Home › Active Directory basics: how AD DS is built › Step 1

AD DS components: logical and physical building blocks

Step 1 of 6 in Active Directory basics: how AD DS is built · video 4:30

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Active Directory Domain Services is made of two kinds of parts: logical structures that shape the directory design, and physical pieces that hold and serve the data. This lesson works through both lists. On the logical side it covers partitions (naming contexts) such as the schema, configuration and domain partitions, then the schema itself, domains, domain trees, forests, sites, subnets, organisational units and generic containers, including the key point that Group Policy objects can be linked to OUs but not to containers. On the physical side it explains domain controllers, the data store in ntds.dit under C:\Windows\NTDS, global catalog servers and read-only domain controllers (RODCs) for branch offices. Knowing which component does what makes later topics such as Group Policy, replication and site design far easier to follow, and helps an admin read an AD DS design without guessing.

Good to know: the global catalog holds a full copy of the objects in its own domain but only a partial set of attributes for objects in other domains. Certificate Services and Remote Access, mentioned at the start, are separate server roles that work with AD DS rather than parts of it.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which three partitions of the AD DS database does the lesson name, and what does each hold?

The schema partition holds the Active Directory schema, the configuration partition holds forest-wide configuration objects, and the domain partition holds the users, computers, groups and other objects of that domain. They live in one database file but are replicated as separate naming contexts.

2. What happens when a user looks for an object stored in another domain of the forest, and how does a global catalog server help?

Without a global catalog the search would have to reach domain controllers in the other domain. A global catalog server keeps a partial copy of objects from every domain in the forest, so it can answer such searches itself and much faster.

3. On a domain controller installed with default settings, what is the AD DS database file called and where is it stored?

It is ntds.dit, kept together with its transaction log files in C:\Windows\NTDS. Every domain controller has its own copy of this data store.

4. A branch office has weak physical security and little local IT support; which kind of domain controller fits there, and why?

A read-only domain controller (RODC). It holds a read-only copy of AD DS, so a stolen or tampered branch server cannot push changes back into the directory, which suits sites that are hard to secure and support.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Introduction and Administration Tools

4.4★ · 10,857 students on Udemy

See the course on Udemy
← About this pathNext: The AD DS schema: classes, attributes and the schema master →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.