The highest-level AD container and security boundary. Its domain trees, one or more, all use one schema, configuration and global catalog.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Forest in context, with comparison tables and the common traps.
Terms in this definition
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - GC
Serves forest-wide searches and logons on port 3268 by holding a partial replica of every object. Where no global catalog exists at a site, universal group membership caching can fill in.
Related terms
- Active Directory Recycle Bin
Once switched on it can't be disabled, and it needs Windows Server 2008 R2 forest functional level or higher. Removed objects retain all attributes, so restoring them doesn't call for an authoritative restore.
- Allowed to Authenticate
When a trust is set to selective authentication, users from the trusted forest need this permission on the computer objects of resources they want to reach.
- AZUREADSSOACC
Seamless SSO adds this computer account to each synchronised forest. Microsoft Entra ID holds a copy of its Kerberos decryption key, so restrict management to Domain Admins and roll the key over no less often than every 30 days.
- Database 32k pages optional feature
Irreversible once enabled, and dependent on the Windows Server 2025 forest functional level, this option moves the AD database from 8k pages to 32k ones so multivalued attributes can grow larger.
- Default-First-Site-Name
Name given automatically to the first site in a new AD DS forest when its first DC is promoted; organisations frequently rename it after a real location.
- Enterprise Admins
Members of this built-in group, found only in the forest root domain, can change things that affect the entire forest, for example creating new domains.
- ESAE
An older design in which admin accounts lived apart in a hardened forest of their own. Microsoft has since stopped recommending it for most organisations, preferring its privileged access strategy and enterprise access model.
- Foreign security principal
Appears in AD when a user or group from an external trusted domain or forest is made a member of a local group, representing that outside account.