Back

Understanding Active Directory - All Seven Types (Video)

In this Tech Talk Conrad Agramont Agile IT CEO discusses the seven types of Active Directory what to use them for and how they can be used togeth...

3 min read
Published on Mar 5, 2020
Understanding Active Directory - All Seven Types (Video)

In this Tech Talk, Conrad Agramont, Agile IT CEO, discusses the seven types of Active Directory, what to use them for, and how they can be used together to deliver solutions. Check out our earlier articles and tech talks on Active Directory:

Understanding Active Directory Licensing P1 and P2

Active Directory Health Checks  

The Shared Responsibility Model

ResponsibilityOn-PremIaaSPaaSSaaS
ApplicationsCustomerCustomerCustomerProvider
DataCustomerCustomerCustomerProvider
MiddlewareCustomerCustomerProviderProvider
NetworkingCustomerProviderProviderProvider
O/SCustomerCustomerProviderProvider
RuntimeCustomerCustomerProviderProvider
ServersCustomerProviderProviderProvider
StorageCustomerProviderProviderProvider
VirtualizationCustomerProviderProviderProvider

What is Active Directory?

Active Directory (AD), introduced in 1999 as part of Windows Server 2000, is a directory service based on Lightweight Directory Access Protocol (LDAP). AD is responsible for authenticating and authorizing all users and computers in a windows domain network.

  • People
    • Names
    • Numbers
    • Address
  • Services
    • Category
    • Names
    • Numbers
    • Address
    • Advertisement

The Types of Active Directories

There are technically 7 different types of Active Directory. Each of them are deployed in different way, places and for different purposes.

Active Directory TypeDeploymentModern?Purpose
Active Directory Federation Services (ADFS)ServerNoSingle Sign On (SSO) For Ad
Azure Active DirectoryCloudYesCloud Identity
Azure Active Directory Application ProxyCloudYesAzure AD enable legacy apps
Azure Active Directory ConnectServer-Sync AD and AAD
Azure Active Directory Connect Cloud ProvisioningServerYesSync AD and AAD (Limited)
Azure Active Directory Domain ServicesCloudYesCloud Hybrid Servers
Local AD (AD)ServerNoLocal Identity

Identity is Your Control Plane

Active Directory Control Plane

What is Local Active Directory (AD)

Purpose

  • Centralized administration for servers, workstations, users, and applications
  • Services (e.g. Exchange) can leverage for email services configuration

Deployment

  • Windows Server OS
  • Active Directory Domain Controllers

Limitations

  • Requires direct network connection
  • Reliance on customer managed networking: DNS, VPN, and Servers (Physical and Virtual)

What is Azure Active Directory (AAD)

Purpose

  • Centralized administration for cloud services
  • Services (e.g. Exchange) can leverage for email services configuration
  • Hybrid scenarios supported via Azure AD Connect connecting to local Active Directory
    • Use your corporate credentials/passwords

Deployment

  • Cloud Service

Limitations

  • Lack of IT protection without AAD P1 and P2 licensing
  • Device bases security requires EM+S licensing for Intune

What is Azure AD Connect Cloud Provisioning?

(Two versions, enterprise and standard, $60 vs $300, difference is number of objects) (Make table from slide)

What is Azure Active Directory Domain Services (AADDS)

Purpose

  • Local Active Directory (Fully compatible with Windows Server Active Directory)
  • Lift and Shift scenarios for Windows servers
    • Use your corporate credentials/passwords
    • NTLM and Kerberos authentication
  • Co-mingle local Active Directory users and Azure Active Directory users

Deployment

  • Cloud Service (Two domain controllers are available by IP only)
  • Highly available domain
  • Auto-remediation
  • Automatic backups

Limitations

  • Organizational Units are flat and not brought over from local AD/AAD
  • Not recommended for workstations
  • Administrators are NOT Domain Admins (it’s also a good thing)

Synced Tenants

What is Azure AD Application Proxy

Azure AD Application Proxy

Purpose

  • Publish on-premises web apps externally in a simplified way without a DMZ
  • Support single sign-on (SSO) across devices, resources, and apps in the cloud and on-premises
  • Support multi-factor authentication for apps in the cloud and on-premises deployment

Deployment

  • Requires Azure AD basic or premium (P1 or P2) subscription
  • Support Authentication: Integrated Windows Authentication (IWA), Header-based, forms, password-based SAML

Limitations

  • Connector must be installed on Windows Server 2102 R2 or higher, Windows 8.1 or higher
  • The on-premises firewall must be enabled for outbound traffic from the connector

Up Next? Getting Rid of Your Local Active Directory

As more and more organizations move more and more of their operations to the cloud, Local Active Directories are becoming redundant, and sometimes challenging pieces of infrastructure.  Last year, Agile IT took the leap, and removed our own Local Active Directory, and since then, have helped dozens of companies do the same. Conrad will be discussing the dangers, challenges and benefits to removing your own local active directory in an upcoming Tech Talk.

This post has matured and its content may no longer be relevant beyond historical reference. To see the most current information on a given topic, click on the associated category or tag.

Related Posts

Office 365 License Comparison: Business Plans Vs. E5, E3 and E1

Implementing Cybersecurity Policies for CMMC Compliance and Managing CUI

CMMC compliance requires well-documented cybersecurity policies. Learn how to implement security controls, create an SSP and POA&M, and manage Controlled Unclassified Information (CUI).

Apr 25, 2025
7 min read
CMMC compliance for DoD contractors

CMMC Compliance Requirements for DoD Contractors and Subcontractors in the Defense Industry

CMMC compliance is mandatory for DoD contractors and subcontractors. Learn about certification levels, requirements, and the consequences of failing to meet compliance.

Apr 24, 2025
6 min read
How to prepare for a CMMC compliance audit

CMMC Compliance Audit Preparation: A Complete Checklist for Small Businesses

Preparing for a CMMC compliance audit is critical for DoD contractors. Use this checklist to perform a gap analysis, assess CMMC readiness, and prepare for a Level 2 assessment.

Apr 23, 2025
8 min read
FAR CUI vs CMMC Understanding

FAR CUI vs CMMC Understanding the Differences and Overlaps

FAR CUI and CMMC both focus on protecting sensitive federal data, but they have key differences. Learn how they work together and whether FAR CUI compliance aligns with CMMC.

Apr 15, 2025
10 min read
What Is a POAM?

What Is a POAM?

Learn how a Plan of Action and Milestones (POAM) helps meet NIST 800-171 & DFARS compliance. Understand its role in FedRAMP, security categorization, and risk mitigation.

Apr 8, 2025
8 min read
Best Cybersecurity Practices for Achieving CMMC Compliance

Best Cybersecurity Practices for Achieving CMMC Compliance

Achieving CMMC cybersecurity compliance requires strong security controls. Learn best practices for securing your IT environment, protecting CUI, and implementing MFA.

Apr 7, 2025
6 min read

Ready to Secure and Defend Your Data
So Your Business Can Thrive?

Fill out the form to see how we can protect your data and help your business grow.

Loading...
Secure. Defend. Thrive.

Let's start a conversation

Discover more about Agile IT's range of services by reaching out.

Don't want to wait for us to get back to you?

Schedule a Free Consultation

Location

Agile IT Headquarters
4660 La Jolla Village Drive #100
San Diego, CA 92122

Secure. Defend. Thrive.

Don't want to wait for us to get back to you?

Discover more about Agile IT's range of services by reaching out

Schedule a Free Consultation