This document introduces Active Directory Domain Services (AD DS) and discusses key concepts related to identity and access management. It explains that AD DS provides identity and access solutions for enterprises by storing user and system identity information, authenticating identities, and authorizing access to resources. The document outlines the authentication process and how access tokens and security descriptors are used to determine authorization. It positions Active Directory as centralizing the identity store to create a trusted domain model that solves management issues in a workgroup configuration.