Home › How domain controllers work › Step 2

What is a global catalog?

Step 2 of 6 in How domain controllers work · video 2:43

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

The global catalog is a partial, read-only, searchable copy of every object in the forest. Each domain controller holds full detail only for objects in its own domain, so a search that must reach other domains has to go to a domain controller that is also a global catalog server. The lesson explains which attributes the global catalog carries, such as given name, display name and mail, and how the partial attribute set (PAS) in the schema controls that list. It gives two everyday uses: Exchange Server locating a mail recipient anywhere in the forest, and a domain controller checking universal group memberships while a user signs in. It then covers placement: the first domain controller in the forest root domain becomes a global catalog, each site should have at least one, and in a multi-domain forest the infrastructure master should not be a global catalog unless every domain controller in its domain is one.

Good to know: since Windows Server 2008 the promotion wizard ticks Global catalog by default for every new domain controller, so in practice most domain controllers are global catalog servers.

Check yourself

Answer in your head first, then open each question to see the answer.

1. A search for a user in another domain of the same forest returns nothing when sent to an ordinary domain controller. Why, and where should the query go instead?

An ordinary domain controller answers only for objects in its own domain. Cross-domain results need a domain controller that is a global catalog server, because only it holds a partial copy of every object in the forest.

2. How do you make the global catalog carry an attribute it does not replicate today?

Add the attribute to the partial attribute set (PAS) in the schema. The global catalog stores only that subset of attributes, chosen because they are the most useful for cross-domain searches.

3. Why does the domain controller that authenticates a user need to contact a global catalog during sign-in?

To find the user's universal group memberships. Universal groups can come from anywhere in the forest, and only a global catalog has that forest-wide view.

4. A branch site reaches head office over a slow WAN link. Why make its local domain controller a global catalog?

So that sign-ins and searches that need global catalog data are answered locally. Without one, every such query crosses the WAN and fails when the link is down.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← What is a domain controller?Next: The AD DS sign-in process →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.