Active Directory Database Structure
Active Directory Database Structure
Database File
: Ntds.dit
DIT
Default Path
: \Windows\ntds\ntds.dit
a) Schema Partition
b) Configuration Partition
c) Domain partition
SCHEMA PARTITION
It contains the object class and attributes. And also contains the source template
for the creation of the domain objects. Throughout the entire forest the same
schema will maintained. Schema admin only has the full control to edit the
schema partition. This schema is created during the root DC. Tool used to edit
this is Active directory schema.
DOMAIN PARTITION
Domain partition contains the entire domain objects like user accounts,
passwords, and group objects membership information. Each and every domain
has its own domain partition because it is entirely different compared to other
domain.
CONFIGURATION PARTITION
It contains the configuration parameters of the forest like how many trees,
domains and its names, global catalog, sited and names, trust relationship Etc.
Throughout the entire forest the same configuration partition will maintain. By
default it is in root DC. Enterprise admin has the full control over this partition.
APPLICATION PARTITION
Application partition is only available in windows 2003.It contains the information
about the active directory integrated applications like DNS, authorized DHCP
information .etc
PERMISSIONS
Schema partition
o
Configuration Partition
Enterprise admin has the permission over this partition
o
Tool used is active directory domain and trusts, active directory sited
and services
Domain Partition
o
NOTE:
ROOT DC - All the three partitions schema, configuration and domain partitions is in
R/W mode.
Schema master
Domain Naming master
PDC Emulator
RID master
Infrastructure master
SCHEMA MASTER
a) Responsible for maintaining schema partition in AD database
b) Responsible for creation, deletion, modification and extending of entries in
schema partition of AD database
c) Schema master contains read write copy of schema partition
Only the users from the root domain will be the member of schema admin. By
default administrator will be the member
INFRASTRUCTURE MASTER
a) It is a domain wide role
b) It is Responsible for interchanging the domain infrastructure information to the
other domain (E.g.) AGDLP strategy
ntds.dit
edb.chk
edb.log
res1.log
res2.log
3) edb.log -
logged.
It is a extensive database transaction log file. Minimum and
Maximum log file size is 10 MB. We cannot able to access the file
only Engine has the permission. Once the 10 MB is full it will be
rename a Automatically.
4) res1.log & res2.log - For reserving 20 MB free space when the HDD run out of
disk space.