Question
What is Active Directory, and which jobs does it do in identity and access management?
Answer
Active Directory (AD) is Microsoft's directory service: one central database of a Windows domain's users, computers, groups and other objects, used to authenticate them and to decide what they may access.
Without a directory every server keeps its own user list, and giving one person access to ten machines means ten accounts and ten passwords. AD replaces that with one identity per person and one place to manage it. It runs on domain controllers (DCs), servers that hold a copy of the directory and answer logon requests.
What it is used for:
- Authentication: users and computers log on against the domain (Kerberos), so one account works on every domain-joined machine.
- Authorization: groups from AD appear in access lists on file shares, servers and applications.
- Central configuration: Group Policy pushes settings to thousands of machines from one place.
- Structure and delegation: organizational units (OUs) group objects so that administration can be split up and handed to the right people.
The IAM goal behind it is efficient access management with the minimum necessary permissions. The tension is that a very detailed permission model becomes unmanageable, while one that is too coarse no longer protects anything.
Go deeper:
Microsoft Learn: Active Directory Domain Services overview — what the directory stores and how domain controllers serve it.
Wikipedia: Active Directory — history, forests/trees/domains, and the services built on it.
Note saved — thanks!
Question
What is the difference between an organizational unit (OU) and a container in Active Directory?
Answer
Both hold objects, but only an OU can have Group Policies linked to it and administrative rights delegated on it; a container is just a folder.
An OU is the building block for administration. You can link a GPO to it (all computers and users inside get those settings), delegate control over it (the helpdesk may reset passwords in this OU only), and nest OUs inside each other.
A container (the built-in Users, Computers and Builtin folders, shown with a plain folder icon) can hold objects but cannot have GPOs linked to it and cannot be nested into your own structure. You also cannot create new containers in the normal admin tools.
Why it matters: an object left in a container misses every OU-linked policy. That is why real objects should be moved into the designed OU structure.
Go deeper:
Wikipedia: Organizational unit (computing) — OUs as the smallest unit for Group Policy and delegation.
Note saved — thanks!