Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.2.4. Directory Services and Active Directory

💡 First Principle: A directory service is a structured database purpose-built to store and organize identity objects — users, groups, devices, and their attributes — so that authentication and authorization systems have a consistent, searchable place to look up "does this identity exist, and what does it belong to?"

Active Directory Domain Services (AD DS) is Microsoft's traditional on-premises directory service, organizing identities into domains and forests, and authenticating primarily via Kerberos. It predates the cloud and was built for a world of corporate networks and domain-joined PCs. Microsoft Entra ID (Phase 3) is a related but distinct, cloud-native directory and identity platform, built on modern web protocols rather than Kerberos — the two are commonly connected via hybrid identity (Phase 3.1.3), but they are not the same product.

⚠️ Exam Trap: A directory service (storing identity objects) and an identity provider (authenticating and issuing tokens) are related but distinct roles — a single product can do both, but the two functions are conceptually separate on this exam.

Reflection Question: What specific problem does a directory service solve that would exist even if an organization only ever had one single application to protect?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications