Terminus Expanse
CurriculumBlogPricingSign in
Back to dispatches
guideswindowsAug 17, 2026

Active Directory, explained: what it actually is and why almost every office network has one

Terminus Expanse

The problem Active Directory solves

Picture a company with 400 employees, each with a laptop, and each laptop needing to know the same set of things: who's allowed to log in, which shared folders they can reach, which printer is nearby, and whether their password just expired. Doing that one machine at a time — walking around creating 400 local accounts, one per laptop — doesn't scale past about a dozen computers before it becomes unmanageable. Active Directory is Microsoft's answer to that problem: a central database of every user, computer, and group in an organization, plus a protocol that lets every Windows machine on the network ask that database "who is this person, and what are they allowed to do?" instead of keeping its own separate answer.

The pieces that make it work

At the center sits a domain controller — a Windows Server machine running Active Directory Domain Services, holding the actual database (technically called the directory) of every account and its properties. When an employee's laptop starts up and they type their password, the laptop doesn't check that password against anything stored locally; it sends an authentication request to a domain controller, which checks the password against the central directory and replies with a ticket proving who they are. That laptop is said to be "joined to the domain," and from that point on, logging in, accessing shared drives, and printing all rely on that same central proof of identity rather than anything configured locally.

Accounts and computers aren't just a flat list — they're organized into Organizational Units (OUs), which work like folders for grouping related objects: an OU for the Sales department, one for Finance, one for IT-managed laptops. OUs matter because they're the unit that policy gets applied to, which brings in the second core piece: Group Policy. A Group Policy Object (GPO) is a bundle of settings — "lock the screen after 10 minutes of idle," "block USB drives," "install this print driver automatically" — that gets linked to an OU and then applied automatically to every account or computer inside it, the moment they connect to the domain. This is the actual mechanism behind something every office worker has experienced: starting a new job, logging into a company laptop for the first time, and finding the wallpaper, security settings, and mapped network drives already configured, without anyone touching that specific machine by hand.

Why "domain" is the word that matters

A domain is the boundary of one Active Directory database — one set of users, one set of policies, one namespace like corp.example.com. Larger organizations often have multiple domains linked together into a forest, usually because different divisions need separate administrative control (a subsidiary company, a different country's IT team) while still needing some trust between them — an employee from one domain being able to access a shared resource in another, for instance. Understanding domains and forests is really understanding administrative boundaries: who's responsible for managing which set of accounts, and how much those separate boundaries are allowed to trust each other.

Authentication, the part that actually keeps things secure

Modern Active Directory environments authenticate using a protocol called Kerberos, and it's worth knowing roughly how it works because so much of AD security terminology assumes you do. When you log in, the domain controller doesn't just say "yes, correct password" — it issues you a Ticket Granting Ticket (TGT), a time-limited, cryptographically signed proof that you successfully authenticated, without your password ever being sent again after that first exchange. From then on, whenever you need to access something else on the network — a file server, a database, an internal website — your computer presents that TGT to get a separate, specific ticket for that exact resource, rather than re-entering your password every time. This is why, once you're logged into a domain-joined Windows machine in the morning, you can move between a dozen internal systems all day without a single additional password prompt: Kerberos is quietly handling authentication behind the scenes using the ticket you were issued at login.

What actually goes wrong, and why it matters

The overwhelming majority of real-world Windows network breaches don't start with someone cracking Active Directory's cryptography — they start with a single compromised low-privilege account, followed by lateral movement: using that first foothold to discover which other accounts and machines it can reach, then repeating that process account by account until something with high enough privilege — often Domain Admin, the account that can do essentially anything in the domain — gets compromised. This is exactly why real-world AD security work focuses so heavily on the structure of permissions: minimizing how many accounts have broad privileges, keeping administrative accounts separate from everyday-use accounts, and auditing which groups can actually reach which resources — because a domain with 5,000 users and only 3 people who can become Domain Admin is fundamentally harder to compromise than one where "IT support" as a whole group has that power, even if every individual password in both scenarios is equally strong.

Why this is worth learning even if you're not a Windows specialist

Active Directory (or its cloud sibling, Microsoft Entra ID, formerly Azure AD) runs the login for the overwhelming majority of corporate laptops on the planet — it's not a niche skill, it's closer to a universal fact about how offices work. Understanding domains, OUs, Group Policy, and Kerberos means understanding why a company laptop behaves the way it does: why IT can push a security update to every machine overnight, why losing network access to the domain controller can lock everyone out at once, and why "Domain Admin" is the single most closely guarded set of credentials in most corporate IT departments.