What Active Directory is and who uses it
Active Directory is a directory service that most organizations use to manage user accounts, computers, and permissions across a network. If you work at a company with more than a handful of employees, your login credentials, email access, file permissions, and printer settings are probably stored in Active Directory rather than on your individual computer.
Active Directory runs on servers that your IT department maintains. You do not install it yourself or "turn it on"—it works in the background when you log into your work computer with your username and password. The system checks your credentials against Active Directory's database and grants you access to the resources your role is supposed to have.
Understanding how to work with Active Directory matters because it affects what you can see on the network, what printers you can use, what shared folders you can open, and whether you can install software. If something on your work computer is not working the way it should, Active Directory is often involved.
Key Takeaways
- Active Directory is managed by your IT department, not by you—you access it by logging into your work computer with your network username and password.
- Your user account, group memberships, and permissions all live in Active Directory, which controls what files, printers, and applications you can reach.
- You can see some of your own Active Directory information by opening Active Directory Users and Computers on a domain-connected computer, but you cannot change it yourself.
- If you need to change your password, reset your account, or request access to a resource, you contact your IT department or help desk—they make the changes in Active Directory.
- On a personal computer or a computer not connected to your organization's network, Active Directory does not apply.
Checking your Active Directory account information
If your computer is connected to your organization's network and you have the right permissions, you can view some of your own Active Directory information. On a Windows computer, open the Start menu, type Active Directory Users and Computers, and press Enter. (On some systems, this tool may not be installed or may not open—if that happens, your IT department has restricted access, which is normal.)
Once the window opens, look in the left panel for your domain name—it usually looks like "company.com" or "corp.local". Click the arrow next to it to expand the folder tree. Navigate to the organizational unit (OU) where your user account is stored; your IT department can tell you which one if you cannot find it. When you locate your username, right-click it and select Properties. This shows you information like your full name, email address, phone number, office location, and group memberships—all the details Active Directory has about you.
You can look at this information, but you cannot change it from this window. If any of it is wrong—your phone number, office location, or job title—you need to contact your IT department or help desk to request the update.
Resetting your password through Active Directory
Most organizations let you change your own Active Directory password without contacting IT. On a Windows computer connected to your network, press Ctrl + Alt + Delete, then select Change a password. A window will open asking for your old password and your new password. Type your current password, then type your new password twice (once to enter it, once to confirm it matches). Click OK.
If the password change succeeds, you will see a message saying the password was changed. If it fails, the error message usually tells you why—for example, your new password might not meet your organization's complexity requirements (a certain number of capital letters, numbers, or special characters). Your IT department's password policy determines what counts as valid.
If you have forgotten your password entirely and cannot log in, you cannot reset it yourself. You will need to contact your IT help desk from another device or in person. They can reset your password and send you a temporary one, or they can unlock your account so you can set a new password at your next login.
Requesting access to files and shared folders
Active Directory controls who can open shared network folders and files. If you try to open a folder and get an "Access Denied" message, it means your user account does not have permission in Active Directory. You cannot grant yourself permission—you have to ask the folder owner or your IT department.
Before you contact IT, find out who owns the shared folder. Right-click the folder, select Properties, then go to the Security tab. Look at the list of names under "Group or user names"—one of them is usually the owner. You can also ask your manager or a colleague who has access to the folder. Once you know who owns it, send them a message explaining what folder you need and why. They can add your account to the permission list in Active Directory, and you will have access the next time you try to open it (sometimes after logging out and back in).
If you do not know who owns the folder or the owner does not respond, contact your IT help desk. They can look up the owner in Active Directory or grant you temporary access while the ownership question gets sorted out.
Printer and network resource access
When you try to print to a network printer and it does not work, Active Directory permissions are often the cause. Your IT department adds your user account to printer groups in Active Directory, which determines which printers show up in your print menu and which ones you can actually use.
If a printer your colleagues use does not appear in your printer list, or if you can see it but get an error when you try to print, contact your IT help desk. Tell them the printer name and location. They can check whether your account is in the printer group and add you if needed. The same process applies to other network resources like VPN access, database connections, or specialized software—your IT department manages all of these through Active Directory group memberships.
What happens when you leave the organization
When you leave a job, your IT department disables your Active Directory account. This does not delete it—the account stays in the system for record-keeping and legal reasons—but it becomes inactive. Your login stops working, your email access closes, and you lose access to all shared folders and network resources.
If you are leaving a job, your IT department usually handles this on your last day or shortly after. If you are a manager and need to offboard someone, contact your IT help desk to request account deactivation. Do not try to delete the account yourself—IT needs to follow your organization's data retention and security policies.
Active Directory on personal and non-domain computers
Active Directory only works on computers that are connected to your organization's network domain. If you use a personal computer, a home laptop, or a computer that your IT department has not added to the domain, Active Directory does not apply. You log in with a local account instead, and you cannot access network resources that require Active Directory permissions.
If you work remotely and need to reach network resources, your organization usually provides a VPN (virtual private network) connection. The VPN lets your personal computer connect to the organization's network as if it were in the office, and then Active Directory permissions apply. Your IT department sets up the VPN and provides instructions for connecting.
Frequently Asked Questions
Can I change my own Active Directory password?
Yes, on a domain-connected computer. Press Ctrl + Alt + Delete, select Change a password, and enter your old password and new password. If you have forgotten your password, you cannot reset it yourself—contact your IT help desk.
Why can't I see a shared folder that my coworker can access?
Your user account does not have permission in Active Directory. Ask the folder owner to add your account to the permission list, or contact your IT help desk. Once they make the change, you may need to log out and back in before you can access it.
What should I do if I get an "Access Denied" error on a network printer?
Your account is not in the printer group in Active Directory. Contact your IT help desk with the printer name and location, and they can add you. The printer should appear in your print menu within a few minutes.
Does Active Directory work on my personal computer?
No, unless your IT department has added it to your organization's domain, which is rare for personal devices. If you work remotely, use a VPN to connect to your organization's network, and then Active Directory permissions apply.
What happens to my Active Directory account when I leave my job?
Your IT department disables it, which closes your email and network access. The account stays in the system for record-keeping but cannot be used to log in or access resources.