Domain hosted and managed in Azure that provides Kerberos, NTLM and LDAP. Its contents come from Entra ID, so no connection to on-premises is required.
Also called Azure AD DS, Azure Active Directory Domain Services, Azure AD Domain Services, Azure AD DS, Entra Domain Services.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AZ-900SC-900AZ-802
Each book explains Microsoft Entra Domain Services in context, with comparison tables and the common traps.
Terms in this definition
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- NTLM
NT LAN Manager, an older Windows challenge-response protocol available through Microsoft Entra Domain Services. Mounting Azure Files over SMB with a key relies on NTLMv2, so permitting Kerberos alone breaks such mounts.
- LDAP
Lightweight Directory Access Protocol, the standard way to bind to and query directories like Active Directory. In Azure it is provided by Entra Domain Services.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
Related terms
- AAD DC Administrators
Grants members admin rights over joined VMs and control of Group Policy for AADDC containers in an Entra Domain Services managed domain. Enterprise Admins and Domain Admins rights don't exist there.
- AADDC Computers
Container built into an Entra Domain Services managed domain, holding joined VMs' computer accounts, with a GPO of its own.
- AADDC Users
Container built into an Entra Domain Services managed domain, holding groups and users synchronised there, with a GPO of its own.
- AD DS
Short for Active Directory Domain Services, the domain controller-based Windows directory run on-premises. Microsoft Entra Domain Services offers a managed counterpart.
- Identity-based authentication
SMB access to Azure Files using identities from AD DS, Entra Domain Services or Entra Kerberos. SAS tokens play no part in SMB access.
- Identity subscription
Where workloads depend on AD DS domain controllers running in VMs, or on Microsoft Entra Domain Services, this is the platform subscription that runs them; it lives beneath the Identity management group.
- Replica set
The two domain controllers that Microsoft runs for Microsoft Entra Domain Services in one region. Further replica sets can be created in other regions to improve resilience.