Home › Active Directory basics: how AD DS is built › Step 3

The AD DS forest: root domain, security and replication boundary

Step 3 of 6 in Active Directory basics: how AD DS is built · video 3:12

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

A forest is the outermost container in AD DS: one or more domain trees that share a single schema and global catalog. This lesson explains the forest root domain, the first domain created, and the objects found only there: the schema master and domain naming master operations roles, the Enterprise Admins group and the Schema Admins group, which is empty by default. It shows how Enterprise Admins gain full control across every domain, and who may add members to Schema Admins. The second half treats the forest as a boundary. It is a security boundary, so users outside it have no access by default, while domains inside it trust one another automatically. It is also the replication boundary for the schema and configuration partitions and for the global catalog, which is why applications needing incompatible schemas require a separate forest. The global catalog's part in UPN sign-in and Exchange address books is mentioned too.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which operations master role is the only one allowed to add new domain names to the directory, and how many of them can a forest have?

The domain naming master. There is exactly one per forest, held by a domain controller in the forest root domain, alongside the single schema master.

2. Who belongs to the Schema Admins group in a new forest, and who can add members to it?

Nobody: the group is empty by default. Members of Enterprise Admins, or of Domain Admins in the forest root domain, can add accounts to it when a schema change is actually needed.

3. What happens by default when a user from a different forest tries to open a file share in your forest?

The user gets no access, because the forest is a security boundary and by default no one from outside it can reach its resources. Users from any domain in the same forest are different: all domains in a forest trust each other automatically.

4. Two business units want applications that need conflicting schema extensions; why can they not share one forest?

The schema and configuration partitions replicate across the whole forest, so every domain controller in it must use the same schema. Applications with incompatible schema needs therefore have to live in separate forests.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Introduction and Administration Tools

4.4★ · 10,857 students on Udemy

See the course on Udemy
← The AD DS schema: classes, attributes and the schema masterNext: The AD DS domain: objects, replication, administration and sign-in →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.