Active Directory
Active Directory is the directory service a Windows network runs on — the forest and domain structure that holds every user, computer, and policy, and the roles and protocols that make a login work. This walks all of it interactively: explore the logical and physical structure, click through the five FSMO roles, see how Group Policy is applied, and step through the Kerberos exchange behind a single sign-on.
Forests, domains, roles, and how a login really works.
Forest → domains → OUs → objects: the structure you administer.
The forest — the top of the structure and the real security boundary.
A forest is the outermost container and the true security boundary of Active Directory: everything inside shares one schema, one configuration, and a global catalog, and every domain in it trusts every other automatically. You do not cross a forest without an explicit trust. The first domain created becomes the forest root.
- One shared schema and configuration
- Automatic two-way transitive trust between its domains
- The security boundary — not the domain
The five single-master roles
Active Directory is multi-master, except for five jobs that would break if two servers did them at once. Two are held per forest, three per domain — click each for what it does and what its loss costs you.
Move a role gracefully with a transfer; when the holder is gone for good, seize it with ntdsutil — and never bring the old holder back.
The busiest role: time, passwords, lockouts, GPOs.
The PDC Emulator is the one that actually matters hour to hour. It is the authoritative time source for the domain (Kerberos fails if clocks drift more than five minutes), it is where password changes and account lockouts are checked first, and it is the default target when you edit Group Policy. One per domain.
Its outage is felt fast — time drift, password and lockout problems — so it is the role you transfer first.
How Group Policy is applied
Every user and computer gets the GPOs linked above it, in a fixed order — Local, Site, Domain, OU — with the last one winning, unless Enforced or Block Inheritance changes the rules.
The mnemonic is LSDOU — Local, Site, Domain, OU.
Finally the OUs, from the top of the tree down to the OU that directly contains the object. Because this is last, the GPO on the OU closest to the object normally wins — which is exactly why a good OU design is what makes Group Policy manageable.
- Later wins
- On a conflicting setting, the GPO applied later overrides the earlier one — so OU beats Domain beats Site beats Local.
- Inheritance
- An object receives every GPO linked above it, all the way up the tree, not just the nearest one.
- Enforced
- A link marked Enforced cannot be overridden by anything lower and cannot be blocked — it flips the 'later wins' rule for itself.
- Block Inheritance
- An OU can block inherited GPOs from above — but Enforced links still get through.
- Security filtering
- A GPO only applies to the users and computers it is filtered to; by default that is Authenticated Users.
What happens at logon
Behind a single sign-on is a six-message exchange between the client, the KDC on a domain controller, and the service. Step through it to see how the password is proven once and then never sent again.
“I am j.smith — here is proof.”
The client asks the KDC's Authentication Service for a ticket-granting ticket. It proves who it is with pre-authentication: a current timestamp encrypted with the key derived from the user's password. Only the real user (and the KDC) can produce it, and the password itself never crosses the wire.
- What is the difference between a forest and a domain in Active Directory?
- A domain is a single administrative and replication partition — its own users, password policy, and object database. A forest is the outer container that can hold several domains sharing one schema and a global catalog, and it is the real security boundary: every domain in a forest trusts every other automatically, so crossing forests takes an explicit trust.
- What are the five FSMO roles?
- The Flexible Single Master Operations roles handle the few jobs that cannot run multi-master. Two are held once per forest — Schema Master and Domain Naming Master — and three once per domain — RID Master, PDC Emulator, and Infrastructure Master. The PDC Emulator, which handles time, passwords, and lockouts, is the one whose loss is felt fastest.
- What is an Organizational Unit (OU)?
- An OU is a container inside a domain used for two things: delegating administration to the right people and scoping Group Policy to the right objects. OUs are invisible to users and are not security groups — you do not grant permissions with an OU, you grant them with groups.
- In what order is Group Policy applied?
- Local, then Site, then Domain, then OU — the mnemonic is LSDOU. Settings applied later override earlier ones, so the GPO linked to the OU closest to the object normally wins. Two overrides bend that: an Enforced link cannot be overridden or blocked, and Block Inheritance stops inherited GPOs except Enforced ones.
- How does Kerberos authentication work?
- The client proves its identity to the KDC once and receives a ticket-granting ticket. It then trades that TGT for a service ticket to each resource it reaches, and presents the service ticket directly to the service, which validates it with its own key without ever contacting the KDC. The password is proven once and never sent again.
- What is the Global Catalog in Active Directory?
- The Global Catalog is a partial, read-only copy of every object in the forest, held on selected domain controllers. It lets forest-wide searches and universal-group membership resolve without querying every domain, which is why at least one Global Catalog per site keeps logons fast.
The rest of the section
- 01RJ45 Wiring: T568A and T568BBoth colour codes, pin by pin, side by side.
- 02RJ11 Wiring and Phone PinoutsSix positions, three lines, two colour systems.
- 03Keystone Jack TerminationStrip, seat, punch, snap — without failing the certification.
- 0466 Block WiringFifty rows, four columns, and where the bridging clips go.
- 05110 Block WiringLay the pairs in, press the connecting block on.
- 06Cat5e vs Cat6 vs Cat6a vs Cat8Speed, distance, and power decide it — not the bigger number.
- 07Fibre Types, Connectors and PolishRead the jacket, read the connector, don't mate blue to green.
- 08Subnetting, ExplainedWhere the numbers come from, and the meaning behind them.
- 09The OSI Model, Layer by LayerSeven layers, what each does, and how they hand off.
- 10PoE Standards and Why It Won't PowerThe switch reserves the class, not the draw.
- 11Camera Lens, Field of View and Pixel DensityCovering the room is not the same as identifying a face in it.
- 12Patch Panels and Labelling to TIA-606A label that survives is worth more than a tidy rack.
- 13Rack Planning: Units, Depth, Weight and HeatIt fits vertically. That was never the hard part.
- 14Writing a Switch ConfigurationFrom factory default to a switch you would hand over.
- 15Networking and Cabling GlossaryThe terms, and what they mean on a job.
- 16POTS to VoIP: What BreaksThe lines nobody remembers until they stop working.
- 17Testing an Analogue Phone LineTip, ring, and the four numbers that tell you whose fault it is.
- 18Toning and Tracing a CableFinding one pair in a bundle of two hundred.
- 19Reading a Cable Certifier ReportWhat PASS* actually means, and which number to look at first.
- 20Which Cable Tester Do You Need?Three tiers, and the one most people actually need.
- 21Running an Office Floor RestackEveryone sits down Monday and their machine works.
- 22Cable Management for Desks and RacksTidy is a by-product. Serviceable is the point.
- 23Asset Tagging and CMDB AuditsThe scan is easy. Scanning it into the right record is the job.
- 24Cabling an Office Fit-OutHow many drops, run where, and what it takes to add one later.
- 25Parcel Locker Site SurveysWhether the unit fits, powers, connects — and gets in the door.
- 26VLANs and TrunkingAccess, trunk, tagged, native — and which one is the security hole.
- 27Spanning Tree and Switching LoopsWhy one patch cord can take a whole floor down in seconds.
- 28Reading a TracerouteWhich loss is real, and whose network it is in.
- 29DHCP, DNS and Helper AddressesWhy the new VLAN gets no addresses, and why it is always DNS.
- 30Wi-Fi Channel Planning and AP PlacementMore access points at lower power, not fewer at maximum.
- 31SMART Attributes That Predict FailureA drive can report PASSED while it is visibly dying.
- 32BitLocker: Keys, Recovery and EscrowThe key exists somewhere, or the data does not.
- 33Grounding and Bonding a Telecom RoomOne ground, one path, and no loops between rooms.
- 34UPS Sizing: VA, Watts and RuntimeThe number on the box is not the number you need.
- 35Mounting Displays on Any WallFind the structure. Everything else is a repair bill.
- 36Mounting IP CamerasHeight, angle, and the surfaces that ruin the picture at night.
We do this work
as well as document it
Anyone learning Active Directory for a role or a cert, or mapping what they half-remember onto the parts that matter.