Active Directory Explained: Forests, Domains, OUs & Objects

Technology Fundamentals

Active Directory Explained: Forests, Domains, OUs & Objects

1 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

Active Directory Domain Services (AD DS) is the identity backbone of most Windows organisations. If you support Windows, you support Active Directory.

Interactive explainer

Active Directory Domain Services

How Windows organises and secures an entire organisation.

11. Forest & domain22. Domain controllers33. Organisational Units44. Objects & attributes

Tap or hover a part to learn more.

1. Forest & domain

The top of the tree.

Active Directory Domain Services (AD DS) organises an organisation into a forest (the top-level security boundary) containing one or more domains. A domain is an administrative and authentication boundary — e.g. corp.example.com.

Check your understanding

1. What is the top-level security boundary in Active Directory?

2. What are Organisational Units (OUs) primarily used for?

Practise this in AI Interview™

Forest, domain, OU

A forest is the top-level security boundary. Inside it, one or more domains act as authentication and administrative boundaries. Within a domain, Organisational Units (OUs) organise objects so you can delegate administration and target Group Policy. Crucially, OUs are for management structure — they are not security groups.

Domain controllers

Domain Controllers (DCs) run Active Directory, hold the AD database and authenticate users and computers. You always run at least two for redundancy; they multi-master replicate changes between each other so there is no single point of failure.

Objects, groups and permissions

Every user, computer and group is an object with attributes. Access is granted to security groups, and users inherit permissions through group membership — the foundation of role-based access and least privilege. Add users to groups; never grant access per-user.

Where this leads

Active Directory underpins Windows Authentication, Group Policy and LDAP. It's assumed knowledge for CompTIA Security+ and every Microsoft pathway.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

AD is the first thing most Windows roles touch. Employers check you understand its structure so you can be trusted to manage users, computers and access.

Technical questions
Explain the difference between a forest, a domain and an OU.+

A forest is the top security boundary; a domain is an authentication/admin boundary within it; an OU organises objects for delegation and Group Policy.

How do users get their permissions in AD?+

Through security group membership — you permission groups and add users to them, applying least privilege.

Behavioural questions
Tell me about a time you tidied up user accounts or access.+

Use STAR: the mess you found, the group/OU structure you introduced, and the reduced risk/permission creep as the result.

Real-world scenarios
“A new starter needs the same access as their team.”+

Expected answer: Add them to the team's security group rather than copying permissions individually — consistent, auditable and least-privilege.

Common misconceptions

What candidates get wrong in interviews and on the job — and what strong professionals actually do.

Myth

'OUs control permissions.'

Reality

OUs organise objects and target policy; security groups control permissions.

Myth

'One DC is fine.'

Reality

production always runs at least two for resilience.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
Help DeskSystems AdministratorSOC Analyst
Skills you're proving
Active DirectoryIdentityLeast privilege
Recommended certifications
Career progression

Help Desk → Sysadmin → Infrastructure/Security Engineer.

What employers expect

That you can manage AD objects safely and understand the security implications.

Frequently asked questions

Is an OU the same as a security group?

No. An OU organises objects for administration and Group Policy; a security group is what you grant permissions to.

Why run more than one domain controller?

For redundancy and load. DCs multi-master replicate, so if one fails authentication continues.

What is a forest?

The top-level security boundary in Active Directory, containing one or more domains.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.