Skip to main content
AD Academy

Myths and misconceptions

Things "everyone knows" about Active Directory — and why they are wrong.

MythOne domain controller is enough

RealityA single DC is a single point of failure: no logon, no GPO, no internal DNS when it dies.

What to do: Run at least two DCs per domain, ideally on separate hosts, both running DNS.

MythAn OU is a kind of security group

RealityAn OU is a management container for GPOs. You cannot grant file permissions to an OU.

What to do: Permissions always go through security groups. OUs are for structure, delegation and policy.

MythDisabling is basically deleting

RealityA disabled account keeps its SID, memberships and rights, and an issued Kerberos ticket stays valid up to 10 hours.

What to do: On offboarding: disable, reset the password and kill sessions. Order matters.

Mythgpupdate /force fixes any GPO problem

RealityIt only re-requests policy. If the GPO is filtered, linked wrong, or SYSVOL is unreachable, nothing changes.

What to do: Real diagnosis is gpresult /h plus events 1058/1085 in the System log.

MythYou can set 8.8.8.8 as DNS on domain machines

Reality8.8.8.8 has no idea where your DC is. Without internal SRV records there is no logon and no GPO.

What to do: Clients point at the DC's DNS; internet resolution is handled by forwarders on that server.

MythIt is convenient to log in as Domain Admin everywhere

RealityEvery logon leaves credentials in the machine's memory. One infected PC means an owned domain.

What to do: Tier model: admins work only from a dedicated admin workstation (PAW), never a user PC.

MythChanging passwords every 30 days equals security

RealityFrequent rotation produces Password1! → Password2!. NIST and Microsoft advise long passphrases changed on suspicion.

What to do: Better: a high minimum length, a banned-password list and MFA instead of monthly rotation.

MythA VM snapshot is a DC backup

RealityRestoring a DC snapshot causes a USN rollback — replication breaks silently.

What to do: Use System State backups and a written, rehearsed forest recovery plan.

MythEntra ID is just AD in the cloud

RealityEntra ID is not AD: no OUs, no GPOs, no classic Kerberos, no plain LDAP. It is an OAuth/SAML identity provider.

What to do: In hybrid: devices via Intune, access via Conditional Access, sync via Entra Connect.

MythWe are small, nobody attacks us

RealityMost ransomware is untargeted — it scans the internet for exposed RDP and weak passwords.

What to do: The basics cover most of it: MFA, no internet-facing RDP, offline backups, patching, few admins.