Active Directory Architecture and Management Questions

Designing, operating and recovering Active Directory Domain Services and the directory estate around it. Covers logical and physical structure (forests, trees, domains, OUs, trusts, schema extension, FSMO roles, Global Catalog, RODCs), sites and replication topology, domain controller placement, promotion, upgrade and functional levels, DC locator and AD-integrated DNS, domain join, Kerberos and NTLM authentication including SPNs and delegation, token size and SID history, LDAP binds and query tuning, Group Policy design, processing order, filtering, deployment and troubleshooting, user, group, computer and service account management including PowerShell account scripting and account lockout investigation, delegation of control and tiered administration, fine-grained password policy, backup, authoritative restore, forest recovery and USN rollback, AD hardening against Kerberoasting, DCSync and Golden Ticket attacks, forest migration, and hybrid identity with Microsoft Entra ID (Microsoft Entra Connect, Cloud Sync, password hash sync, pass-through authentication, federation, password writeback). Questions are asked from the directory administrator's and architect's seat. Platform-neutral identity protocols and lifecycle design, Windows file-server administration (shares, NTFS permissions, profiles), Linux directory integration, and generic DNS and DHCP service operations are covered elsewhere.

MediumTechnical
25 practiced

What is the difference between AD DS and Entra ID, and what does it change for a team planning a hybrid environment?

EasyTechnical
28 practiced

Your team debates organising users into OUs versus groups. What is each for, and how do you decide which to use when delegating administration or applying Group Policy?

EasyTechnical
34 practiced

Using PowerShell, how would you look up a user by logon name and show whether the account is enabled, when they last signed in, and which groups they belong to? Handle the user not existing.

MediumTechnical
33 practiced

How does a Windows client find and choose a domain controller to authenticate against, and how would you investigate a client that keeps using a distant one?

MediumTechnical
24 practiced

Kiosk machines must give every user the same locked-down experience regardless of which user policies would normally apply. How would you get Group Policy to do that, and what side effects should you watch for?

Unlock Full Question Bank

Get access to all Active Directory Architecture and Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.