What is Microsoft Active Directory Domain Services (AD DS)? (2024)

By

  • Ben Lutkevich,Site Editor
  • Toni Boger,TechTarget

What is Active Directory Domain Services?

Active Directory Domain Services (AD DS) is a server role in Active Directory that allows admins to manage and store information about resources from a network, as well as application data, in a distributed database.

AD DS helps admins manage network elements -- both computing devices and users -- and reorder them into a custom hierarchical structure. AD DS also integrates security by authenticating logons and controlling access to directory resources.

What is Microsoft Active Directory Domain Services (AD DS)? (1)

How is Active Directory Domain Services used?

Active Directory is a directory service that runs on Microsoft Windows Server. It is used for identity and access management. AD DS stores and organizes information about the people, devices and services connected to a network. AD DS serves as a locator service for those objects and as a way for organizations to have a central point of administration for all activity on the corporate network.

AD DS is used in on-premises Windows environments, and Microsoft Azure AD DS is used in cloud-based Windows environments. They can be used together in hybrid cloud environments.

How does AD DS work?

AD DS is the core component of Active Directory that enables users to authenticate and access resources on the network. Active Directory organizes objects into a hierarchy, which lets various Domain Services connect with them and users access or manage them. The hierarchical structure includes the following:

  • Domains. A group of objects, such as users or groups of devices, that share the same AD database makes up a domain.
  • Organizational units. Within a domain, organizational units are used to organize objects within the domains.
  • Active Directory trees. Multiple domains grouped together in a logical hierarchy make up an AD tree. The bonds between domains in a tree are known as "trusts."
  • Active Directory forests. This AD functional level is made up of multiple trees grouped together. Trees in an AD forest share trusts, just like domains in a tree share trusts. Trusts enable constituent parts of a tree or forest to share things like directory schemas and configuration specifications.
What is Microsoft Active Directory Domain Services (AD DS)? (2)

What services does AD DS provide?

Active Directory covers a range of services. AD Domain Services is the main service that encompasses these five services.

Domain Services

Domain Services stores centralized directory information and lets users and domains communicate. When a user attempts to connect to a device or resource on a network, this service provides login authentication, verifying the user's login credentials and access permissions.

Lightweight Directory Services (LDS)

AD LDS is similar to Domain Services, but it uses Lightweight Directory Access Protocol (LDAP), which has fewer restrictions. AD LDS enables cross-platform capabilities that, for instance, let Linux-based computers function on the network.

Active Directory Federation Services (AD FS)

AD FS provides single sign-on authentication, enabling users to sign in once to access multiple applications in the same session.

Rights Management

This service controls data access policies and provides access rights management. For example, Rights Management determines which folders users can access.

Certificate Services

Certificate Services allows the domain controller to create and manage digital certificates, signatures and public key cryptography.

What are the benefits of Active Directory Domain Services?

The four key benefits of AD DS include the following:

  1. Hierarchical structure. This is the main benefit of AD DS, providing the organizational structure for the information contained in Active Directory.
  2. Flexibility. AD DS gives users flexibility in determining how data is organized on the network. It simplifies administrative tasks by centralizing services like user and rights management and provides some security. Users can access Active Directory from any computer on the network.
  3. Single point of access. Domain Services creates a single point of access to network resources. This lets IT teams collaborate more efficiently and limit the access points to sensitive resources.
  4. Redundancy. AD DS has built in replication and redundancy If one domain controller fails, another automatically takes over its responsibilities.

What are Active Directory Domain Services terms to know?

Some common AD DS related terms and concepts include the following:

  • Global catalog. The Global catalog holds all AD DS objects. Administrators can find directory information -- such as a username -- across any domain.
  • LDAP. This protocol provides the language that servers and clients within the directory use to communicate with each other.
  • Multi-master replication. A function that ensures all domain controllers on a network are updated with any changes made to Active Directory.
  • Objects. These are the pieces of information that Active Directory organizes. There are two types of objects: Container objects are organizational units, such as forests and trees, that hold other objects inside of them. Leaf objects represent things like users, computers and other devices on the network.
  • Query and index mechanism. This mechanism enables users to search the global catalog for directory information.
  • Schema. The schema is a set of rules a user establishes to define classes of objects and attributes in the directory. These rules also dictate the characteristics of object instances and naming formats.
  • Sites. The physical groupings of IP subnets. They enable the easy replication of information among the domain controllers and the deployment of group policies.

What role do domain controllers play in AD DS?

Domain controllers are physical servers that host AD DS and newer Windows services like Kerberos Key Distribution Center, Netlogon, Intersite Messaging and Windows Time. Active Directory requires at least one domain controller to respond to authentication requests and verify users on the network.

Domain controllers also replicate the AD DS database inside an AD forest. Changes made in a directory on one domain controller -- such as a password change or account deletion -- replicate to other domain controllers on the network.

Learn more about Active Directory and how to troubleshoot common issues and find out how to handle replication problems.

This was last updated in July 2021

Continue Reading About Active Directory Domain Services (AD DS)

  • Explore the benefits of Azure AD vs. on-prem AD
  • Construct a solid Active Directory password policy
  • How does AD DS differ from Microsoft Azure Active Directory?
  • Securing Active Directory also involves good backup practices
  • Set up users with key PowerShell Active Directory commands

Related Terms

What is an uninterruptible power supply (UPS)?
An uninterruptible power supply (UPS) is a device that allows a computer to keep running for at least a short time when incoming ...Seecompletedefinition
What is Microsoft Azure File Service?
Microsoft Azure Files -- sometimes known as Microsoft Azure File Service -- is a simple, secure, serverless, fully managed and ...Seecompletedefinition
What is the blue screen of death (BSOD)?
The blue screen of death (BSOD) -- also known as a stop error screen, blue screen error, fatal error or bugcheck -- is a critical...Seecompletedefinition

Dig Deeper on IT operations and infrastructure management

  • Active Directory domain (AD domain)By: StephenBigelow
  • Active Directory functional levelsBy: StephenBigelow
  • How to use Azure AD Connect synchronization for hybrid IAMBy: KyleJohnson
  • DNS server troubleshooting for Linux and WindowsBy: DamonGarn
What is Microsoft Active Directory Domain Services (AD DS)? (2024)
Top Articles
Local cycling and walking infrastructure plans (LCWIPs)
Here's How Investing $50 Per Week Can Generate $35,000 in Annual Dividend Income by Retirement | The Motley Fool
Tiny Tina Deadshot Build
Cappacuolo Pronunciation
Victory Road Radical Red
Palm Coast Permits Online
Skycurve Replacement Mat
Obor Guide Osrs
Bin Stores in Wisconsin
Top Scorers Transfermarkt
Don Wallence Auto Sales Vehicles
San Diego Terminal 2 Parking Promo Code
Marist Dining Hall Menu
Mawal Gameroom Download
Atrium Shift Select
Minn Kota Paws
Paketshops | PAKET.net
Swimgs Yung Wong Travels Sophie Koch Hits 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Springs Cow Dog Pig Hollywood Studios Beach House Flying Fun Hot Air Balloons, Riding Lessons And Bikes Pack Both Up Away The Alpha Baa Baa Twinkle
Fire Rescue 1 Login
Premier Boating Center Conroe
Alaska Bücher in der richtigen Reihenfolge
Nioh 2: Divine Gear [Hands-on Experience]
Troy Bilt Mower Carburetor Diagram
Missouri Highway Patrol Crash
Craigslist Maui Garage Sale
Walmart Car Department Phone Number
Heart Ring Worth Aj
Scream Queens Parents Guide
Sister Souljah Net Worth
Inkwell, pen rests and nib boxes made of pewter, glass and porcelain.
Paris Immobilier - craigslist
Black Panther 2 Showtimes Near Epic Theatres Of Palm Coast
Jailfunds Send Message
Tom Thumb Direct2Hr
Will there be a The Tower season 4? Latest news and speculation
Log in to your MyChart account
Craigslist Sf Garage Sales
417-990-0201
Tire Pro Candler
Reli Stocktwits
Http://N14.Ultipro.com
Robeson County Mugshots 2022
Nearest Ups Office To Me
Miracle Shoes Ff6
Walmart Car Service Near Me
Carteret County Busted Paper
Hovia reveals top 4 feel-good wallpaper trends for 2024
Metra Union Pacific West Schedule
Kobe Express Bayside Lakes Photos
Elizabethtown Mesothelioma Legal Question
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6458

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.