1. Active Directory Components
Forests – One or more domain trees, with each tree having its own unique name
space.
Domain trees – One or more domains with contiguous name space.
Domains – A logical unit of computers and network resources that defines a
security boundary.
Organization Units (OUs): A container that represents a logical grouping of
resources
2. What Is a Directory Service?
A directory service that uses the “tree” concept for managing resources on a Windows
network.
Stores information about the network resources and services, such as user data, printer,
servers, databases, groups, computers, and security policies.
Identifies all resources on a network and makes them accessible to users and applications.
A service that helps track and locate objects on a network
Active Directory Management
Users
Services
Workstations Files
3. What are we Authenticating?
Authentication of a person
Others know you by your appearance or voice
By your picture on an identification badge
Other information you have or know
Authentication of a computer
Computer authenticating another computer
Print spooler authenticating a printer, etc.
Person using a public workstation
Workstation will (should) not store authentication information for every user.
Person needs to remember the authentication information
3
7. Domain Controllers
Server that stores the Active Directory database
and authenticates users with the network during
logon.
Stores database information in a file called
ntds.dit.
Active Directory is a multimaster database.
Information is automatically replicated between
multiple domain controllers.
Windows Server
DC
DC
DC