Skip to main content
AD Academy
Active Directory Basics
Beginner12 minLast updated: Topic 1 of 2

What is Active Directory?

A general definition and the role of AD in an organizational network.

Not read

What you will learn here

  • What Active Directory is in plain words
  • Which problems it solves in a company
  • Its basic building blocks

(AD) is a Directory Service by Microsoft. It stores information about all objects on the network: users, computers, groups, printers and policies. Using AD, administrators can centrally manage access and permissions in large organizations.

Why do we even need AD?

  • Centralized management of users and computers.
  • Single Sign-On for enterprise applications.
  • Group Policies to configure computers on the network.
  • A hierarchical structure suited for large organizations.
Architecture and Theory — Under the Hood

DS is a distributed database. Each holds a local copy of the NTDS.dit file (default C:\Windows\NTDS), and updates it with other DCs using Multi-Master Replication.

  • Schema — The definition of object types (Classes) and attributes (Attributes). Shared across the entire .
  • Configuration — Topology: Sites, Subnets, Replication Links.
  • — The objects themselves: Users, Computers, Groups.
  • Global Catalog (GC) — A partial (Read-Only) copy of all objects, for quick search and login.
Practical Definition (PowerShell / GUI)
# Check Domain and Forest Status
Get-ADDomain
Get-ADForest
Get-ADDomainController -Filter * | Select Name,Site,IsGlobalCatalog,OperatingSystem

# Object Count
(Get-ADUser -Filter *).Count
(Get-ADComputer -Filter *).Count
powershell
Real-world Scenarios in an Organization
  • Organization with 3 branches: DC in each branch so that login does not go over the WAN line.
  • Company mergers: Separate for each company + Trust between them, instead of immediate merger.
  • RODC in a physically insecure branch — read-only copy without passwords.
Diagnosis and Troubleshooting
dcdiag /v            # General DC diagnosis
repadmin /replsummary  # Replication status
netdom query fsmo      # Who holds the FSMO roles
bash
Glossary and Quick Command Line
  • DN — Distinguished Name, the full address of an object.
  • SID — Unique Security Identifier.
  • GUID — An identifier that never changes, even after transfer between domains.
  • FSMO — 5 unique roles: Schema, Naming, RID, PDC Emulator, Infrastructure.

Check yourself

What does Active Directory store?

Was this page helpful?