Trust is earned, not given

A different perspective

2016-09-08 · Projects

Windows domains, part 2: AD 2000 changed everything — forests, trees, and transitive trust

Part 2from the Windows domains series · 6 parts in all

When Windows 2000 shipped Active Directory, it did not upgrade the NT domain — it replaced its geometry. Three ideas did most of the work, and all three are still with us in Windows Server 2025.

One: the directory became a real database with multimaster writes

AD stores objects in NTDS.dit, an ESE (Jet) database, replicated by multi-master replication: every domain controller is writable for most attributes, changes propagate by (mostly) choosing the newest version, and the KCC topology engine keeps the replication graph connected. The five operations that genuinely need a single writer — schema changes, new domains, PDC-emulator fallback for NT clients, relative ID (SID) allocation, and cross-domain group membership visibility — became the five FSMO roles instead of five PDCs.

Two: transitive trusts collapsed the maze

AD trusts within a tree are Kerberos-based, two-way, and transitive: if A trusts B and B trusts C, A trusts C automatically. A tree is a contiguous namespace (americas.maplecart.com, emea.maplecart.com); a forest is one or more trees sharing one schema, one configuration partition, and one Global Catalog. The forest — not the domain — is the security boundary, which is why "should this be a new forest?" remains the most consequential question in every AD design review. Short-cut trusts (selective authentication, forest trusts with name-suffix routing) came later, but the default geometry stopped needing hand-drawn paths.

Three: delegation and policy moved below the domain

Organizational Units gave administrators nested containers to delegate with ACLs and to receive Group Policy objects — the "another domain for the helpdesk" problem simply evaporated. Group Policy replaced system-policy files with a real precedence engine (LocalSiteDomainOU-then-out), and the Global Catalog made "find the user's groups corporation-wide" a one-LDAP-query affair.

:: the AD vocabulary, as seen from a healthy domain controller
repadmin /replsummary          :: multimaster replication health at a glance
netdom query fsmo              :: the five single-master roles and where they live
dsquery server -isgc           :: which DCs currently carry the Global Catalog
dsget user "CN=bh,CN=Users,DC=maplecart,DC=local" -memberof

:: OUs replaced resource-domain sprawl: delegate and link policy instead
dsadd ou "OU=Workstations,DC=maplecart,DC=local"

What we gave up

Complexity moved rather than vanished. Replication needs sites and subnets to be declared honestly; the schema is forest-wide and forever (attributes cannot be deleted, only deactivated); and any DC compromise endangers the whole domain, since anyone who can touch NTDS.dit can extract every account's secrets. Part 3 zooms into the wire protocol that made the new geometry safe to trust: Kerberos — and its stubborn co-tenant, NTLM.

Next: how Windows actually proves who you are.