Home › How domain controllers work › Step 1

What is a domain controller?

Step 1 of 6 in How domain controllers work · video 3:33

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

A domain controller is the server that holds a copy of the AD DS database, NTDS.dit, and of the SYSVOL folder, which carries the files and templates behind Group Policy Objects. This lesson explains multi-master replication: most changes can be made on any writable domain controller and are then replicated to the others, while a read-only domain controller (RODC) keeps a copy that cannot be edited. It covers the move from the obsolete File Replication Service to DFS Replication for SYSVOL, and the services a domain controller runs besides the database, including Kerberos authentication and the Key Distribution Center that issues the ticket-granting ticket. It also sets out the rule of at least two domain controllers per domain, so sign-ins keep working when one fails and the load is shared. For branch offices with weak physical security, it compares two protections: an RODC that caches few or no passwords, and BitLocker drive encryption.

Good to know: FRS has since been removed from Windows Server. A domain controller running Windows Server 2019 or later cannot join a domain whose SYSVOL still replicates with FRS, so migrate SYSVOL to DFS Replication (dfsrmig) first.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which two things does every domain controller keep a copy of?

The AD DS database file NTDS.dit and the SYSVOL folder. NTDS.dit holds the directory objects themselves, while SYSVOL holds the templates and files that Group Policy Objects need, so a domain controller needs both to authenticate users and hand out policy.

2. What happens to domain sign-ins if the AD DS database cannot be reached at all?

They fail, because every user account lives in that database and domain-based authentication depends on it. This is the reason for running at least two domain controllers in each domain.

3. Which service on a domain controller issues the ticket-granting ticket (TGT) when an account signs in?

The Key Distribution Center (KDC). It works alongside the Kerberos authentication service and gives the signed-in account a TGT, which is later used to request access to other computers.

4. A branch office needs a local domain controller, but the server will sit in an unlocked cupboard. How can you limit the damage if it is stolen?

Deploy a read-only domain controller: its database cannot be changed locally and by default it caches no user passwords (you can allow caching for the branch users only), so far less is exposed. Encrypting its drive with BitLocker adds a second layer, because a stolen disk stays encrypted in another computer.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← About this pathNext: What is a global catalog? →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.