AD Domain Services (AD DS) gives an organization ways to store directory data and make it available to standard users and admins on the network. Stores information such as usernames and passwords and manages the right needed for authorized users.

AD Structure

Forests are “containers” of separate domains, users, computers, and other objects all under the same umbrella. AD is a hierarchical database that every user can access regardless of privilege. A basic user can enumerate:

Domain ComputersDomain Users
Domain Group InformationOrganizational Units (OUs)
Default Domain PolicyFunctional Domain Levels
Password PolicyGroup Policy Objects (GPOs)
Domain TrustsAccess Control Lists (ACLs)
  • Arranged in hierarchical tree structure, with a forest at the top containing one or more domains (which can also have subdomains themselves).
    • A domain is a structure within which objects (users, computers, groups) are accessible.
    • Domains have Organizational Units (OU)
INLANEFREIGHT.LOCAL/
├── ADMIN.INLANEFREIGHT.LOCAL
│   ├── GPOs
│   └── OU
│       └── EMPLOYEES
│           ├── COMPUTERS
│           │   └── FILE01
│           ├── GROUPS
│           │   └── HQ Staff
│           └── USERS
│               └── barbara.jones
├── CORP.INLANEFREIGHT.LOCAL
└── DEV.INLANEFREIGHT.LOCAL
  • Different domains can have trust relationships (e.g. a company acquires another and needs to absorb the directory)

Directory Terms

TermDescription
AttributesEvery object is associated with an attribute to define the characteristics of that given object. These have an LDAP name associated for LDAP queries like displayName gives Full Name
SchemaSchema is the blueprint of an enterprise environment.
GUIDA global unique Identifier (GUID) is 128-bit value assigned when a domain user or group is created. It is unique across the enterprise.
Security principalsSecurity principles (in AD) are domain objects that can manage access to other resources within the domain. Managed by the Security Accounts Manager (SAM). These are users, groups, and computers that are granted permissions on resources. Each principle is represented by a SID.
SIDSecurity Identifier (SID) is a unique identifier for a security principal or security group.
DNDistinguished Name (DN) describes the full path to an object in the AD (cn=bjones, ou=IT, ou=employees, dc=inlanrfreight, dc=local)
RDNRelative Dstinguished Name (RDN) is a single component of a DN that identifies the object in question at the current level in the naming hierarchy.
samAccountNamesamAccountName is the user’s logon name
userPrincipleNameuserPrincipleName is another way to identify the users in AD. Composed of prefix (user account name) and a suffix (domain name) bjones@inlanefreight.local.
FSMOFlexible Single Master Operations (FSMO) roles give DCs the ability to continue authenticating and granting perms without interruptions. Help replication in AD to run smoothly.
Global CatalogGlobal Catalog (GC) is a domain controller that stores all objects in an Active Directory forest.
RODCRead-Only Domain Controller (RODC) has a read-only AD database.
ReplicationReplication happens in AD when AD objects are updated and transferred from one DC to another.
SPNService Principle Name (SPN) uniquely identifies a service instance. Used by Kerberos auth to associate an instance of a service with a logon account.
GPOGroup Policy Object (GPO) are collections of policy settings. Each GPO has a GUID. “how systems and users should be configured”
ACLAccess Control List (ACL) is the ordered collection of access control entries (ACEs) that apply to a specific object. “who can access this object and how”
ACEan Access Control Entry (ACE) in an ACL identifies a trustee (user account, group account, or logon session) and lists the access rights that are allowed, denied, or audited. The SID appears in ACEs.
DACLDiscretionary Access Control List (DACL) defines which security principles are granted or denied access to an object. If no DACL exists, everyone has access full access to the object. It’s the part of the ACL that controls access.
SACLSystem Access Control List (SACL) allows for admins to log access attempts that are made to secured objects.
FQDNFully Qualified Domain Name (FQDN) is the complete name for specific computer or host. [host name].[domain name].[tld] used to find object location in tree hierarchy or DNS. e.g. DC01.INLANEFREIGHT.LOCAL
TombstoneTombstone is a container object in AD that holds deleted AD objects. Remains for a set period of the Tombstone Lifetime. Works only if Recycle bin is not enabled. Most attributes are stripped.
AD Recycle BinAD Recycle Bin is where any deleted objects are preserved for a period of time.
SYSVOLSYSVOL folder or shares stores copies of public files in the domain such as system policies, Group Policy settings, logon/logoff scripts etc. It is replicated to all DCs within the environment using File Replication Services (FRS)
AdminSDHolderAdminSDHolder objects is used to manage ACLs for members of built-in groups in AD marked as privileged. Managed via SDProp process that runs on a schedule on the PDC Emulator Domain Controller that checks members of protected groups to ensure that the correct ACL is applied to them. If an attacker creates an ACL to grant a user rights over a member of the Domain Admins Groups, these rights will be removed by SDProp unless they modify other settings within the AD.
dsHeuristicsdsHeuristics attribute is a string value on the Directory Service object that defines forest-wide configuration settings. it can exclude built-in groups from the Protected Groups list. Protected Groups are protected via the AdminSDHolder object. If a group is excluded from the dsHeuristics then any changes will not be reverted by the SDProp
adminCountadminCount attribute determines whether or not the SDProp process protects a user.
sIDHistorysIDHistory holds any SIDs that an objects was assigned previously,
NTDS.DITNTDS.DIT is the heart of the AD. It is stored at C:\Windows\NTDS and is a database that stores AD data like user and group objects, group membership and password hashes.
MSBROWSEMSBROWSE is an older networking protocol that maintains a list of shared printers and files.
RIDRelative Identifier (RID) is the last part of a SID unique to only the domain. AD assigns new RID when you create a new object.

Types of Objects

An object can be any resource present within the AD

ObjectDescription
UsersUsers are leaf objects so cannot contain any other objects within them. Has a SID and GUID; can have over 800 possible user attributes.
ContactsContacts (leaf objects) represent an external user and contains information attributes like name, email address. Do not contain security principals.
ComputersComputers are leaf objects, have their own security principals and SID and GUID
Shared foldersShared Folders object points to a shared folder on the specific computer where the folder resides. Can be locked down so only specific users can access it. They do not have security principals but have a GUID.
GroupsGroups is a container object because it can contain other objects like users, computers and other groups (nested groups). A group is a security principal and has a SID and GUID. Used to assign permissions and access. Does not contain or manage GPOs
Organizational UnitsOrganizational Units (OUs) is a container that system admins can use to store their similar objects for ease of administration. Used for administrative structure. An example would be a top-level OU called Employees with child OUs like marketing, HR, finance, etc.
Built-inBuilt-in is a container that holds default groups in AD domain.
Foreign Security PrincipalForeign Security Principal is an object created in AD to represent a security principal that belong to a trusted external forest. Used when an object from an external forest is added in the current domain.

FSMO Roles

RolesDescription
Schema MasterThis role manages the read/write copy of the AD schema, which defines all attributes that can apply to an object in AD.
Domain Naming MasterManages domain names and ensures that two domains of the same name are not created in the same forest.
Relative ID (RID) MasterThe RID Master assigns blocks of RIDs to other DCs within the domain that can be used for new objects. The RID Master helps ensure that multiple objects are not assigned the same SID. Domain object SIDs are the domain SID combined with the RID number assigned to the object to make the unique SID.
PDC EmulatorThe host with this role would be the authoritative DC in the domain and respond to authentication requests, password changes, and manage Group Policy Objects (GPOs). The PDC Emulator also maintains time within the domain.
Infrastructure MasterThis role translates GUIDs, SIDs, and DNs between domains. This role is used in organizations with multiple domains in a single forest. The Infrastructure Master helps them to communicate. If this role is not functioning properly, Access Control Lists (ACLs) will show SIDs instead of fully resolved names.

Trusts

Used to establish forest-forest or domain-domain authentication. A trust creates a link between the authentication systems of two domains.

Trust TypeDescription
Parent-childDomains within the same forest. The child domain has a two-way transitive trust with the parent domain.
Cross-linka trust between child domains to speed up authentication.
ExternalA non-transitive trust between two separate domains in separate forests which are not already joined by a forest trust. This type of trust utilizes SID filtering.
Tree-roota two-way transitive trust between a forest root domain and a new tree root domain. They are created by design when you set up a new tree root domain within a forest.
Foresta transitive trust between two forest root domains.

AD Federation Services

AD Federation Services (ADFS) provide SSO to systems and application for users on Windows Server operating systems. Uses claims-based Access Control Authorization model, identifies users by a set of claims related to their identity that are packaged into a security token by the identity provider.

Group Managed Service Accounts

Group Managed Service Accounts (gMSA) is a secure way of running automated tasks, apps and services that mitigates Kerberoasting.