SlideShare a Scribd company logo
Active Directory Domain Services
(AD DS)
Active Directory
‱ Active Directory (AD) is a directory service that
runs on Microsoft Windows Server. The main
function of Active Directory is to enable
administrators to manage permissions and
control access to network resources. In Active
Directory, data is stored as objects, which
include users, groups, applications, and
devices, and these objects are categorized
according to their name and attributes.
Active Directory Domain Services
‱ Active Directory Domain Services (AD DS) are
a core component of Active Directory and
provide the primary mechanism for
authenticating users and determining which
network resources they can access. AD DS also
provides additional features such as Single
Sign-On (SSO), security certificates, LDAP, and
access rights management.
Schema
‱ A set of rules that defines the classes of
objects and attributes that can be contained in
the directory.
– e.g. the fact that AD has user objects that include
a user name and password is because the schema
defines the user object class that, the two
attributes, and the association between the object
class and attributes.
Policy-based administration
‱ Provides a single point at which to configure
settings that are then deployed to multiple
systems.
‱ Such policies include;
– Group policy
– Audit policies
– Fine-grained password policies
Replication Services
‱ Distribute directory data across a network
– This includes both the data store itself as well as
data required to implement policies and
configuration, including logon scripts.
Global Catalog
‱ Enables you to query AD and locate objects in
the data store.
‱ Contains information about every object in
the directory.
‱ Can be used by programmatic interfaces such
as Active Directory Services Interface (ADSI)
and Lightweight Directory Access Protocol
(LDAP).
Components/Objects of an AD
Infrastructure
‱ Activity Directory data store
‱ Domain controller
‱ Domain
‱ Forest
‱ Tree
‱ Functional level
‱ Organizational unit (OU)
‱ Sites
Active Directory Data Store
‱ AD DS stores its identities in the directory – a
data store on domain controllers
‱ The directory is a single file named Ntds.dit
‱ that is located in the %SystemRoot%Ntds
folder on a domain controller
‱ The database is divided into several partitions,
including the schema, configuration, global
catalog, and the domain naming context.
Domain Controller (DC)
‱ The DCs are servers that perform the AD DC
role.
‱ The DCs also run the Kerberos Key Distribution
Center (KDC) service.
Domain
‱ Requires one or more DCs
‱ DCs replicate the domain’s partition of the
data store so that any DC can authenticate any
identity in the domain.
‱ Is a scope of administrative policies such as
password complexity and account lockout
policies.
Forest
‱ A collection of one or more AD domains.
‱ The first domain installed in a forest is called the
forest root domain.
‱ A forest contains a single definition of network
configuration and a single instance of the
directory schema.
‱ A forest is a single instance of the directory – no
data is replicated by AD outside the boundaries
of the forest.
‱ A forest defies a security boundary.
Tree
‱ The DNS namespace of domains in a forest
creates trees within the forest.
‱ If a domain is a subdomain of another
domain, the two domains are considered a
tree.
‱ The domains must constitute a contiguous
portion of the DNS namespace.
‱ Trees are the result of the DNS names chosen
for the domains in a forest.
Functional Level
‱ The functionality available in an AD domain or
forest depends on its functional level.
‱ The three domain functional levels are:
– Windows 2000 native
– Windows Server 2003
– Windows Server 2008
‱ The functional level determines the versions
of Windows permitted on domain controllers.
Organization Units (OU)
‱ OUs provide a container for objects, and
provide a scope with which to manage objects.
‱ OUs can have Group Policy Objects (GPOs)
linked to them.
‱ GPOs can contain configuration settings that
will then be applied automatically by users or
computers in an OU.
Sites
‱ An AD site is an object that represents a portion of the
enterprise within which network connectivity is good.
‱ A site creates a boundary of replication and service
usage.
‱ DCs within a site replicate changes within seconds.
‱ Changes are replicated between sites on a controlled
basis with the assumption that intersite connections
are slow, expensive, or unreliable compared to the
connections within a site.
‱ Clients will prefer to use distributed services provided
by servers in their site or in the closest site.

More Related Content

PPTX
Microsoft Active Directory.pptx
PPTX
02-Active Directory Domain Services.pptx
PPT
Active directory slides
PPT
ACTIVE-DIRECTORY.ppt
 
PPT
Active directory and application
PPT
active-directory-domain-services
 
PPTX
Dhcp server configuration
PPT
Active Directory Training
Microsoft Active Directory.pptx
02-Active Directory Domain Services.pptx
Active directory slides
ACTIVE-DIRECTORY.ppt
 
Active directory and application
active-directory-domain-services
 
Dhcp server configuration
Active Directory Training

What's hot (20)

PPTX
Understanding the Windows Server Administration Fundamentals (Part-1)
PPTX
Domain Controller.pptx
PPT
Microsoft Active Directory
PPTX
Active Directory
PPT
PPTX
What is active directory
PPTX
Presentation On Group Policy in Windows Server 2012 R2 By Barek-IT
PPT
Active Directory Services
PPT
Active Directory
PPT
Active directory
 
PPT
Chapter03 Creating And Managing User Accounts
PPTX
Active Directory Domain Services.pptx
PPTX
Microsoft Offical Course 20410C_02
PPTX
Virtualization Explained | What Is Virtualization Technology? | Virtualizatio...
PPTX
MCSA 70-412 Chapter 05
PPTX
Active directory domain service
PPT
Active directory
PPTX
External collaboration with Azure B2B
PDF
Intro to DNS
PPTX
Dns 2
Understanding the Windows Server Administration Fundamentals (Part-1)
Domain Controller.pptx
Microsoft Active Directory
Active Directory
What is active directory
Presentation On Group Policy in Windows Server 2012 R2 By Barek-IT
Active Directory Services
Active Directory
Active directory
 
Chapter03 Creating And Managing User Accounts
Active Directory Domain Services.pptx
Microsoft Offical Course 20410C_02
Virtualization Explained | What Is Virtualization Technology? | Virtualizatio...
MCSA 70-412 Chapter 05
Active directory domain service
Active directory
External collaboration with Azure B2B
Intro to DNS
Dns 2
Ad

Similar to Active-Directory-Domain-Services.pptx (20)

PPTX
Active-Directory-Domain-Services.pptx
PPT
70 640 Lesson01 Ppt 041009
PPTX
Active Directory Domain Services Presentation
PPTX
Activedirecotryfundamentals
PPT
Active diirecotry
PPT
Active directory installation windows 2003 1
PPTX
active directory.pptx
PPTX
ADDS (Active directory Domain Service) in side server
PPTX
Active Directory component
PPT
Mcts chapter 3
PPTX
Active Directory for Auditors
PPT
ACTIVE-DIRECTORY in system and network .ppt
PPT
Active directoryfinal
PPT
ACTIVE-DIRECTORY.ppt
PPT
09 - Active Directory.ppt
PPT
ACTIVE-DIRECTORY and m365 hybrid identity.ppt
PPT
Active Directory I
PDF
Introduction to System and network administrations
PDF
Active Directory
PDF
Final domain control policy
Active-Directory-Domain-Services.pptx
70 640 Lesson01 Ppt 041009
Active Directory Domain Services Presentation
Activedirecotryfundamentals
Active diirecotry
Active directory installation windows 2003 1
active directory.pptx
ADDS (Active directory Domain Service) in side server
Active Directory component
Mcts chapter 3
Active Directory for Auditors
ACTIVE-DIRECTORY in system and network .ppt
Active directoryfinal
ACTIVE-DIRECTORY.ppt
09 - Active Directory.ppt
ACTIVE-DIRECTORY and m365 hybrid identity.ppt
Active Directory I
Introduction to System and network administrations
Active Directory
Final domain control policy
Ad

Recently uploaded (20)

PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PDF
System and Network Administration Chapter 2
PDF
Digital Strategies for Manufacturing Companies
PPTX
history of c programming in notes for students .pptx
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PPTX
Transform Your Business with a Software ERP System
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PPTX
ai tools demonstartion for schools and inter college
PPTX
Online Work Permit System for Fast Permit Processing
PPTX
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
PDF
AI in Product Development-omnex systems
PPT
Introduction Database Management System for Course Database
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
How Creative Agencies Leverage Project Management Software.pdf
PDF
Understanding Forklifts - TECH EHS Solution
Adobe Illustrator 28.6 Crack My Vision of Vector Design
System and Network Administration Chapter 2
Digital Strategies for Manufacturing Companies
history of c programming in notes for students .pptx
Odoo POS Development Services by CandidRoot Solutions
Design an Analysis of Algorithms I-SECS-1021-03
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Which alternative to Crystal Reports is best for small or large businesses.pdf
Transform Your Business with a Software ERP System
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
ai tools demonstartion for schools and inter college
Online Work Permit System for Fast Permit Processing
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
AI in Product Development-omnex systems
Introduction Database Management System for Course Database
2025 Textile ERP Trends: SAP, Odoo & Oracle
How to Migrate SBCGlobal Email to Yahoo Easily
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
How Creative Agencies Leverage Project Management Software.pdf
Understanding Forklifts - TECH EHS Solution

Active-Directory-Domain-Services.pptx

  • 1. Active Directory Domain Services (AD DS)
  • 2. Active Directory ‱ Active Directory (AD) is a directory service that runs on Microsoft Windows Server. The main function of Active Directory is to enable administrators to manage permissions and control access to network resources. In Active Directory, data is stored as objects, which include users, groups, applications, and devices, and these objects are categorized according to their name and attributes.
  • 3. Active Directory Domain Services ‱ Active Directory Domain Services (AD DS) are a core component of Active Directory and provide the primary mechanism for authenticating users and determining which network resources they can access. AD DS also provides additional features such as Single Sign-On (SSO), security certificates, LDAP, and access rights management.
  • 4. Schema ‱ A set of rules that defines the classes of objects and attributes that can be contained in the directory. – e.g. the fact that AD has user objects that include a user name and password is because the schema defines the user object class that, the two attributes, and the association between the object class and attributes.
  • 5. Policy-based administration ‱ Provides a single point at which to configure settings that are then deployed to multiple systems. ‱ Such policies include; – Group policy – Audit policies – Fine-grained password policies
  • 6. Replication Services ‱ Distribute directory data across a network – This includes both the data store itself as well as data required to implement policies and configuration, including logon scripts.
  • 7. Global Catalog ‱ Enables you to query AD and locate objects in the data store. ‱ Contains information about every object in the directory. ‱ Can be used by programmatic interfaces such as Active Directory Services Interface (ADSI) and Lightweight Directory Access Protocol (LDAP).
  • 8. Components/Objects of an AD Infrastructure ‱ Activity Directory data store ‱ Domain controller ‱ Domain ‱ Forest ‱ Tree ‱ Functional level ‱ Organizational unit (OU) ‱ Sites
  • 9. Active Directory Data Store ‱ AD DS stores its identities in the directory – a data store on domain controllers ‱ The directory is a single file named Ntds.dit ‱ that is located in the %SystemRoot%Ntds folder on a domain controller ‱ The database is divided into several partitions, including the schema, configuration, global catalog, and the domain naming context.
  • 10. Domain Controller (DC) ‱ The DCs are servers that perform the AD DC role. ‱ The DCs also run the Kerberos Key Distribution Center (KDC) service.
  • 11. Domain ‱ Requires one or more DCs ‱ DCs replicate the domain’s partition of the data store so that any DC can authenticate any identity in the domain. ‱ Is a scope of administrative policies such as password complexity and account lockout policies.
  • 12. Forest ‱ A collection of one or more AD domains. ‱ The first domain installed in a forest is called the forest root domain. ‱ A forest contains a single definition of network configuration and a single instance of the directory schema. ‱ A forest is a single instance of the directory – no data is replicated by AD outside the boundaries of the forest. ‱ A forest defies a security boundary.
  • 13. Tree ‱ The DNS namespace of domains in a forest creates trees within the forest. ‱ If a domain is a subdomain of another domain, the two domains are considered a tree. ‱ The domains must constitute a contiguous portion of the DNS namespace. ‱ Trees are the result of the DNS names chosen for the domains in a forest.
  • 14. Functional Level ‱ The functionality available in an AD domain or forest depends on its functional level. ‱ The three domain functional levels are: – Windows 2000 native – Windows Server 2003 – Windows Server 2008 ‱ The functional level determines the versions of Windows permitted on domain controllers.
  • 15. Organization Units (OU) ‱ OUs provide a container for objects, and provide a scope with which to manage objects. ‱ OUs can have Group Policy Objects (GPOs) linked to them. ‱ GPOs can contain configuration settings that will then be applied automatically by users or computers in an OU.
  • 16. Sites ‱ An AD site is an object that represents a portion of the enterprise within which network connectivity is good. ‱ A site creates a boundary of replication and service usage. ‱ DCs within a site replicate changes within seconds. ‱ Changes are replicated between sites on a controlled basis with the assumption that intersite connections are slow, expensive, or unreliable compared to the connections within a site. ‱ Clients will prefer to use distributed services provided by servers in their site or in the closest site.