What is Active Directory partitions

Hello all,

Hope this post finds you in good health and spirit.

This post is regarding active directory partitions or directory naming contexts

Active directory database is divided into logical parts and each part is known as Naming context or AD partition. there are three naming contexts:- Schema, configuration and domain naming context.

Schema partition

The schema partition contains object and attribute definitions. In other words, the schema partition contains a list of definitions that define what objects and attributes for those objects can exist in the Active Directory. Schema information is enterprise in nature—all domain controllers in a tree or forest share a common schema and any schema modifications are replicated across the forest. Because the schema defines objects and attributes, an object that is created, along with it’s attributes, must conform to the definitions of the schema.

Configuration partition

The configuration partition contains information about the physical structure of the Active Directory, such as the sites and domains and where domain controllers reside in the enterprise. Configuration information is replicated to all domain controllers in the tree or forest.

Domain Partition

The domain partition contains information about all Active Directory objects that are specific to that domain, such as users and groups, OUs, and other resources. All domain partition information is completely replicated to all domain controllers within the domain. For global catalog servers in other domains, a read-only subset of the domain partition is replicated. This allows the global catalog server to know what is available in each domain so that other domain users can access resources, but changes to the domain partition can only be made from within the domain.

So, that’s all in this blog. I will meet you soon with next stuff .Have a nice day !!!

Guys please don’t forget to like and share the post. You can also share the feedback on below windows techno email id.

If you have any questions feel free to contact us on  also follow us on facebook@windowstechno to get updates about new blog posts.

What is Active Directory partitions

Active Directory Partition

AD database is stored in one file i.e. ntds.dit. However, the AD database is divided up into partitions for better replication and administration.

Different categories of data are stored in replicas of different directory partitions, as follows:

  1. Domain data: It is stored in domain directory partitions.

    1. Domain Directory Partition: Every domain controller stores one writable domain directory partition. It replicates data with DC’s in the same domain. Active Directory Users and Computers obtains it data from this partition. All Domain Controllers in that domain replicate changes to each other regardless of whether the Domain Controller is a global catalog server.

      What is Active Directory partitions

    2. Global Catalog Directory Partition: A domain controller that is a global catalog server stores one writable domain directory partition and a partial, read-only replica of every other domain in the forest. Global catalog read-only replicas contain a partial set of attributes for every object in the domain. It Replicates GC data with all GC’s in the forest. The Global Catalog Partition is created automatically by software on the Domain Controller. This software copies some of the attributes for each object in the Global Catalog Partition. This information is replicated to other Domain Controllers inside and outside the domain. This is how, given enough time, all Global Catalog servers will have a partial replicate of all objects in the domain.

      Note: Partial Attribute Set data – Need to be added in schema edit window (don’t use ADSIedit, use schema management from mmc after running regsvr32 schmmgmt.dll in run command)

What is Active Directory partitions

2. Configuration data: Every domain controller stores one writable Configuration Directory Partition that stores forest-wide data controlling site and replication operations. Replicates with all DC’s in the forest. This partition contains configuration information for the whole forest. For example, it contains information about sites in the forest and partition defined in the Active Directory database.

What is Active Directory partitions

3. Schema data: Every domain controller stores one writable Schema Partition that stores schema definitions for the forest. The schema partitions define what can be stored in the Active Directory database. It essentially defines the layout of the database.
Although the schema directory partition is writable, schema updates are allowed on only the domain controller that holds the role of schema operations master.

What is Active Directory partitions

4. Application data : Domain controllers that are running Windows Server 2003 or above can store data inside AD database called Application directory partitions. Application directory partition replicas can be replicated to any set of domain controllers in a forest, irrespective of domain. The application partition is created by Applications to store their data. It is different from any other partition in that the application can choose which Domain Controller or Controllers to store the data on. The advantage for the application storing the data this way is that the application has access to the same replicate and fault tolerance used by the Domain Controllers. An example of an Application is DNS Integrated Active Directory Zones. When this zone type is used, the data is stored in an application partition. Replicates with any specified DC in which app has created the separate partition. E.g. AD integrated DNS will have an Application directory partition in AD. Similarly, Exchange 2010

What is Active Directory partitions

Windows Server 2016

The active directory database is stored in a single NTDS.dit file which is logically separated into the following partitions:

  1. Schema Partition
  2. Configuration Partition
  3. Domain Partition
  4. Application Partition

Schema Partition

There is only one schema partition per forest and it is stored in all DCs of the forest.  It contains the definition of objects and rules for their manipulation and creation in an active directory. It is replicated to all DCs of the forest.

Configuration Partition

Just like schema partition, there is just one master configuration partition per forest and a second one on all DCs in a forest. It contains the forest-wide active directory topology including DCs and sites and services. It is replicated to all DCs in a forest.

Domain Partition

Many domain partitions exist per forest and they are stored on all DCs in a domain. They contain information about users, groups, computers and OUs. It is replicated to all DCs in a given domain.

Application Partition

This partition stores information about applications in an AD. Suppose AD integrated DNS zones information is stored in this partition.

Share

Published by

Rspamd is a widely used email and spam filtering solution. It consists of a set…

Since Debian 10, the Debian Linux distribution uses systemd to control starting and stopping of…

More than a decade ago, the world was introduced to the wonders of cryptocurrencies and…

Echo is a built-in Linux command-line utility that is used on standard output to display…

This tutorial shows you for different methods to create a directory with the help of…

Finding and opening files via Windows Explorer is easy, but it takes a bit longer.…