Active Directory Architecture and Management Questions

Designing, operating and recovering Active Directory Domain Services and the directory estate around it. Covers logical and physical structure (forests, trees, domains, OUs, trusts, schema extension, FSMO roles, Global Catalog, RODCs), sites and replication topology, domain controller placement, promotion, upgrade and functional levels, DC locator and AD-integrated DNS, domain join, Kerberos and NTLM authentication including SPNs and delegation, token size and SID history, LDAP binds and query tuning, Group Policy design, processing order, filtering, deployment and troubleshooting, user, group, computer and service account management including PowerShell account scripting and account lockout investigation, delegation of control and tiered administration, fine-grained password policy, backup, authoritative restore, forest recovery and USN rollback, AD hardening against Kerberoasting, DCSync and Golden Ticket attacks, forest migration, and hybrid identity with Microsoft Entra ID (Microsoft Entra Connect, Cloud Sync, password hash sync, pass-through authentication, federation, password writeback). Questions are asked from the directory administrator's and architect's seat. Platform-neutral identity protocols and lifecycle design, Windows file-server administration (shares, NTFS permissions, profiles), Linux directory integration, and generic DNS and DHCP service operations are covered elsewhere.

MediumTechnical
32 practiced

Domain Admin accounts are used for everyday work across your company. How would you redesign administration to protect high-privilege accounts?

MediumTechnical
24 practiced

Helpdesk should reset passwords and unlock accounts only for ordinary users, server ops should manage computer accounts in server OUs, and Domain Admins keep full control. Design the delegation model and show how you would verify it.

HardSystem Design
25 practiced

Design a self-service password reset service for a hybrid directory. How do you verify users, write the new password back to on-premises AD, and stop social-engineering abuse?

HardTechnical
47 practiced

A web application running as a service account must query a SQL backend as the end user. How do you make that work without granting more trust than necessary, and what changes if the two services sit in different domains?

MediumTechnical
26 practiced

Two companies need limited resource access between their separate forests. How would you set up the trust, and how do you keep the other resources in the second forest out of reach?

Unlock Full Question Bank

Get access to all 11 Active Directory Architecture and Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.