Active Directory  «Prev  Next»
Lesson 1

Active Directory Logical Structure

Active Directory is Microsoft's implementation of the X.500 directory service recommendations (X.500 is a series of ITU-T networking standards covering electronic directory services), providing the structure and functions for organizing, managing, and controlling network resources across a Windows Server environment. At its core, Active Directory is a centralized database and a common administrative interface built on the Microsoft Management Console (MMC), enabling administrators to manage users, computers, groups, policies, and network resources from a single point of control.

Active Directory communicates using the Lightweight Directory Access Protocol (LDAP — LDAPv3, RFC 4511 — is the primary access protocol for Active Directory), providing interoperability with other directory services and enabling a wide range of applications and platforms to authenticate against and query the directory. While the core logical structure of Active Directory has remained consistent across Windows Server versions through Windows Server 2022, modern deployments increasingly extend into hybrid cloud environments through Microsoft Entra ID (formerly Azure Active Directory), which provides cloud-based identity and access management alongside on-premises Active Directory.

This module introduces the logical structure of Active Directory. By the end of this module you will have a clear understanding of how the directory is organized, how administrative authority is delegated, and how the logical components of Active Directory fit together to support enterprise network administration.

From Peer-to-Peer Networks to Directory-Based Networks

Since the inception of network operating systems, administrators have needed an efficient way to manage network resources at scale. Networks evolved naturally from peer-to-peer architectures, in which each machine managed its own resources independently, to directory-based networks, in which a centralized directory service provides a unified view of all resources across the network. Directory-based networks became the preferred architecture because they reduce administrative workload, enforce consistent policy, and scale to the size of large enterprise environments.

To define how a directory service should be structured and how it should address the needs of administrators, the Institute of Electrical and Electronics Engineers (IEEE) developed the X.500 recommendations — a set of standards originally envisioned to encompass a large centralized directory spanning the entire world, divided by geopolitical boundaries. While the full X.500 Directory Access Protocol (DAP) stack proved too complex for widespread adoption, the core concepts were retained and implemented via LDAP over TCP, which became the practical standard for directory services. Active Directory, OpenLDAP, and Microsoft Entra ID all use LDAP-over-TCP as their primary access mechanism rather than the original X.500 DAP.

Multiple vendors adopted the X.500 recommendations and built directory services around them. Microsoft's implementation — Active Directory — became the dominant enterprise standard and has been adopted by organizations of all sizes worldwide. The core logical structure it introduced: domains, organizational units, trees, and forests, remains the foundation of Windows Server network administration today.

Module Learning Objectives

In this module, you will learn how to:

  1. Describe the role of Active Directory in Windows Server
  2. Describe the internet standards and technologies supported by Active Directory, including LDAPv3 (RFC 4511), Kerberos authentication, and DNS integration
  3. Describe the naming conventions in Active Directory that must be considered when establishing a Windows network
  4. Describe the logical structure of Active Directory
  5. Define the role of domains
  6. Define the role of organizational units (OUs)
  7. Define the relationship between trees and forests

In the next lesson you will learn the structure and elements of Active Directory as well as its relationship to other tools of network administration.


SEMrush Software 1 SEMrush Banner 1