Active Directory Architecture and Management Questions

Designing, operating and recovering Active Directory Domain Services and the directory estate around it. Covers logical and physical structure (forests, trees, domains, OUs, trusts, schema extension, FSMO roles, Global Catalog, RODCs), sites and replication topology, domain controller placement, promotion, upgrade and functional levels, DC locator and AD-integrated DNS, domain join, Kerberos and NTLM authentication including SPNs and delegation, token size and SID history, LDAP binds and query tuning, Group Policy design, processing order, filtering, deployment and troubleshooting, user, group, computer and service account management including PowerShell account scripting and account lockout investigation, delegation of control and tiered administration, fine-grained password policy, backup, authoritative restore, forest recovery and USN rollback, AD hardening against Kerberoasting, DCSync and Golden Ticket attacks, forest migration, and hybrid identity with Microsoft Entra ID (Microsoft Entra Connect, Cloud Sync, password hash sync, pass-through authentication, federation, password writeback). Questions are asked from the directory administrator's and architect's seat. Platform-neutral identity protocols and lifecycle design, Windows file-server administration (shares, NTFS permissions, profiles), Linux directory integration, and generic DNS and DHCP service operations are covered elsewhere.

HardTechnical
42 practiced

You must consolidate two legacy AD forests into a new forest with a different namespace. Lay out your migration plan and what you do about the problems it will throw up.

HardSystem Design
29 practiced

You must allow limited resource access among three separate forests while keeping most resources isolated. Propose a trust topology, justify the direction and type of each trust, and explain the security risks each trust introduces and how you contain them.

HardSystem Design
34 practiced

Create a disaster recovery plan for AD in a hybrid cloud estate. How do you handle an on-premises DC failure and what happens to sync and sign-in during and after it?

HardSystem Design
24 practiced

Design Active Directory for a company with 50,000 users across six regions that needs 24x7 authentication and low logon latency. Where do you draw forest and domain boundaries, where do domain controllers go and of what kind, and what would you give up?

HardTechnical
25 practiced

A penetration test shows an attacker with ordinary domain credentials reached Domain Admin. Which AD attack paths are likely, and how would you harden against them and detect them?

Unlock Full Question Bank

Get access to all 18 Active Directory Architecture and Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.