LOGBOOK

HELP

1 / 29
time's up — finish this card
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag
Topic Access Management with Active Directory

Question

What is Active Directory, and which jobs does it do in identity and access management?

Answer

Active Directory (AD) is Microsoft's directory service: one central database of a Windows domain's users, computers, groups and other objects, used to authenticate them and to decide what they may access.

Without a directory every server keeps its own user list, and giving one person access to ten machines means ten accounts and ten passwords. AD replaces that with one identity per person and one place to manage it. It runs on domain controllers (DCs), servers that hold a copy of the directory and answer logon requests.

What it is used for:

  • Authentication: users and computers log on against the domain (Kerberos), so one account works on every domain-joined machine.
  • Authorization: groups from AD appear in access lists on file shares, servers and applications.
  • Central configuration: Group Policy pushes settings to thousands of machines from one place.
  • Structure and delegation: organizational units (OUs) group objects so that administration can be split up and handed to the right people.

The IAM goal behind it is efficient access management with the minimum necessary permissions. The tension is that a very detailed permission model becomes unmanageable, while one that is too coarse no longer protects anything.

Go deeper:

A simplified example of a publishing company's internal network.  The company has four groups with varying permissions to the three shared folders on the network.
A simplified example of a publishing company's internal network. The company has four groups with varying permissions to the three shared folders on the network.
Abiola Streete · CC BY-SA 4.0 · Wikimedia Commons
or press any other key
Topic Access Management with Active Directory

Question

What is the difference between an organizational unit (OU) and a container in Active Directory?

Answer

Both hold objects, but only an OU can have Group Policies linked to it and administrative rights delegated on it; a container is just a folder.

An OU is the building block for administration. You can link a GPO to it (all computers and users inside get those settings), delegate control over it (the helpdesk may reset passwords in this OU only), and nest OUs inside each other.

A container (the built-in Users, Computers and Builtin folders, shown with a plain folder icon) can hold objects but cannot have GPOs linked to it and cannot be nested into your own structure. You also cannot create new containers in the normal admin tools.

Why it matters: an object left in a container misses every OU-linked policy. That is why real objects should be moved into the designed OU structure.

Go deeper:

or press any other key