Active Directory Domain Services Flashcards
AD DS logical components
- Domain
- Tree
- Forest
- OU
- Partition
- Schema
- Container
AD DS physical components
- Data store
- Global catalog
- DC
- RODC
- Site
- Subnet
Trusts: Parent and child
- Created when new domain is added to an existing tree.
- Transitive, two-way
Trusts: Tree-root
- Created when a new tree is added to the forest
- Transitive, two-way
Trusts: Forest
- Manually created between forests
- Transitive, one-way or two-way
Trusts: Shortcut trust
- Manually created to reduce authentication time between domains
- Non transitive, one-way or two-way
Trusts: external
- Manually created to allow access to resources from a domain in another forest or NT 4.0 domain
- Non transitive, One-way or two-way
Trusts: realm
- Manually created between AD DS and another service running kerberos 5
- Transitive or non transitive, one-way or two-way
Security principal
Any entity that can be authenticated by the operating system e.g user account, computer account, or a thread or process that runs in the security context of a user or computer account
SID
- Security identifier
- Unique identifier for a security entity issued by an authority such as a domain controller
AD components: Data Store
- Holds the AD database
- Two files on each DC
AD DS database file path
C:\Windows\NTDS\NTDS.DIT
AD DS transaction log file path
C:\Windows\NTDS\EDB.log
NTDS.DIT partitions
- Domain partition
- Configuration partition
- Schema partition
- Application partitions
NTDS.DIT partitions: domain partition
Stores object information for the domain
NTDS.DIT Partitons: configuration partition
Stores config in for the forest and domain trees
NTDS.DIT partitions: schema partiton
Stores the schema
NTDS.DIT partiton: application partition
Where applications store data in AD DS
IDP
Identity provider e.g AD DS, Azure AD
Azure AD Connect
Tool that allows an organization to establish a hybrid identity. Synchronizes user identities, attributes, and objects between both IDPs (Azure AD and AD DS on prem)
Hybrid identity
Same username and password used to access resources in both IDP environments (cloud and on prem)