SlideShare a Scribd company logo
Active Directory Domain Services
(AD DS)
Active Directory
• Active Directory (AD) is a directory service that
runs on Microsoft Windows Server. The main
function of Active Directory is to enable
administrators to manage permissions and
control access to network resources. In Active
Directory, data is stored as objects, which
include users, groups, applications, and
devices, and these objects are categorized
according to their name and attributes.
Active Directory Domain Services
• Active Directory Domain Services (AD DS) are
a core component of Active Directory and
provide the primary mechanism for
authenticating users and determining which
network resources they can access. AD DS also
provides additional features such as Single
Sign-On (SSO), security certificates, LDAP, and
access rights management.
Schema
• A set of rules that defines the classes of
objects and attributes that can be contained in
the directory.
– e.g. the fact that AD has user objects that include
a user name and password is because the schema
defines the user object class that, the two
attributes, and the association between the object
class and attributes.
Policy-based administration
• Provides a single point at which to configure
settings that are then deployed to multiple
systems.
• Such policies include;
– Group policy
– Audit policies
– Fine-grained password policies
Replication Services
• Distribute directory data across a network
– This includes both the data store itself as well as
data required to implement policies and
configuration, including logon scripts.
Global Catalog
• Enables you to query AD and locate objects in
the data store.
• Contains information about every object in
the directory.
• Can be used by programmatic interfaces such
as Active Directory Services Interface (ADSI)
and Lightweight Directory Access Protocol
(LDAP).
Components/Objects of an AD
Infrastructure
• Activity Directory data store
• Domain controller
• Domain
• Forest
• Tree
• Functional level
• Organizational unit (OU)
• Sites
Active Directory Data Store
• AD DS stores its identities in the directory – a
data store on domain controllers
• The directory is a single file named Ntds.dit
• that is located in the %SystemRoot%Ntds
folder on a domain controller
• The database is divided into several partitions,
including the schema, configuration, global
catalog, and the domain naming context.
Domain Controller (DC)
• The DCs are servers that perform the AD DC
role.
• The DCs also run the Kerberos Key Distribution
Center (KDC) service.
Domain
• Requires one or more DCs
• DCs replicate the domain’s partition of the
data store so that any DC can authenticate any
identity in the domain.
• Is a scope of administrative policies such as
password complexity and account lockout
policies.
Forest
• A collection of one or more AD domains.
• The first domain installed in a forest is called the
forest root domain.
• A forest contains a single definition of network
configuration and a single instance of the
directory schema.
• A forest is a single instance of the directory – no
data is replicated by AD outside the boundaries
of the forest.
• A forest defies a security boundary.
Tree
• The DNS namespace of domains in a forest
creates trees within the forest.
• If a domain is a subdomain of another
domain, the two domains are considered a
tree.
• The domains must constitute a contiguous
portion of the DNS namespace.
• Trees are the result of the DNS names chosen
for the domains in a forest.
Functional Level
• The functionality available in an AD domain or
forest depends on its functional level.
• The three domain functional levels are:
– Windows 2000 native
– Windows Server 2003
– Windows Server 2008
• The functional level determines the versions
of Windows permitted on domain controllers.
Organization Units (OU)
• OUs provide a container for objects, and
provide a scope with which to manage objects.
• OUs can have Group Policy Objects (GPOs)
linked to them.
• GPOs can contain configuration settings that
will then be applied automatically by users or
computers in an OU.
Sites
• An AD site is an object that represents a portion of the
enterprise within which network connectivity is good.
• A site creates a boundary of replication and service
usage.
• DCs within a site replicate changes within seconds.
• Changes are replicated between sites on a controlled
basis with the assumption that intersite connections
are slow, expensive, or unreliable compared to the
connections within a site.
• Clients will prefer to use distributed services provided
by servers in their site or in the closest site.

More Related Content

What's hot

AD & LDAP
AD & LDAPAD & LDAP
Microsoft Active Directory
Microsoft Active DirectoryMicrosoft Active Directory
Microsoft Active Directorythebigredhemi
 
Active Directory Domain Services.pptx
Active Directory Domain Services.pptxActive Directory Domain Services.pptx
Active Directory Domain Services.pptx
syedasadraza13
 
Active Directory
Active DirectoryActive Directory
Active Directory
Small World Group L.L.C
 
Active directory architecture
Active directory architectureActive directory architecture
Active directory architecture
rahuldaredia21
 
Active Directory
Active Directory Active Directory
Active Directory
Sandeep Kapadane
 
Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02
gameaxt
 
Active directory domain service
Active directory domain serviceActive directory domain service
Active directory domain service
Festus Oriaku
 
Active Directory Training
Active Directory TrainingActive Directory Training
Active Directory Training
Nishad Sukumaran
 
Ldap introduction (eng)
Ldap introduction (eng)Ldap introduction (eng)
Ldap introduction (eng)
Anatoliy Okhotnikov
 
Active Directory Services
Active Directory ServicesActive Directory Services
Active Directory ServicesVarun Arora
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptx
MeriemBalhaddad
 
Windows Server 2016 Webinar
Windows Server 2016 WebinarWindows Server 2016 Webinar
Windows Server 2016 Webinar
Men and Mice
 
Active directory and application
Active directory and applicationActive directory and application
Active directory and application
aminpathan11
 
LDAP
LDAPLDAP
The Ldap Protocol
The Ldap ProtocolThe Ldap Protocol
The Ldap Protocol
Glen Plantz
 
Windows Server 2012 Managing Active Directory Domain
Windows Server 2012 Managing  Active Directory DomainWindows Server 2012 Managing  Active Directory Domain
Windows Server 2012 Managing Active Directory Domain
Napoleon NV
 
Active directory domain services
Active directory domain servicesActive directory domain services
Active directory domain services
IGZ Software house
 
LDAP - Lightweight Directory Access Protocol
LDAP - Lightweight Directory Access ProtocolLDAP - Lightweight Directory Access Protocol
LDAP - Lightweight Directory Access Protocol
S. Hasnain Raza
 
Active directory ii
Active directory   iiActive directory   ii
Active directory iideshvikas
 

What's hot (20)

AD & LDAP
AD & LDAPAD & LDAP
AD & LDAP
 
Microsoft Active Directory
Microsoft Active DirectoryMicrosoft Active Directory
Microsoft Active Directory
 
Active Directory Domain Services.pptx
Active Directory Domain Services.pptxActive Directory Domain Services.pptx
Active Directory Domain Services.pptx
 
Active Directory
Active DirectoryActive Directory
Active Directory
 
Active directory architecture
Active directory architectureActive directory architecture
Active directory architecture
 
Active Directory
Active Directory Active Directory
Active Directory
 
Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02
 
Active directory domain service
Active directory domain serviceActive directory domain service
Active directory domain service
 
Active Directory Training
Active Directory TrainingActive Directory Training
Active Directory Training
 
Ldap introduction (eng)
Ldap introduction (eng)Ldap introduction (eng)
Ldap introduction (eng)
 
Active Directory Services
Active Directory ServicesActive Directory Services
Active Directory Services
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptx
 
Windows Server 2016 Webinar
Windows Server 2016 WebinarWindows Server 2016 Webinar
Windows Server 2016 Webinar
 
Active directory and application
Active directory and applicationActive directory and application
Active directory and application
 
LDAP
LDAPLDAP
LDAP
 
The Ldap Protocol
The Ldap ProtocolThe Ldap Protocol
The Ldap Protocol
 
Windows Server 2012 Managing Active Directory Domain
Windows Server 2012 Managing  Active Directory DomainWindows Server 2012 Managing  Active Directory Domain
Windows Server 2012 Managing Active Directory Domain
 
Active directory domain services
Active directory domain servicesActive directory domain services
Active directory domain services
 
LDAP - Lightweight Directory Access Protocol
LDAP - Lightweight Directory Access ProtocolLDAP - Lightweight Directory Access Protocol
LDAP - Lightweight Directory Access Protocol
 
Active directory ii
Active directory   iiActive directory   ii
Active directory ii
 

Similar to Active-Directory-Domain-Services.pptx

Introduction to System and network administrations
Introduction to System and network administrationsIntroduction to System and network administrations
Introduction to System and network administrations
girmayou1
 
ADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side serverADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side server
BilalMehmood44
 
Final domain control policy
Final domain control policy  Final domain control policy
Final domain control policy
BhagyashriJadhav16
 
09 - Active Directory.ppt
09 - Active Directory.ppt09 - Active Directory.ppt
09 - Active Directory.ppt
ssuserf7cd2b
 
Win2KServer Active Directory
Win2KServer Active DirectoryWin2KServer Active Directory
Win2KServer Active Directory
Phil Ashman
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
Shekhar Singh
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questions
subhashmr
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questions
Umesh Sawant
 
Security and LDAP integration in InduSoft Web Studio
Security and LDAP integration in InduSoft Web StudioSecurity and LDAP integration in InduSoft Web Studio
Security and LDAP integration in InduSoft Web Studio
AVEVA
 
Active Directoryptx sunday.pptx
Active Directoryptx sunday.pptxActive Directoryptx sunday.pptx
Active Directoryptx sunday.pptx
UtPearls
 
Directory Services Nma Unit-1
Directory Services Nma Unit-1Directory Services Nma Unit-1
Directory Services Nma Unit-1
GPAPassedStudents
 
Lecture 11 active directory
Lecture 11 active directoryLecture 11 active directory
Lecture 11 active directory
Tanveer Malik
 
Directory services by SAJID
Directory services by SAJIDDirectory services by SAJID
Directory services by SAJID
Sajid khan
 
Active Directory Ii
Active Directory   IiActive Directory   Ii
Active Directory Iideshvikas
 

Similar to Active-Directory-Domain-Services.pptx (20)

Introduction to System and network administrations
Introduction to System and network administrationsIntroduction to System and network administrations
Introduction to System and network administrations
 
ADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side serverADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side server
 
Active directoryfinal
Active directoryfinalActive directoryfinal
Active directoryfinal
 
Final domain control policy
Final domain control policy  Final domain control policy
Final domain control policy
 
70 640 Lesson01 Ppt 041009
70 640 Lesson01 Ppt 04100970 640 Lesson01 Ppt 041009
70 640 Lesson01 Ppt 041009
 
Active directory
Active directoryActive directory
Active directory
 
09 - Active Directory.ppt
09 - Active Directory.ppt09 - Active Directory.ppt
09 - Active Directory.ppt
 
Win2KServer Active Directory
Win2KServer Active DirectoryWin2KServer Active Directory
Win2KServer Active Directory
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questions
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questions
 
Security and LDAP integration in InduSoft Web Studio
Security and LDAP integration in InduSoft Web StudioSecurity and LDAP integration in InduSoft Web Studio
Security and LDAP integration in InduSoft Web Studio
 
Active Directoryptx sunday.pptx
Active Directoryptx sunday.pptxActive Directoryptx sunday.pptx
Active Directoryptx sunday.pptx
 
6425 c 01
6425 c 016425 c 01
6425 c 01
 
Directory Services Nma Unit-1
Directory Services Nma Unit-1Directory Services Nma Unit-1
Directory Services Nma Unit-1
 
Lecture 11 active directory
Lecture 11 active directoryLecture 11 active directory
Lecture 11 active directory
 
Directory services by SAJID
Directory services by SAJIDDirectory services by SAJID
Directory services by SAJID
 
Mcts chapter 3
Mcts chapter 3Mcts chapter 3
Mcts chapter 3
 
Active Directory Ii
Active Directory   IiActive Directory   Ii
Active Directory Ii
 
04232015094601
0423201509460104232015094601
04232015094601
 

Recently uploaded

Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Globus
 
May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
Adele Miller
 
BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
Ortus Solutions, Corp
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
Globus
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke
 
Enhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdfEnhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdf
Globus
 
APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)
Boni García
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
Paco van Beckhoven
 
Graspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code AnalysisGraspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code Analysis
Aftab Hussain
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Globus
 
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Crescat
 
First Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User EndpointsFirst Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User Endpoints
Globus
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
rickgrimesss22
 
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of CodeA Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
Aftab Hussain
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
abdulrafaychaudhry
 
Prosigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology SolutionsProsigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology Solutions
Prosigns
 
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdfVitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
abdulrafaychaudhry
 
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
takuyayamamoto1800
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
Globus
 

Recently uploaded (20)

Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
 
May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
 
BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
 
Enhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdfEnhancing Research Orchestration Capabilities at ORNL.pdf
Enhancing Research Orchestration Capabilities at ORNL.pdf
 
APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)APIs for Browser Automation (MoT Meetup 2024)
APIs for Browser Automation (MoT Meetup 2024)
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
 
Graspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code AnalysisGraspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code Analysis
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
 
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
 
First Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User EndpointsFirst Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User Endpoints
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
 
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of CodeA Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
 
Prosigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology SolutionsProsigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology Solutions
 
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdfVitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdf
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
 
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
 

Active-Directory-Domain-Services.pptx

  • 1. Active Directory Domain Services (AD DS)
  • 2. Active Directory • Active Directory (AD) is a directory service that runs on Microsoft Windows Server. The main function of Active Directory is to enable administrators to manage permissions and control access to network resources. In Active Directory, data is stored as objects, which include users, groups, applications, and devices, and these objects are categorized according to their name and attributes.
  • 3. Active Directory Domain Services • Active Directory Domain Services (AD DS) are a core component of Active Directory and provide the primary mechanism for authenticating users and determining which network resources they can access. AD DS also provides additional features such as Single Sign-On (SSO), security certificates, LDAP, and access rights management.
  • 4. Schema • A set of rules that defines the classes of objects and attributes that can be contained in the directory. – e.g. the fact that AD has user objects that include a user name and password is because the schema defines the user object class that, the two attributes, and the association between the object class and attributes.
  • 5. Policy-based administration • Provides a single point at which to configure settings that are then deployed to multiple systems. • Such policies include; – Group policy – Audit policies – Fine-grained password policies
  • 6. Replication Services • Distribute directory data across a network – This includes both the data store itself as well as data required to implement policies and configuration, including logon scripts.
  • 7. Global Catalog • Enables you to query AD and locate objects in the data store. • Contains information about every object in the directory. • Can be used by programmatic interfaces such as Active Directory Services Interface (ADSI) and Lightweight Directory Access Protocol (LDAP).
  • 8. Components/Objects of an AD Infrastructure • Activity Directory data store • Domain controller • Domain • Forest • Tree • Functional level • Organizational unit (OU) • Sites
  • 9. Active Directory Data Store • AD DS stores its identities in the directory – a data store on domain controllers • The directory is a single file named Ntds.dit • that is located in the %SystemRoot%Ntds folder on a domain controller • The database is divided into several partitions, including the schema, configuration, global catalog, and the domain naming context.
  • 10. Domain Controller (DC) • The DCs are servers that perform the AD DC role. • The DCs also run the Kerberos Key Distribution Center (KDC) service.
  • 11. Domain • Requires one or more DCs • DCs replicate the domain’s partition of the data store so that any DC can authenticate any identity in the domain. • Is a scope of administrative policies such as password complexity and account lockout policies.
  • 12. Forest • A collection of one or more AD domains. • The first domain installed in a forest is called the forest root domain. • A forest contains a single definition of network configuration and a single instance of the directory schema. • A forest is a single instance of the directory – no data is replicated by AD outside the boundaries of the forest. • A forest defies a security boundary.
  • 13. Tree • The DNS namespace of domains in a forest creates trees within the forest. • If a domain is a subdomain of another domain, the two domains are considered a tree. • The domains must constitute a contiguous portion of the DNS namespace. • Trees are the result of the DNS names chosen for the domains in a forest.
  • 14. Functional Level • The functionality available in an AD domain or forest depends on its functional level. • The three domain functional levels are: – Windows 2000 native – Windows Server 2003 – Windows Server 2008 • The functional level determines the versions of Windows permitted on domain controllers.
  • 15. Organization Units (OU) • OUs provide a container for objects, and provide a scope with which to manage objects. • OUs can have Group Policy Objects (GPOs) linked to them. • GPOs can contain configuration settings that will then be applied automatically by users or computers in an OU.
  • 16. Sites • An AD site is an object that represents a portion of the enterprise within which network connectivity is good. • A site creates a boundary of replication and service usage. • DCs within a site replicate changes within seconds. • Changes are replicated between sites on a controlled basis with the assumption that intersite connections are slow, expensive, or unreliable compared to the connections within a site. • Clients will prefer to use distributed services provided by servers in their site or in the closest site.