What is a directory service? How does it work?
The directory service is a service that can operate with multi-point redundancy when necessary in order to store and organize information including authorization policies and access permissions of users and endpoints. The directory service organizes all users, computers, and other objects in the network where it is located or authorized, according to logical and hierarchical groupings. It uses this information to authenticate and/or authorize users, computers, and resources that are part of the corporate network.
A directory service is a service that stores information about entities such as users, computers, and printers as records, just like in a phone book, has a database.
This “guide” classifies records of network-connected physical assets, such as name, location, and unit, according to their attributes. The classified assets first Organizational Unit and then To the Domain It is connected. Furthermore, a Domain may be connected to a Domain Tree, which consists of the grouping of certain domains. Multiple domain trees, in turn, combine to form a Forest.
As a result Domain It is the logical grouping of the objects mentioned above and enables the establishment of administrative boundaries for these objects. The objects in a domain are not required to be on the same physical network. If a user has access to the domain and sufficient privileges, they can log on from anywhere in that domain and from any computer account, and access the organization's resources. Directory user, which is part of the organization and has its own unique identity within the domain (SID) is the person who can use shared files, computers, printers, and software within the scope of authority and permissions. A directory computer, on the other hand, is a computer that has its own computer account and provides access to the domain.
What is a domain? What does a domain controller do?
The domain is the most fundamental component that also houses the administrative units of the directory service. Commonly used as "Domain" in English, Domain Controller is managed by. In fact, a Domain Controller is like a kind of authority for the domain. The domain controller is responsible for all authentications, authorizations, additions, deletions, edits, and changes within the domain.
The domain controller, a copy of the directory database Replika contains. Changes made in the domain are carried out via the domain controller. A change made by one controller is replicated by all domain controllers in the domain. Thus, the entire domain (for example, all campuses of a university with a single domain) is informed of all changes.
Domain controller It holds the records of all directory information. Thus, domain controllers can perform operations such as logging in, authentication, and searching the directory. It can host one or more domain controllers in the same domain. For example, a university with campuses in different locations can have one or more domain controllers for each campus. The most important advantage of using multiple domain controllers is that if a problem occurs in any of the controllers, another one takes over to maintain uninterrupted operation, thereby increasing fault tolerance. In addition, distributing the load is crucial for productivity in multi-computer and multi-user organizations. If a domain controller has no backup, the system may go down when a problem occurs.
Domain controllers constantly synchronize themselves to stay aware of changes in the database. For example, when a student changes their password and wants to go to a different campus and log in from the library, the domain controller there needs to be aware of this change so the user can log in with their new password. This process is called “Replication” so data duplication deny.
What can be done with a directory service?
thanks to the directory service, various administrative constraints can be created, meaning it can be determined which user has how much access to which asset. At the same time users' (such as company employees or university students) work environments (such as software they can use on the computers they log into) malleable and can be made to comply with certain standards. In addition, such shapings can be done through groups Group Policy It is possible. For example, when a group of faculty members and a group of students at a university connect to the system (using their own usernames and passwords), they can be granted different permissions and access to different software, files, and assets.
Why is directory service security important?
An unauthorized person who takes control of a domain controller also takes control of the entire domain. Thus, they take over all authentication and authorization processes and can destroy security policies. Therefore, the security of the directory service is extremely important.
What does it look like from the user's perspective?
When a university student goes to the library and wants to log in with their username and password from a computer registered in the directory, a connection is established with the domain controller. This username and password are authenticated against the student credentials located in the directory service database. When this authentication takes place, the student has logged into the computer, meaning they are accepted by the operating system for the access request. On the opened computer, the student is greeted by the operating system desktop. The warnings they will see here, the software they can use, and their permissions regarding what they can do are predetermined. For example, if authorized, they can use a word processor or access the library database through a browser. Different access policies can be created for different groups within the directory. The policies created for student access may differ from those prepared for other employees or faculty members. Furthermore, different access policies can even be created for students in different departments.
What are the different directory service options?
Commonly used directory services include Microsoft Active Directory, Apache Directory, OpenLDAP, Samba, NetIQ eDirectory, Red Hat Directory Services, and IBM Security Directory Server. While each of these directory service software has different features, the majority of them operate compatibly with a protocol called Lightweight Directory Access Protocol (LDAP).
Today, the most effective way to break free from brand dependency is to turn to free and open-source software.
Brand dependency brings about adaptation issues in the medium to long term, driving users into a lack of options and forcing them to pay high total cost of ownership.
In addition, compatibility issues are also influential in the selection of add-on components. For example, one of the most prominent shortcomings of Microsoft Active Directory is its inability to manage different clients together. For instance, if your organization uses Windows, Linux, and OS X® operating systems, Microsoft Active Directory only takes into account the changes in those with the Windows operating system installed. Naturally, the reason for this is a commercial decision made by its manufacturer.
Open-source software offers alternatives to proprietary directory services as software that can be continuously developed and customized for specific requirements. The most well-known among the alternatives OpenLDAPAlthough it is ®, it is used by a limited number of businesses due to its limited features and the requirement for an experienced technical manager. It is noteworthy that these businesses are generally small and medium-sized enterprises without a Microsoft dependency.
What is SambaBox? What are its advantages?
SambaBox®, which is an open-source software Samba4© is a directory service developed by Profelis. Among its most important advantages are reducing the total cost of ownership for organizations and enabling the simultaneous management of clients with different operating systems. Competing with Microsoft Active Directory through its easy integration and inclusion of all the features a directory server should have, SambaBox also draws attention with its web-based management interface.
Furthermore, SambaBox can authenticate users using different operating systems common in businesses, such as Windows, Linux, and macOS, thereby eliminating the dependency of businesses on a single operating system.
With a very low total cost of ownership compared to its alternatives, SambaBox is also a software that holds the Certificate of Domestic Goods. For more information about SambaBox sambabox.io You can visit their website.
What is total cost of ownership?
Of a used software Total Cost of Ownership, not only the license fee paid at the time of purchase, but also the costs paid during the period the software is used for updates, maintenance, hardware investments necessary to ensure the continuity of the performance expected from the software, and the training of those who will use or manage the software. Therefore, in software procurements, the expenses incurred during the usage period other than the initial license cost should also be evaluated within the total cost of ownership.



