Short for Active Directory Domain Services, the domain controller-based Windows directory run on-premises. Microsoft Entra Domain Services offers a managed counterpart.
Also called Active Directory Domain Services.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500SC-900SC-300AZ-802ALZ
Each book explains AD DS in context, with comparison tables and the common traps.
Terms in this definition
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- Microsoft Entra Domain Services
Domain hosted and managed in Azure that provides Kerberos, NTLM and LDAP. Its contents come from Entra ID, so no connection to on-premises is required.
Related terms
- Active Directory site
An AD DS object grouping IP subnets with fast links between them. Sites shape how replication flows and help clients find a domain controller close by.
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- AD DS authentication (Azure Files)
Option that domain-joins a storage account to on-premises AD DS, letting synced hybrid users mount its SMB shares using Kerberos. RBAC controls share-level access, while Windows ACLs govern files and folders.
- Authentication policy
Lets administrators control how long Kerberos ticket-granting tickets last for chosen accounts and under what conditions they may access things. Introduced as an AD DS object at the Windows Server 2012 R2 domain functional level.
- Authentication policy silo
Privileged accounts (users, computers, services) placed together in this AD DS container are restricted, through attached authentication policies, to signing in within it.
- AzFilesHybrid
Its Join-AzStorageAccount cmdlet registers a storage account with on-premises Active Directory, so file shares on Azure can authenticate AD DS identities.
- Custom banned password list
Up to 1,000 words specific to an organisation, such as product names or locations, that Microsoft Entra Password Protection refuses in passwords, on top of Microsoft's global list. On-premises AD DS can enforce it too.
- Custom DNS server
DNS server addresses configured on a VNet, or overridden on a NIC, in place of Azure-provided DNS, such as AD DS domain controllers; VMs need to be able to reach that private IP.