Browse learn

What Is Active Directory?

Learn what Active Directory is, how AD DS organizes domains and objects, which protocols it uses, and where it fits in enterprise identity.

On this page

Link to Active Directory: Definition and Core PurposeActive Directory: Definition and Core Purpose

Active Directory (AD) is Microsoft's directory service technology designed to provide centralized identity, authentication, and resource management for enterprise and campus networks. At its core, AD solves the fundamental problem of organizing, securing, and controlling access to users, devices, groups, and other network resources—at scale. Rather than managing accounts and permissions individually across hundreds or thousands of systems, organizations use AD to define and enforce consistent security, login, and resource policies from a single authoritative directory.

For example, a mid-sized company may register every employee in AD, enabling those users to log in to any company Windows machine, access file shares and printers as permitted, and automatically inherit security and configuration policies—such as password rules or desktop restrictions—centrally set by IT.

While authentication is a primary function of Active Directory, its role is much broader. AD also manages authorization (what resources an identity can access), policy enforcement (what configuration or restrictions apply to users and devices), directory-based application integration, and data about objects themselves.

Link to Architecture: How Is Active Directory Organized?Architecture: How Is Active Directory Organized?

Active Directory organizes information as objects, each representing a real-world entity such as a user, computer, group, or printer. These objects are arranged into a logical, hierarchical structure that streamlines management and delegation.

Link to DomainsDomains

A domain is the fundamental building block in AD—a logical unit that holds a set of objects (users, groups, computers) sharing a common directory database and security boundary. Each domain has its own policies and can be managed independently or as part of a larger structure.

Example distinguished name (DN) for a user in the domain example.com:

text
CN=Jane Doe,OU=HR,DC=example,DC=com

Link to Trees and ForestsTrees and Forests

Multiple domains can be grouped into a tree—a contiguous namespace under a single root domain. A collection of one or more trees makes up a forest, which defines the security and trust boundary for an enterprise. All domains within a forest share a common schema and global catalog, supporting collaboration while retaining separate administrative domains.

  • Forest: Top-level security boundary; can include multiple domain trees.
  • Tree: Hierarchical arrangement of domains; child-parent relationships via DNS naming conventions.

Link to Organizational Units (OUs)Organizational Units (OUs)

Organizational Units provide flexible subdivision within a domain. OUs are containers that can represent departments, roles, physical locations, or any grouping relevant to the organization’s needs. OUs allow for delegated administration and targeted application of policies.

Link to SchemaSchema

The schema defines the rules and structure of objects stored in AD: what object classes (like user or group) exist, and which attributes are available for each. The schema is extensible—organizations can add new classes or attributes as application needs evolve.

Link to Domain Controllers and ReplicationDomain Controllers and Replication

A domain controller (DC) is a server running AD Domain Services. All DCs in a domain maintain synchronized, replicated copies of directory data, ensuring high availability and resiliency. Changes made on one DC propagate automatically to others.

Link to Core Features: Authentication, Authorization, and Group PolicyCore Features: Authentication, Authorization, and Group Policy

Active Directory provides robust features for managing network security and consistency across users and devices.

Link to AuthenticationAuthentication

When a user signs in to a domain-joined workstation, their credentials are verified against stored data in AD using secure protocols. If authentication succeeds, the user is granted a Kerberos ticket, enabling single sign-on (SSO) across resources within the domain and forest.

Link to AuthorizationAuthorization

AD uses security principals (users, groups, computers) and security groups to control resource access. Permissions can be assigned directly to users, but are most often managed via group membership—enabling scalable, role-based access control. For example, only members of the Finance group might have permission to access sensitive financial data stored on a file server.

Link to Group Policy Objects (GPOs)Group Policy Objects (GPOs)

Group Policy provides centralized, rule-based management of user and computer settings across an entire organization. Through Group Policy Objects (GPOs), administrators can enforce password policies, install software, restrict desktop features, configure network settings, and apply security rules—targeted to domains, sites, or OUs. This capability extends well beyond authentication, supporting comprehensive configuration management.

For example, a company could enforce a minimum password length and complexity for all users in a particular OU, or deploy a specific VPN configuration to all laptops. GPOs are replicated via AD and the SYSVOL file share, ensuring reliable, scalable enforcement.

Link to Protocols and Integration: Active Directory and LDAPProtocols and Integration: Active Directory and LDAP

Active Directory is deeply integrated with industry standards, supporting a broad range of interoperable protocols:

Link to LDAP: Directory Access ProtocolLDAP: Directory Access Protocol

Lightweight Directory Access Protocol (LDAP) is the core protocol for reading and modifying directory data. AD fully supports LDAP v2 and v3 (as specified by RFC 4510/4511), allowing non-Windows and cross-platform tools to query and manage AD objects—authenticate users, look up groups, or enumerate organizational units.

A typical LDAP query might search for all users with a specific attribute, or enumerate the members of a given group in AD.

Link to DNS: Naming and LocationDNS: Naming and Location

AD uses DNS (Domain Name System) for domain naming and for locating domain controllers during login and service requests.

Link to Kerberos: Authentication ProtocolKerberos: Authentication Protocol

AD leverages Kerberos for secure, mutual authentication within the domain. This enables strong, ticket-based single sign-on across enterprise resources.

Link to AD-Specific ExtensionsAD-Specific Extensions

While AD uses LDAP for directory access, it extends the protocol to support capabilities not present in standard LDAP directories—such as integrated security descriptors, advanced schema objects, and policy enforcement via Group Policy. These features are unique to Microsoft’s implementation.

Link to Common Misconceptions and Developer GotchasCommon Misconceptions and Developer Gotchas

Several common misconceptions can hinder effective integration and troubleshooting:

  • AD is not the same as LDAP: Active Directory is a directory service that uses and extends LDAP as its directory-access protocol. LDAP itself is a protocol (RFC 4510/4511); AD is a Microsoft product suite with additional features and behaviors.
  • AD does more than authentication: Authentication is just one aspect. AD handles authorization, resource mapping, policy enforcement, and directory organization.
  • Group Policy is broader than password management: Group Policy can enforce a wide variety of user and computer settings beyond passwords, including network restrictions, application settings, and software deployment.
  • Cross-platform integration is supported: While AD is native to Windows, its use of protocols like LDAP and Kerberos enables other systems (Linux, macOS, network appliances, custom apps) to interact with the directory—though certain advanced features like Group Policy are Windows-specific.

Developers integrating with AD must account for differences between AD and generic LDAP, including schema extensions, security descriptors, and the way AD handles certain attributes and controls. Common issues include incorrect DN formatting, misunderstanding group nesting, or expecting AD to support all "vanilla" LDAP operations identically.

Link to Summary: When and Why to Use Active DirectorySummary: When and Why to Use Active Directory

Active Directory excels as a centralized identity and policy management platform in environments dominated by Windows systems, or where unified authentication across many resources is needed. Its integration of authentication, authorization, directory services, and comprehensive policy enforcement via Group Policy streamlines administration and security at scale.

Compelling use-cases include:

  • Managing onboarding/offboarding and access rights for thousands of users
  • Enforcing consistent security and configuration policies on all endpoints
  • Delegating administration and rights via logical directory organization
  • Enabling single sign-on across diverse Windows-based resources

Alternatives such as OpenLDAP or cloud directories may fit scenarios with simpler requirements, non-Windows environments, or cloud-native application stacks. However, for enterprises with complex policy, security, and compatibility requirements—especially those invested in Microsoft ecosystems—Active Directory remains a foundational directory service.


Sources

  • Active Directory Domain Services overview — Microsoft Learn
  • Active Directory documentation — Windows Server Docs
  • RFC 4510: Lightweight Directory Access Protocol (LDAP)
  • RFC 4511: Lightweight Directory Access Protocol (LDAP)
  • Group Policy overview for Windows Server — Microsoft Learn
  • Active Directory Security Groups — Microsoft Learn

Link to SourcesSources