windows troubleshooting
- Training new helpdesk agents

## When not to use
- Complex automation (write real scripts)
- Non-Windows environments

## Compatibility
- Windows PowerShell 5.1+ / PowerShell 7; ActiveDirectory module; appropriate delegated rights

## Variants
### No AD module on the workstation
Install RSAT or use implicit remoting to a management server.
### Least-privilege delegation
Agents need only the specific AD rights for these cmdlets, not Domain Admin.

## Why it happens
The GUI is slow and unscriptable. Ten cmdlets replace hundreds of clicks and make the answers pasteable into tickets.

## Edge cases
- Test destructive cmdlets (unlock, restart) in a lab first.
- Log who runs what; AD changes should be attributable.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst__ZAPcO5O5GENAWgiHUGnEw
