Home › Active Directory basics: how AD DS is built › Step 4
The AD DS domain: objects, replication, administration and sign-in
Step 4 of 6 in Active Directory basics: how AD DS is built · video 3:13
What you will learn
- The three common object types: users, computers and groups
- How multimaster replication works inside a domain
- What the Administrator account and Domain Admins group can do
- How the domain handles authentication and supports authorisation
About this lesson
A domain is the logical container where most day-to-day Active Directory work happens. This lesson describes the three object types admins handle most: user accounts, which hold what is needed to authenticate a person and build their access token; computer accounts, one for every domain-joined machine; and groups, used for permissions and Group Policy. It then looks at the domain from four angles. As a replication boundary, every domain controller holds the full domain data under a multimaster model, while other domains receive only a subset. As an administrative centre, it has a built-in Administrator account and a Domain Admins group with full control of domain objects and local admin rights on joined computers. It provides authentication at start-up and sign-in, and supports authorisation, including Dynamic Access Control with central access rules. A capacity of nearly two billion objects explains why one domain is often enough.
Check yourself
1. Which replication model does AD DS use inside a domain, and what does it allow?
A multimaster model: any domain controller in the domain can accept changes to objects and then replicates them to all the other domain controllers in that domain.
2. What happens to a change made to a user object when the forest contains several domains?
The domain controller where the change was made replicates it in full to every other DC in the same domain. Other domains in the forest receive only a subset of the changes, because the domain is the replication boundary for domain data.
3. Why does a member of Domain Admins have administrator rights on a domain-joined workstation by default?
Domain Admins is placed in the local Administrators group of every domain-joined computer, so its members are local admins on each of them. The built-in Administrator account gets the same rights because it is a member of Domain Admins.
4. A company with central IT and 50,000 accounts asks whether it needs several domains; what does the lesson suggest?
One domain is usually enough: a single domain can hold nearly two billion objects, so size alone is rarely a reason to split. Multiple domains are worth considering mainly for decentralised administration or locations with separate admin needs.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.