Active Directory Services Overview
Active Directory Certificate Services (AD CS)
Active Directory Certificate Services (AD CS) allows you to create, distribute, and manage customized public key certificates. Most organizations use certificates to prove the identity of
users or computers, as well as to encrypt data during transmission across unsecured network connections. AD CS enhances security by binding the identity of a person, device, or service to their own private key. Storing the certificate and private key within
Active Directory helps securely protect the identity, and Active Directory becomes the centralized location for retrieving the appropriate information when an application places a request.
Active Directory Domain Services (AD DS)
Active Directory Domain Services (AD DS) stores directory data and manages communication between users and domains, including user logon processes, authentication, and directory searches. AD
DS is the central location for configuration information, authentication requests, and information about all of the objects that are stored within your forest. Using AD DS, you can efficiently manage users, computers, groups, printers, applications, and other
directory-enabled objects from one secure, centralized location.
Active Directory Federation Services (AD FS)
Active Directory Federation Services (AD FS) provides Web single-sign-on (SSO)
technologies to authenticate a user to multiple Web applications over the life of a single online session. AD FS is a highly secure, highly extensible, and Internet-scalable identity access solution that allows organizations to authenticate users from partner
organizations. Using AD FS, you can easily and very securely grant external users access to your organization’s domain resources. AD FS can also simplify integration between untrusted resources and domain resources within your own organization.
Active Directory Lightweight Directory Services (AD LDS)
Active Directory Lightweight Directory Services (AD LDS) is a Lightweight Directory Access Protocol (LDAP) directory service that provides flexible support for directory-enabled
applications, without the restrictions of Active Directory Domain Services (AD DS). Instead of using your organization’s AD DS database to store the directory-enabled application data, AD LDS can be used to store the data. AD LDS can be used in conjunction
with AD DS so that you can have a central location for security accounts (AD DS) and another location to support the application configuration and directory data (AD LDS). Using AD LDS, you can reduce the overhead associated with Active Directory replication,
you do not have to extend the Active Directory schema to support the application, and you can partition the directory structure so that the AD LDS service is only deployed to the servers that need to support the directory-enabled application.
Active Directory Rights Management Services (AD RMS)
Active Directory Rights Management Services (AD RMS) protects your information and works with AD RMS-enabled applications to help safeguard digital information from unauthorized use.
AD RMS can help make sure that only those individuals who need to view a file can do so. AD RMS can protect a file by identifying the rights that a user has to the file. Rights can be configured to allow a user to open, modify, print, forward, or take other
actions with the rights-managed information. With AD RMS, you can even safeguard data when it is distributed outside of your network.
See Also
Other Languages
External Resources and Books