Active Directory is the database of users, computers, groups and permissions that a Windows network runs on, plus the domain controllers that answer questions about it. It confirms who somebody is at sign in, decides what they may reach, and pushes configuration to every machine that has joined the domain.
- Everything inside is an object with attributes
- The forest is the security boundary, not the domain
- Kerberos tickets need clocks within five minutes
- Group membership is fixed at sign in
- Any domain controller holds every credential
On this page
The familyThe family of services under one name
Active Directory is not one service. It is a family, and when somebody says Active Directory they almost always mean the first of these.
Active Directory Domain Services is the directory itself: the database of users, computers and groups, and the authentication that goes with it. Everything else on this page is about Domain Services.
Active Directory Certificate Services issues and manages certificates inside the organization. It is how internal websites, wireless authentication and smart cards get certificates a domain joined machine already trusts. It is also frequently misconfigured in ways that hand an attacker a path to domain administrator, which made it a focus of security research recently.
Active Directory Federation Services lets an external application authenticate users against the internal directory without seeing their password. It was the standard way to connect on premises identity to cloud services, and it is being displaced by the cloud directory doing that job directly.
Active Directory Lightweight Directory Services is a directory for applications that need one, without the domain machinery around it. Uncommon, and worth recognizing in a network diagram.
Active Directory Rights Management Services attaches usage rules to documents so they stay enforced after the file leaves the file share. Rarely deployed, and when it is, it is because a regulator asked.
The practical point: these are separate roles on separate servers, with separate failure modes. A statement like "Active Directory is down" is not specific enough to act on, and asking which of these is meant is usually the fastest first question.
StructureThe structure, from the inside out
The hierarchy has four levels and they are usually explained in the wrong order, from the outside in, which makes them harder to hold on to. From the inside:
An object is one thing in the directory: a user, a computer, a printer, a shared folder, a group. Objects have attributes, the fields describing them, and a unique identifier that never changes even when the name does.
An organizational unit is a container for directory objects. It exists for two administrative reasons and only two: to delegate management of the objects inside it, and to apply policy to them. An organizational unit that does neither is a folder, and folders are how directories become unmanageable.
A domain is one administrative boundary, with one directory database, one set of security policies and one replication group. It is the unit that actually matters. Most organizations need exactly one, and most of the complexity in the wild came from building more than one for reasons that stopped applying years ago.
A forest is the outermost boundary and the one people misplace. It is the security boundary. Domains inside one forest trust each other automatically across the whole forest, which means a compromise in any of them is a problem for all of them.
If two parts of a business must genuinely not reach each other, the split has to be at the forest, not at the domain.
A tree sits between domain and forest, grouping domains that share a contiguous name. It is mostly vocabulary now.
Domain controllers, and what they actually do
A domain controller is a Windows server holding a copy of the Active Directory database and answering three kinds of question: is this user who they say they are, which network resources are they allowed to reach, and what does the directory say about this object.
Every domain controller holds a writable copy, and they replicate changes to each other. Two consequences:
Replication takes time. A password changed on one controller is not instantly known to all of them, which is the cause of the classic complaint that a new password works on one machine and not another. There is an exception for password changes, which are pushed urgently, and it does not cover everything.
Any domain controller is the whole directory. Physical access to one is access to the entire database of every credential in the domain. That is why they belong in locked rooms, why the virtual machines running them belong on restricted hosts, and why a backup of one is as sensitive as the server itself.
A handful of tasks cannot be done by every controller at once, so five roles are held by one controller each, and the one people meet is the PDC emulator, which is authoritative for time in the domain. Time matters more than it looks, which is the next section.
AuthenticationKerberos, in the amount most people need
Authentication uses Kerberos, and the mechanism explains several everyday symptoms.
When someone signs in, the domain controller issues a ticket granting ticket, a signed token proving who they are, valid for a limited period.
When they open a file share, their machine presents that ticket to get a service ticket for that specific service, and shows the service ticket to the file server. The file server never sees the password and never asks the domain controller anything.
Three practical consequences fall out of that design.
Clocks must agree. Tickets carry timestamps and are rejected if the clocks are more than five minutes apart by default. A machine with a wrong clock cannot authenticate at all, and the error rarely mentions time.
Permission changes need a new ticket. Group membership is baked into the ticket at sign in. Add someone to a group and they will not have the access until they sign out and back in, which is the real answer to a very common help desk question.
Tickets are stolen, not passwords. Modern attacks target the tickets in memory rather than the passwords, which is why the defenses are about limiting where privileged accounts sign in rather than about password complexity.
NTLM is the older protocol still present for compatibility. It is weaker, it is the target of relay attacks, and turning it off is a project every organization should have started and few have finished.
Group PolicyGroup Policy, and the reason it endures
Group Policy is how Active Directory pushes configuration management across the network. A policy object holds settings, it is linked to a site, a domain or an organizational unit, and every machine and user in scope applies it on a schedule.
The order of application is the part worth memorizing, because it decides who wins: local settings first, then site, then domain, then each organizational unit from the top down. Later overrides earlier, so the organizational unit closest to the object wins by default.
Two switches change that, one forcing a policy to survive lower ones and one blocking inheritance, and every environment that uses both heavily has become hard to reason about.
It is old technology and it endures for one reason: Group Policy works on a machine that has not been touched since it was built, needs no agent, and applies whether or not any user is logged in.
Modern management through mobile device tooling is better for machines that live outside the office and worse at the deep configuration Group Policy reaches. Most organizations run both and should be explicit about which owns what, because two systems setting the same value is a bad afternoon.
PermissionsHow access to a resource actually gets decided
Active Directory holds the identities. The resources themselves hold the permissions, and understanding that split explains most access management confusion.
Every folder, share, printer and object carries an access control list: a set of entries, each naming a security principal and what it may do. The list lives with the resource, not in the directory.
At sign in, the domain controller builds an access token for the user containing their own identifier and the identifiers of every group they belong to, including groups those groups belong to.
When they reach a file server, the server compares the token against the access control list on the folder. The directory is not consulted at that moment at all.
That mechanism explains three things people find surprising.
Deny wins. An explicit deny entry beats any allow, no matter which group granted it. One deny placed on a group somebody happens to belong to overrides everything, and it is invisible unless you look at that folder.
Nested groups compound quietly. A user in a group, which is in a group, which was granted access to a share five years ago, has that access and no record of why. The token computes all of it at sign in and the user never sees the chain.
A token can get too large. Belonging to a very large number of groups makes the token exceed a limit and authentication starts failing in ways that look like anything but group membership. It is rare, and it is memorable when it happens.
The convention that keeps this manageable is old and still correct: put user accounts into groups that describe roles, put those groups into groups that describe access to a resource, and grant permissions only to the second kind. Then adding somebody to a role gives them everything the role needs, and nobody ever grants a permission to a person.
AdministrationManaging it, day to day
Administration happens through a small set of tools, and which one somebody reaches for says a lot about how the directory will look in three years. All of them ship with the role, which is most of the answer to what the free Active Directory tools actually are.
Active Directory Users and Computers is the console everyone starts with. It manages user accounts, computer objects, groups and organizational units by clicking. It is fine for one change and it is how directories drift, because nothing done in it is recorded anywhere except in the directory itself.
Active Directory Administrative Center is the newer console, and its useful feature is that it shows the PowerShell command for whatever you just did. Doing a task once by clicking and then reading the command is the fastest way to learn the scripted version.
Group Policy Management Console is where policy objects are written, linked and modeled. Its reporting can tell you which settings would apply to a given user on a given machine, which answers most policy arguments in about a minute.
PowerShell is where management should end up. Every object operation is available, and a script is repeatable, reviewable and able to run against a thousand accounts.
The joiners, movers and leavers process in particular belongs in a script rather than in a console, because it is the same set of steps every time and the manual version is where the leftovers come from.
Sites and Services exists for one job most small networks never touch: telling the directory which physical locations exist and how they connect, so clients authenticate against a nearby domain controller and replication follows the links you actually have.
The tasks that come up constantly are worth naming, because each one has a scripted form worth writing once: creating an account with the right group membership, disabling a leaver and moving their object, resetting a password, adding a machine to the domain, finding accounts that have not logged in for ninety days, and reporting who is in the privileged groups.
That last report is the one to schedule. A directory nobody audits accumulates access management debt silently, and the report costs nothing to run.
Why it is attackedWhy attackers go straight for it
Active Directory is the most attacked component of a Windows estate, and it is worth understanding why rather than treating it as a security topic in the abstract.
Active Directory is the definition of trust on the network. Every joined machine believes what it says. Control the directory and you control every server and every laptop that trusts it, without needing to attack any of them individually.
Active Directory is old and compatible. Decades of backward compatibility mean weak protocols, default security settings from another era, and features nobody uses that are still enabled across the estate.
It rewards patience. An attacker who lands on any workstation is inside the domain. From there the work is enumeration, finding a path from that user account to a privileged one, and Active Directory is designed to answer questions about itself to any authenticated user.
The paths that get used most:
Kerberoasting. Any authenticated user can request a service ticket for an account that runs a service, and that ticket is encrypted with the account's password hash. Take it away and crack it offline, at leisure. The defense is long random passwords on service accounts, or managed accounts where the system generates them.
Password spraying. One common password tried against every account, slowly enough to avoid lockouts. The defense is multi factor authentication and banning the passwords people actually choose.
Delegation and nested groups. Permissions granted years ago, inherited through group membership nobody has read since. The defense is knowing who is actually in the privileged groups, which almost nobody does without a tool.
Stale objects. User accounts of people who left, computer objects for machines that no longer exist, service accounts for systems retired in a previous decade. Each is a credential nobody is watching, and each one is the visible end of an incomplete deprovisioning.
The single most valuable habit is knowing what is in the privileged groups and why, and reviewing it. Everything else is refinement.
PitfallsWhere it goes wrong
Everyone is an administrator of something. Privileged security groups accumulate members, and those members accumulate access to resources across the network. A yearly review of who is in the domain and enterprise administrator groups is the highest value hour anyone spends on this.
Administrators sign in to workstations. A privileged account used on an ordinary machine leaves its ticket in that machine's memory, so compromising any workstation becomes compromising the domain. Separate accounts for privileged work, used only on machines built for it, is the control that breaks this.
Nobody removes anything. Directories only grow. User accounts of leavers, computer objects decommissioned years ago, security groups created for a project that ended. Each is a way in that nobody is monitoring.
The organizational unit structure copies the org chart. It should follow the policy and the administrative delegation you need, not the reporting lines, which change every year and drag the directory structure across with them.
One domain controller. Replication exists for a reason, and a single controller is a single point of failure for every login in the business.
The backup is not tested. Restoring a directory is a specific procedure with its own failure modes, and the time to learn it is not during an outage.
ComparisonActive Directory and Microsoft Entra ID are two different directories
| Criterion | Active Directory | Microsoft Entra ID |
|---|---|---|
| Where it runs | On your domain controllers | Microsoft's service, no servers of yours |
| What it authenticates to | Domain joined machines, file shares, internal applications | Cloud applications over modern protocols |
| Protocols | Kerberos and LDAP | OAuth, SAML, OpenID Connect |
| Structure | Domains, organizational units, a hierarchy | Flat, with groups and administrative units |
| Configuration management | Group Policy, deep and old | Device management, broader and shallower |
| Applies to a laptop in a hotel | Only over a VPN | Yes, directly |
| The usual arrangement | Both, synchronized | Both, synchronized |
These are different products with confusingly similar names, and the confusion causes real mistakes. The important sentence: Microsoft Entra ID is not Active Directory in the cloud. It is a different directory with a different model, and the two are joined by a synchronization tool that copies identities upward.
Most organizations run both, which means two directories to secure rather than one, and a synchronization server that is itself a high value target because it holds credentials for both sides.
FAQFrequently asked questions
What is Active Directory in simple terms?
Active Directory is the database of users, computers, groups and access permissions a Windows network runs on, plus the domain controllers that answer questions about it.
What is a domain controller?
A Windows server holding a copy of the directory and answering authentication and lookup requests. Every one of them holds a full writable copy, which is why physical access to any of them is serious.
What is the difference between a domain and a forest?
A domain is one administrative unit with one database. A forest holds one or more domains and is the actual security boundary, because domains inside a forest trust each other automatically.
What is Group Policy?
The Active Directory mechanism that pushes configuration management to machines and users. Policies are linked to a site, a domain or an organizational unit, and the closest one usually wins.
Why do permission changes not take effect immediately?
Because group membership is written into the Kerberos ticket at sign in. A new ticket is needed, which means signing out and back in.
Why does a wrong clock break logins?
Kerberos tickets carry timestamps and are rejected beyond a five minute difference by default. The error usually says something else entirely.
Is Entra ID the same as Active Directory?
No. Different directory, different model, different protocols. Most organizations run both and synchronize identities between them.
What is Kerberoasting?
Requesting a service ticket for an account that runs a service, then cracking it offline because it is encrypted with that account's password hash. Long random passwords on service accounts is the fix.
How many domain controllers should we have?
At least two, in different physical locations if the business has more than one. A single domain controller is a single point of failure for every login across the network.
Should we still use NTLM?
No, and most environments still do somewhere. Finding what depends on it is the first step, and it is usually an old application or a device nobody owns.
What is an organizational unit for?
Delegating administration and applying policy. If it does neither, it is a folder that adds structure without adding control.
What is the single most useful thing to check?
Who is in the privileged security groups, and why each of those users is there.
How do I install Active Directory Users and Computers on Windows 11?
To manage Active Directory from Windows 11 you need the Remote Server Administration Tools, which include Active Directory Users and Computers.
On Windows 11, and on current Windows 10, open Settings, go to optional features, choose add a feature, and install RSAT: Active Directory Domain Services and Lightweight Directory Services Tools. It needs a Pro or Enterprise edition, and it then appears under Windows Tools.
Keep readingRelated concepts
Read next · Identity and access What Is MFA? The directory decides what an account may reach. This decides whether the account is really theirs. Open this next16 min- Network security · 14 min What Is a Firewall? Network segmentation is what limits how far a compromised directory account can travel.
- Tools · 11 min Free Active Directory Tools, Starting With the Ones Already Installed The free tools for managing it, most of which are already installed.
- Protocols · 10 min PTP, NTP, and Why a Clock Breaks Authentication First Where the time comes from.
- Operations · 10 min What a CMDB Is, and the Question That Justifies One Where discovery finds what the inventory missed.
- Addressing · 9 min What Is DHCP? What breaks when the DNS servers a client is handed point somewhere other than the domain controller.
- Operations · 10 min Provisioning What creating and removing that account is called.
- Hypervisors · 11 min Hyper-V vs VMware What runs on the virtual machines these hypervisors are hosting.
- Directory and identity · 13 min Group Policy Explained How configuration is actually pushed to the objects this directory holds.
- Ports · 10 min Port 88, and Why a Domain Stops Working Without It The system that puts a KDC on every controller.
- Directory and identity · 13 min LDAP Explained The protocol applications use to read this directory and check a password against it.
- Ports · 10 min SMB Port 445, and the One Rule That Matters About It What the domain member traffic on this port is actually doing.
- Managed IT · 10 min Google Workspace vs Microsoft 365, and What Actually Decides It What is already in the server room.
- Operations · 9 min Windows Server End of Life, Version by Version How to find the machines the inventory missed.
- Platforms · 11 min OneDrive vs SharePoint, and What Happens When Someone Leaves Where the files belong once the identities are settled, decided by what happens to a file after the person who made it leaves.
- Shared storage · 9 min NFS vs SMB, and Why the Clients Decide Why SMB checks every user against the directory while default NFS trusts the client machine.