A server running AD DS. Placing these servers in Azure as well as on-premises keeps synchronisation and user sign-in working if one location fails.
Also called domain controller.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-900SC-200SC-300AZ-802MD-102
Each book explains DC in context, with comparison tables and the common traps.
Terms in this definition
- AD DS
Short for Active Directory Domain Services, the domain controller-based Windows directory run on-premises. Microsoft Entra Domain Services offers a managed counterpart.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- Active Directory site
An AD DS object grouping IP subnets with fast links between them. Sites shape how replication flows and help clients find a domain controller close by.
- Audit Credential Validation
Logs credential checks during user sign-in, such as a domain controller handling NTLM authentication; part of advanced auditing.
- Cloud Kerberos trust
Microsoft's preferred model for hybrid Windows Hello for Business. Microsoft Entra Kerberos hands out a partial ticket-granting ticket, a domain controller swaps it for a complete one, and there is no need for PKI or synchronising keys.
- Cloud TGT
Issued by Microsoft Entra ID alongside the PRT when someone signs in to Windows, this ticket for the KERBEROS.MICROSOFTONLINE.COM realm lets a device request service tickets for cloud resources like Azure Files with no domain controller involved.
- DC agent
Runs on every writable domain controller as a password filter, checking each password change against banned password lists downloaded earlier. A restart is needed after installing it, and if the proxy is down it keeps enforcing the policy it has cached.
- Lingering object
When a domain controller stays offline beyond the tombstone lifetime, objects removed elsewhere in the meantime can survive on it; these leftovers are called lingering objects.
- Namespace server
A domain controller or member server hosting a DFS namespace; domain-based namespaces may be hosted on more than one.
- Non-authoritative synchronisation
After cloning or a restore, a domain controller can have SYSVOL (or another DFSR folder) reset so it pulls a fresh copy from a partner. The authoritative alternative instead nominates one member as the source everyone else takes.