Home › Active Directory basics: how AD DS is built › Step 3
The AD DS forest: root domain, security and replication boundary
Step 3 of 6 in Active Directory basics: how AD DS is built · video 3:12
What you will learn
- What the forest root domain holds that other domains do not
- The forest-wide roles: schema master and domain naming master
- Why the forest is both a security and a replication boundary
- When an organisation needs more than one forest
About this lesson
A forest is the outermost container in AD DS: one or more domain trees that share a single schema and global catalog. This lesson explains the forest root domain, the first domain created, and the objects found only there: the schema master and domain naming master operations roles, the Enterprise Admins group and the Schema Admins group, which is empty by default. It shows how Enterprise Admins gain full control across every domain, and who may add members to Schema Admins. The second half treats the forest as a boundary. It is a security boundary, so users outside it have no access by default, while domains inside it trust one another automatically. It is also the replication boundary for the schema and configuration partitions and for the global catalog, which is why applications needing incompatible schemas require a separate forest. The global catalog's part in UPN sign-in and Exchange address books is mentioned too.
Check yourself
1. Which operations master role is the only one allowed to add new domain names to the directory, and how many of them can a forest have?
The domain naming master. There is exactly one per forest, held by a domain controller in the forest root domain, alongside the single schema master.
2. Who belongs to the Schema Admins group in a new forest, and who can add members to it?
Nobody: the group is empty by default. Members of Enterprise Admins, or of Domain Admins in the forest root domain, can add accounts to it when a schema change is actually needed.
3. What happens by default when a user from a different forest tries to open a file share in your forest?
The user gets no access, because the forest is a security boundary and by default no one from outside it can reach its resources. Users from any domain in the same forest are different: all domains in a forest trust each other automatically.
4. Two business units want applications that need conflicting schema extensions; why can they not share one forest?
The schema and configuration partitions replicate across the whole forest, so every domain controller in it must use the same schema. Applications with incompatible schema needs therefore have to live in separate forests.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.