The directory service for Windows networks, storing users, computers, groups, and other objects in a hierarchical database that domain-joined systems query and authenticate against. It issues and validates credentials for network logon, applies centrally-defined configuration policy to the machines and users under it, and replicates its data between domain controllers so the directory stays consistent across sites. Applications and services read it over LDAP as the authoritative source of identity and group membership.