Active Directory Architecture and Management Questions

Designing, operating and recovering Active Directory Domain Services and the directory estate around it. Covers logical and physical structure (forests, trees, domains, OUs, trusts, schema extension, FSMO roles, Global Catalog, RODCs), sites and replication topology, domain controller placement, promotion, upgrade and functional levels, DC locator and AD-integrated DNS, domain join, Kerberos and NTLM authentication including SPNs and delegation, token size and SID history, LDAP binds and query tuning, Group Policy design, processing order, filtering, deployment and troubleshooting, user, group, computer and service account management including PowerShell account scripting and account lockout investigation, delegation of control and tiered administration, fine-grained password policy, backup, authoritative restore, forest recovery and USN rollback, AD hardening against Kerberoasting, DCSync and Golden Ticket attacks, forest migration, and hybrid identity with Microsoft Entra ID (Microsoft Entra Connect, Cloud Sync, password hash sync, pass-through authentication, federation, password writeback). Questions are asked from the directory administrator's and architect's seat. Platform-neutral identity protocols and lifecycle design, Windows file-server administration (shares, NTFS permissions, profiles), Linux directory integration, and generic DNS and DHCP service operations are covered elsewhere.

HardSystem Design
34 practiced

Create a disaster recovery plan for AD in a hybrid cloud estate. How do you handle an on-premises DC failure and what happens to sync and sign-in during and after it?

HardSystem Design
32 practiced

Design a backup and disaster recovery plan for a five-domain forest with a one-hour RPO and an eight-hour RTO. Say how you would test it.

MediumTechnical
47 practiced

Sales users need a mapped network drive to the sales file share, a logon-time compliance script, and a locked-down user registry setting, all through Group Policy. How would you build the policy, limit it to the right people and machines, and test it before wide rollout?

HardTechnical
28 practiced

Your incident team believes an attacker holds persistent forged-ticket access to the domain after compromising a DC. How does that attack work, how would you detect it, and how do you evict the attacker?

HardTechnical
29 practiced

You have lost the only writable domain controller in a site and have known-good backups. How do you recover, and how do you decide which kind of restore to perform?

Unlock Full Question Bank

Get access to all 33 Active Directory Architecture and Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.