如需獲得最佳網頁瀏覽體驗,請使用 IE 11 或更高版本、Chrome、Firefox 或 Safari。

Active Directory是什么?


Dive into Active Directory 02:25

Active Directory (AD)是一个数据库和一组服务,可将用户与其完成工作所需的网络资源关联起来。



继续阅读,了解有关Active Directory益处的详细信息,其工作原理,以及Active Directory数据库中包含的内容。

Active Directory的益处

Active Directory可简化管理员和终端用户的工作,同时增强组织的安全性。管理员可以享受集中化的用户和权限管理,以及通过AD组策略功能对计算机和用户配置进行集中控制。用户只需进行一次身份验证,然后便可无缝访问域中其已获授权的任何资源(单一登录)。此外,文件存储在中心数据库中以供与其他用户共享,从而实现轻松协作,而且可以由IT团队正确进行备份以确保业务连续性。

Active Directory工作原理

Active Directory工作原理

Active Directory主服务是Active Directory域服务(AD DS),这是Windows Server操作系统的一部分。运行AD DS的服务器称为域控制器(DC)。组织通常具有多个DC,并且每个DC具有整个域的目录的副本。在一个域控制器内对目录进行的更改(例如更新密码或删除用户帐户)会复制到其他DC,使它们保持最新。全局目录服务器是一个DC,用于存储其域的目录中所有对象的完整副本以及林中其他所有域的所有对象的部分副本;这使用户和应用程序可以找到其林的任何域中的对象。运行Windows(而不是Windows Server)的台式机、笔记本电脑和其他设备可以是Active Directory环境的一部分,但不运行AD DS。AD DS依赖多个既定的协议和标准,包括LDAP(轻型目录访问协议)、Kerberos和DNS(域名系统)。

务必要了解的是,Active Directory仅适用于内部部署的Microsoft环境。云中的Microsoft环境使用Azure Active Directory,其与内部部署环境中的同名目录具有相同的用途。AD和Azure AD是彼此独立的,但是如果贵组织同时具有内部部署和云IT环境,则可以使它们在一定程度上协同工作(混合部署)。

Active Directory的结构如何?

Active Directory的结构如何?



什么是Active Directory数据库?

什么是Active Directory数据库?

Active Directory数据库(目录)包含有关域中AD对象的信息。常见类型的AD对象包括用户、计算机、应用程序、打印机和共享文件夹。某些对象还包含其他对象(因此您将看到以“层次结构”形式描述的AD)。尤其是,组织通常通过将AD对象组织到组织单位(OU)中来简化管理,并通过将用户分到组中来简化安全性。这些OU和组本身就是存储在目录中的对象。


数据库是结构化的,这意味着存在某种设计用来确定存储的数据类型以及数据的组织方式。该设计称为架构。Active Directory也不例外:其架构包含可在Active Directory林中创建的每个对象类的正式定义,以及Active Directory对象中存在的每个属性。AD附带默认架构,但是管理员可以对其进行修改以符合业务需求。要了解的关键之处在于,最好提前仔细规划好架构;因为AD在身份验证和授权方面具有核心地位,以后更改AD数据库的架构会严重影响您的业务。

我可以从何处详细了解Active Directory?

我可以从何处详细了解Active Directory?

Active Directory对于各种现代企业取得成功都至关重要。查看这些附加实用页面,以了解Active Directory关键领域的最佳做法:


On-Demand Webcast: Best Practices to Avoid Common Active Directory Migration Mistakes
On-Demand Webcast: Best Practices to Avoid Common Active Directory Migration Mistakes
On-Demand Webcast: Best Practices to Avoid Common Active Directory Migration Mistakes
Mergers, acquisitions, and divestitures are common business activities that can have a huge impact on your Microsoft 365 tenant. These events come with complicated legal maneuvers and rigid timelines.
Colonial Pipeline Ransomware and MITRE ATT&CK Tactic TA0040
Colonial Pipeline Ransomware and MITRE ATT&CK Tactic TA0040
Colonial Pipeline Ransomware and MITRE ATT&CK Tactic TA0040
Ransomware attacks are exploiting Active Directory. This security-expert-led webcast explores a 3-prong defense against them.
M&A IT Integration Checklist: Active Directory
M&A IT Integration Checklist: Active Directory
M&A IT Integration Checklist: Active Directory
If your organization is involved in a merger and acquisition, the impending IT integration project might seem overwhelming.
Nine Best Practices to Improve Active Directory Security and Cyber Resilience
Nine Best Practices to Improve Active Directory Security and Cyber Resilience
Nine Best Practices to Improve Active Directory Security and Cyber Resilience
This ebook explores the anatomy of an AD insider threat and details the best defense strategies against it.
Five Ways to Secure Your Group Policy
Five Ways to Secure Your Group Policy
Five Ways to Secure Your Group Policy
Discover how to dramatically improve security by ensuring proper GPO governance.
Four Best Practices for Hybrid Active Directory Group Management
Four Best Practices for Hybrid Active Directory Group Management
Four Best Practices for Hybrid Active Directory Group Management
Tired of best practices guides that explain what to do and why to do it, but not how to actually get it done? This e-book is different. It lays out four of the most fundamental security best practices for any on-prem or hybrid Microsoft shop — and explains the top tools and techniques for impl
TEC TALK - Office 365 & Azure Active Directory Security | Quest
TEC TALK - Office 365 & Azure Active Directory Security | Quest


TEC TALK - Office 365 & Azure Active Directory Security | Quest

Learn how to prioritize Office 365 & Azure AD security for your remote workforce in this TEC Talk presented by Microsoft Certified Master, Sean Metcalf.

5 Quick Tips for an Efficient Active Directory Administration
5 Quick Tips for an Efficient Active Directory Administration
5 Quick Tips for an Efficient Active Directory Administration
Microsoft’s Active Directory is critically important to the health of your network and must be properly maintained. Without the proper tools, however, maintaining your Active Directory efficiently will be overwhelming and difficult.Luckily, Active Administrator from Quest can help make you fas


The anatomy of Active Directory attacks

The anatomy of Active Directory attacks

Learn the most common Active Directory attacks, how they unfold and what steps organizations can take to mitigate their risk.

8 ways to secure your Active Directory environment

8 ways to secure your Active Directory environment

Taking the right steps to secure your Active Directory has never been more critical. Learn 8 Active Directory security best practices to reduce your risk.

Active Directory forest: What it is and best practices for managing it

Active Directory forest: What it is and best practices for managing it

Active Directory forest is a critical — but often underappreciated — element of the IT infrastructure. Learn what it is and how to manage it.

Active Directory disaster recovery: Creating an airtight strategy

Active Directory disaster recovery: Creating an airtight strategy

Businesses cannot operate without Active Directory up and running. Learn why and how to develop a comprehensive Active Directory disaster recovery strategy.

5 Active Directory migration best practices

5 Active Directory migration best practices

Active Directory delivers key authentication services so it’s critical for migrations to go smoothly. Learn 5 Active Directory migration best practices.

Active Directory security groups: What they are and how they improve security

Active Directory security groups: What they are and how they improve security

Active Directory security groups play a critical role in controlling access to your vital systems and data. Learn how they work.


成功管理AD – IT环境的核心。