What is Active Directory, and which jobs does it do in identity and access management?
Active Directory (AD) is Microsoft's directory service: one central database of a Windows domain's users, computers, groups and other objects, used to authenticate them and to decide what they may access.
Without a directory every server keeps its own user list, and giving one person access to ten machines means ten accounts and ten passwords. AD replaces that with one identity per person and one place to manage it. It runs on domain controllers (DCs), servers that hold a copy of the directory and answer logon requests.
What it is used for:
- Authentication: users and computers log on against the domain (Kerberos), so one account works on every domain-joined machine.
- Authorization: groups from AD appear in access lists on file shares, servers and applications.
- Central configuration: Group Policy pushes settings to thousands of machines from one place.
- Structure and delegation: organizational units (OUs) group objects so that administration can be split up and handed to the right people.
The IAM goal behind it is efficient access management with the minimum necessary permissions. The tension is that a very detailed permission model becomes unmanageable, while one that is too coarse no longer protects anything.
Go deeper:
Microsoft Learn: Active Directory Domain Services overview — what the directory stores and how domain controllers serve it.
Wikipedia: Active Directory — history, forests/trees/domains, and the services built on it.