Action below gives people access to Windchill.
How do you control their permissions - add them to one or more Org/Groups, true?
So, management of user accounts requires both Active Directory and Windchill actions. We choose to allow every single user in Active Directory to log on, but they have no access to any data - that comes from membership in one or more Groups in Windchill, requiring action only in Windchill and none in Active Directory.