Home › How domain controllers work › Step 3
The AD DS sign-in process
Step 3 of 6 in How domain controllers work · video 3:39
What you will learn
- How a computer finds a domain controller to authenticate a user
- What an access token contains and how applications use it
- How to read the parts of a SID, including the RID
- The difference between the TGT and service tickets
About this lesson
This lesson follows what happens when a user signs in to a domain-joined computer. The computer first uses DNS to find a domain controller, the Local Security Authority (LSA) handles the authentication, and an access token is built holding the security identifiers (SIDs) of the user and of every group the user belongs to. Programs such as Word use that token to check permissions on files. The lesson takes a SID apart: the S prefix, revision level, identifier authority, domain identifier and relative ID (RID), and points out that the domain Administrator account always ends in 500. It then splits sign-in into two stages: checking credentials against AD DS, which ends with a ticket-granting ticket (TGT), and a background request for a service ticket to the local computer and to any other computer the user later connects to. Computers also sign in with their own accounts at startup, and those logons are recorded in the event logs.
Check yourself
1. What does the access token created at sign-in contain, and what is it for?
It contains the SIDs of the user and of every group the user is a member of. Every process the user starts carries this token, so a resource such as a Word document can compare those SIDs with its permissions.
2. You find a domain SID that ends in -500. Which account is it?
The domain's built-in Administrator account. SIDs within a domain differ only in the final relative ID, and 500 is a well-known RID reserved for that account.
3. Once a user has received a TGT, can they open files on a server straight away?
Not yet. The TGT only proves who the user is; a background process presents it to a domain controller to get a service ticket, first for the local computer and then for each other computer the user connects to.
4. Does a domain-joined computer authenticate to AD DS itself, and how would you know?
Yes. At startup it signs in with its computer account name and password and becomes a member of Authenticated Users. Nothing appears on screen, but the event log records the logon, and the Security log shows more when auditing is enabled.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.