Memory hook: DNS locates; replication shares; policy configures.
Must remember
- AD DS stores domain identities and directory configuration. Deploy domain controllers with reliable DNS, time and replication; an Azure VM domain controller still requires correct guest-level directory design.
- RODCs suit locations where physical security is limited; password replication policy controls which credentials may be cached. Do not treat every account as safe to cache on a branch RODC.
- FSMO roles handle specific single-master operations. Transfer roles during planned changes; seize only when the old holder cannot return safely under the required recovery process.
- Forest roles: Schema Master coordinates schema updates; Domain Naming Master coordinates domain naming changes. Domain roles: RID Master allocates relative-ID pools; PDC Emulator supports time/password and legacy coordination functions; Infrastructure Master maintains relevant cross-domain references. Do not memorize all five as forest-wide roles. Placement/recovery depends on the actual topology and supported guidance.
- Sites/subnets guide replication and client locality. Trust direction controls who can be authenticated across domains/forests; authentication through a trust does not automatically grant resource permissions.
- Choose group scope and nesting according to domain/forest access needs. Managed/group managed service accounts reduce manual service-password handling where supported; service permissions still require least privilege.
- Group Policy normally processes local, site, domain and OU settings with inheritance, filtering and enforcement affecting results. Preferences configure settings but are not always equivalent to enforced policy; use Resultant Set of Policy/gpresult to inspect actual application.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A branch has weak physical security | Evaluate an RODC with a restrictive password replication policy. |
| One user receives unexpected settings | Inspect applied GPOs, OU placement, filtering and inheritance. |
Traps
- A trust is an authentication path, not blanket authorization.
- Seizing an FSMO role is not the routine first step for a temporary network outage.
Active recall
1. What makes AD time important?
Kerberos authentication depends on acceptable clock skew.
2. Why define AD sites?
To represent network locality for replication and client/DC selection.
3. What does gpresult help show?
The policy results applied to a user/computer.
4. How reduce service-account password administration?
Use supported managed service accounts with appropriate permissions.
5. What should be checked before DC promotion?
DNS, connectivity, time, permissions, supported configuration and replication design.