Windows Server

What are Active Directory Forest, Trees, Domain, and Sites

Active Directory (AD) is a directory service developed by Microsoft for the Windows domain environment. Active Directory forest is the top container in an Active Directory setup that contains domains, users, computers, and group policies. The Active Directory structure is built on the domain level. The framework that holds the objects can be viewed at different levels namely forest, domain trees, and domains. An Active Directory framework can have more than one domain, and the above tiers are referred to a forest. See the following guides for other information. What are the differences between Universal, Global, and Domain Local Group Scopes, and Differences between Active Directory Lightweight Directory Services and Active Directory Domain Services, What are Active Directory Forest, Trees, Domain, and Sites, and how to add a second Domain Controller to your environment?

Note: Under each domain, you can have as many trees as possible. Having an Active Directory environment of this nature can create autonomy and segregation of duty thereby increasing security and if not configured correctly, it can also lead to exploitation in the Active Directory environment.

Within a deployment, objects are grouped into domains as shown in the below diagram. The objects for a single domain are stored in a single database (which can be replicated). Domains are identified by their DNS name structure, (namespace).

Forest: A forest is a collection of trees that share a common global catalog, directory schema, logical structure, and directory configuration. The forest represents the security boundary within which users, computers, groups, and other objects are accessible. A forest is a collection of one or more domains which may have one or more trees. What makes a forest unique is that it shares the same schema. The schema defines what and how Active Directory objects are stored.
– A forest is a group of trees that do not share a contiguous namespace.

Domain: A domain is defined as a logical group of network objects (computers, users, devices) that share the same Active Directory database.
– When you add a domain to an existing tree, the new domain is a child domain of an existing parent domain.

Tree: A tree is a collection of one or more domains and domain trees in a contiguous namespace, and is linked in a transitive trust hierarchy. When you have multiple domains in the same namespace (e.g., techdirect.local, zone.techdirect.local), they are considered to be in the same tree. The tree also supports multiple levels of domains.
– A tree is a hierarchical arrangement of Windows domains that share a contiguous namespace.

Some other information to note
– Parent and child domains are automatically linked by a trust. Users in different domains can use these trusts to access resources in another domain assuming that they have access. Trees in the forest are linked together via a trust automatically. This ensures that any users in any domain in the forest can access any resource in the forest to which they have access.

  • Global Catalog In order for users to find resources in any domain in the forest (remember that each domain has a separate database), Domain Controllers can be made into Global Catalog Servers. A Global Catalog Server contains partial information about every object in the forest. Using this information, the user can conduct searches.
  • Trust relationship: A logical relationship established between domains that allow pass-through authentication, providing for users in a trusted domain to access resources in a trusting domain, without having a user account in the trusting domain.
  • Organizational units (OU) are containers that hold other Active Directory objects like users, computers, printers, shared folders, and even other organizational Units. The advantage of OU is that it can be used to set security policies and delegate administrative control.
Reasons to create Additional domain: There will be many occasions in which you will need to create additional domains. Multiple domains are useful when you are dealing with
- Different password requirements between organizations
- Large numbers of objects
- Different internet domain names
- Better control of replication
- Decentralized network administration

In order for you to decide whether to create multiple domains and how to use them to best effect, you need to have a clear understanding of the relationship between trees and forests-known as a trust relationship.
The Slide show below will explain to you the workings of the trust relationship.

While forests, trees, domains are all logical grouping of objects, the physical grouping of objects is made possible using a site.

A site group objects based on IP addresses. Hence it cannot span across different physical locations. For example, if there are various branches of your organization located at different places, each location can be identified using a site. A site is mainly used for replication and traffic control purposes. It is important to understand that site and domains are not interrelated. A site can contain multiple domains and a single domain could span across multiple sites.

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

Notify of
1 Comment
Inline Feedbacks
View all comments
1 month ago

Hi Christian, This is a great article. Can you explain a bit more about your last comment with examples: “It is important to understand that site and domains are not interrelated. A site can contain multiple domains and a single domain could span across multiple sites.

Would love your thoughts, please comment.x
Kindly subscribe to TechDirectArchive
This is default text for notification bar