Home › How domain controllers work › Step 1
What is a domain controller?
Step 1 of 6 in How domain controllers work · video 3:33
What you will learn
- What NTDS.dit and SYSVOL hold on every domain controller
- How multi-master replication differs from the read-only copy on an RODC
- Why every domain needs at least two domain controllers
- How RODCs and BitLocker protect domain controllers in branch offices
About this lesson
A domain controller is the server that holds a copy of the AD DS database, NTDS.dit, and of the SYSVOL folder, which carries the files and templates behind Group Policy Objects. This lesson explains multi-master replication: most changes can be made on any writable domain controller and are then replicated to the others, while a read-only domain controller (RODC) keeps a copy that cannot be edited. It covers the move from the obsolete File Replication Service to DFS Replication for SYSVOL, and the services a domain controller runs besides the database, including Kerberos authentication and the Key Distribution Center that issues the ticket-granting ticket. It also sets out the rule of at least two domain controllers per domain, so sign-ins keep working when one fails and the load is shared. For branch offices with weak physical security, it compares two protections: an RODC that caches few or no passwords, and BitLocker drive encryption.
Check yourself
1. Which two things does every domain controller keep a copy of?
The AD DS database file NTDS.dit and the SYSVOL folder. NTDS.dit holds the directory objects themselves, while SYSVOL holds the templates and files that Group Policy Objects need, so a domain controller needs both to authenticate users and hand out policy.
2. What happens to domain sign-ins if the AD DS database cannot be reached at all?
They fail, because every user account lives in that database and domain-based authentication depends on it. This is the reason for running at least two domain controllers in each domain.
3. Which service on a domain controller issues the ticket-granting ticket (TGT) when an account signs in?
The Key Distribution Center (KDC). It works alongside the Kerberos authentication service and gives the signed-in account a TGT, which is later used to request access to other computers.
4. A branch office needs a local domain controller, but the server will sit in an unlocked cupboard. How can you limit the damage if it is stolen?
Deploy a read-only domain controller: its database cannot be changed locally and by default it caches no user passwords (you can allow caching for the branch users only), so far less is exposed. Encrypting its drive with BitLocker adds a second layer, because a stolen disk stays encrypted in another computer.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.