Active Directory, Identity and Access • IDA maintains security of resources such as emails, files, apps and databases. IDA stores information about users, groups, computers and other IDs. • Resources are secured with permissions on an access control list (ACL) • Security subsystem of server compares ID of user to IDs on ACL to determine weather grant or deny access • Computers, groups, services and other objects must be represented by IDs • Information used to identify an object could be user name or a security identifier (SID) and the password • The Active Directory data store is known as the DIRECTORY which is an identity store • The directory is hosted and managed by the DOMAIN CONTROLLER, which is a server performing the AD DS role

