Home › How domain controllers work › Step 3

The AD DS sign-in process

Step 3 of 6 in How domain controllers work · video 3:39

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

This lesson follows what happens when a user signs in to a domain-joined computer. The computer first uses DNS to find a domain controller, the Local Security Authority (LSA) handles the authentication, and an access token is built holding the security identifiers (SIDs) of the user and of every group the user belongs to. Programs such as Word use that token to check permissions on files. The lesson takes a SID apart: the S prefix, revision level, identifier authority, domain identifier and relative ID (RID), and points out that the domain Administrator account always ends in 500. It then splits sign-in into two stages: checking credentials against AD DS, which ends with a ticket-granting ticket (TGT), and a background request for a service ticket to the local computer and to any other computer the user later connects to. Computers also sign in with their own accounts at startup, and those logons are recorded in the event logs.

Good to know: with Kerberos the password itself never crosses the network: the client proves it knows the password with encrypted pre-authentication data.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What does the access token created at sign-in contain, and what is it for?

It contains the SIDs of the user and of every group the user is a member of. Every process the user starts carries this token, so a resource such as a Word document can compare those SIDs with its permissions.

2. You find a domain SID that ends in -500. Which account is it?

The domain's built-in Administrator account. SIDs within a domain differ only in the final relative ID, and 500 is a well-known RID reserved for that account.

3. Once a user has received a TGT, can they open files on a server straight away?

Not yet. The TGT only proves who the user is; a background process presents it to a domain controller to get a service ticket, first for the local computer and then for each other computer the user connects to.

4. Does a domain-joined computer authenticate to AD DS itself, and how would you know?

Yes. At startup it signs in with its computer account name and password and becomes a member of Authenticated Users. Nothing appears on screen, but the event log records the logon, and the Security log shows more when auditing is enabled.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← What is a global catalog?Next: Domain controller SRV records →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.