# Active Directory based Device Management

Hexnode lets you import your Active Directory into it and apply policies straight to the existing **users, groups** or **organizational unit (OUs)**. Active Directory based management scales down the load on admins by directly assigning and enforcing security policies to a set of users or groups within the domain.

### Applying Policy on Active Directory User Groups

Once you have synced your Active Directories with Hexnode, you can apply policies on the existing user groups, organizational units or the entire domain.

Let’s start by creating a policy,

1. Go to **Policies** tab and [create a new policy](https://www.hexnode.com/mobile-device-management/help/how-to-create-modify-delete-or-clone-policies/) with required configurations.
    Any policy of your choice can be configured.
2. Navigate to **Policy Targets > Domains**. Click on **+Add Domain**. You can see your domains listed here. For any domain, click on the arrow next to it to expand. Here, you can select multiple OUs or the entire domain.
3. After selection, click on **OK**.
4. Next, select **User Groups**. Click on **+Add User Group**. You can see all your AD user groups listed in here.
5. Select the desired user groups and click on **OK**.
6. You have now successfully set your AD groups and OUs as policy targets. On clicking **Save**, the policy you have configured will be active on all the target devices you have selected.
[![Associate policy with active directory domain users](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Associate-policy-with-active-directory-domain-users-.png "Associate policy with active directory domain users")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Associate-policy-with-active-directory-domain-users-.png)
[![Active Directory user-device - OUs groups](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Active-Directory-user-device-OUs-groups.png "Active Directory user-device - OUs groups")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Active-Directory-user-device-OUs-groups.png)

### Active Directory based Remote Device Management

Hexnode lets you perform remote actions such as lock device, remote ring, install application, enable/disable kiosk mode, enable/disable lost mode, enable/disable personal hotspot and so on, on the devices linked to your AD groups.

To perform remote device management, navigate to **Manage** tab **> Directory Services.**

[![Active Directory based device management](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Active-Directory-based-device-management.png "Active Directory based device management")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Active-Directory-based-device-management.png)

[![Active Directory domains listed-users-groups on mdm](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Active-Directory-domains-users-groups-listed-on-mdm.png "Active Directory domains-users-groups listed on mdm")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Active-Directory-domains-users-groups-listed-on-mdm.png)

You can see all your AD domains listed here. Click on the arrow adjacent to any domain. It will expand to show the OUs within. Now you can select multiple OUs or the domain as a whole.

Make your selection and click on **Actions**. Here we have multiple options. Clicking on any of them performs the corresponding actions in bulk on the groups, OUs or domains selected.