A Windows laptop signs in, opens a file share and picks up its policies, and one server answers all three requests. That server is the domain controller, and it is the first place to look when sign-ins slow down or fail across an office. This guide explains what a domain controller is, what it holds, what the five FSMO roles do, how many you need and when a cloud-only setup can replace it.
TL;DR
- A domain controller (DC) is a Windows Server that runs Active Directory Domain Services. It checks passwords, issues Kerberos tickets and holds a copy of the directory for its domain.
- Every DC in a domain keeps a full copy of the domain's data, and changes replicate between them. Five FSMO roles keep the few jobs that cannot be shared on one DC at a time.
- One DC is a single point of failure. Two is the practical floor, and a snapshot is not a backup of either.
- Cloud-only is possible with Entra ID and Intune. Legacy LDAP and Kerberos apps, plus internal DNS, are what keep a DC in the picture.
What a Domain Controller Does
Microsoft describes Active Directory Domain Services (AD DS) as a directory service that stores information about objects on the network, such as user accounts, computers, servers and printers, and makes it available to authorized users and administrators. A domain controller is a server that runs that service. The word "controller" is the whole job: it decides who gets in.
The sign-in path is short. A user types a password. The workstation asks a domain controller to verify it. The DC, acting as the Kerberos key distribution center, hands back a ticket, and the workstation presents that ticket to the file server, the print server or the intranet app. The target server never sees the password.
Four services answer on a DC, and they map to four ports in Microsoft's domain controller firewall table: Kerberos on 88, DNS on 53, LDAP on 389 and SMB on 445 for the SYSVOL share. Block any one of them between a client and its DC and the symptom is a slow or failed sign-in, not an obvious error.
Time matters more than it looks. Kerberos stamps its tickets to stop replay attacks, so the client clock and the DC clock must agree. Microsoft's default tolerance is 5 minutes. Past that, sign-ins fail even with the right password, which is why the time source in a domain is a controller job and not an afterthought.
The video below is a short explainer on the same topic.
Domain Controller vs Active Directory
The two terms get used for each other, and they name different things. Active Directory is the directory service and the data it keeps. A domain controller is the server that runs it. A domain can have several domain controllers, and removing the role leaves a plain Windows Server behind.
A domain controller also differs from the protocol apps use to talk to it. Our guide to what LDAP is covers binds, ports and signing, so this post stays on the server side.
Microsoft's AD DS overview lists what the service includes: a schema that defines object classes and attributes, a global catalog, a query and index mechanism, and a replication service. The global catalog holds a partial copy of every object in the forest, which lets a user in one domain look up a colleague in another.
What Lives on a Domain Controller
A domain controller keeps four things. Knowing where each one lives tells you what to back up and what to protect.
- The directory database. The file is NTDS.dit, and it holds users, groups, computers and their attributes.
- SYSVOL. A shared folder that carries Group Policy templates and logon scripts to every client.
- DNS records. Many domains run DNS on their DCs and store the zones in Active Directory, since clients find a DC by looking up DNS records.
- The Kerberos service. The key distribution center runs on every DC, so any of them can issue tickets.
SYSVOL is the piece that turns policy into settings on a laptop. The policies themselves are edited in the console covered in our Group Policy editor guide, and they only reach clients because SYSVOL replicates to every DC.
DNS deserves a flag. Domain members find their DC through DNS, so a DC that is healthy but unreachable by name looks broken to every client. If a user can ping the server by address but nothing else works, start with the checks in our post on DNS server not responding.
Replication and the Five FSMO Roles
Microsoft calls Active Directory a multi-master database. Any DC can accept a change, such as a new user or a password reset, and the change replicates to the others. Every DC in a domain holds a complete copy of the domain's directory data.
Multi-master has one cost. Two DCs can accept conflicting changes at the same moment. Microsoft's default answer is "last writer wins", and the other change is discarded. A few jobs cannot tolerate that, so they are single-master instead.
Those jobs are the Flexible Single Master Operation roles, or FSMO roles. Microsoft lists five: schema master, domain naming master, RID master, PDC emulator and infrastructure master. Two apply to the whole forest and three apply to each domain.
Three of the five stay quiet day to day. The schema master is only contacted when the schema changes. The domain naming master is only contacted when a domain is added or removed. The RID master hands out pools of relative IDs that DCs use to build the unique security ID of every new user, group and computer.
The PDC emulator is the busy one. Per Microsoft, it receives password changes preferentially, handles bad-password forwarding, processes account lockout, and serves as the authoritative time source for the domain. The PDC emulator in the forest root should take its time from an external source.
The infrastructure master updates references between objects in different domains. Microsoft notes that it should not sit on a global catalog server unless every DC in the domain is a global catalog, in which case it does not matter. When the AD Recycle Bin is enabled, every DC updates its own cross-domain references and the role has no tasks left.
In a one-domain forest, the setup a small office normally has, all five roles sit on the first DC that was promoted. They only move when someone moves them. The thread below shows what that can cost: an admin migrated two sites, left the roles split across two DCs and the site subnets pointing at the old layout, and then chased sporadic DNS and authentication failures between servers.
Before you retire a DC, run netdom query fsmo and move any role it holds. A role holder that vanishes without a transfer has to be seized, which is a recovery step.
Read-Only and Global Catalog Domain Controllers
Not every DC is a full read-write copy. A read-only domain controller (RODC) is the variant Microsoft built for locations where physical security cannot be guaranteed, such as a branch office with a server in a closet. It hosts read-only partitions of the AD DS database, so a stolen or compromised box cannot push changes back into the domain.
A global catalog server is a DC that also holds the partial forest-wide copy described above. In a single-domain network every DC can be one.
How Many Domain Controllers You Need
One DC works until it does not. With a single controller, a reboot for patching takes sign-in, DNS and Group Policy refresh offline for the whole office. A laptop that signed in recently may keep working from cached credentials, but a new Kerberos ticket, a password change or a join to the domain has nowhere to go.
Two DCs remove that dependency. Clients try the second controller when the first one is down, replication keeps both copies current and one can be patched while the other serves. The second DC can be small, and it should not share a host with the first.
When everything depends on one DC and it goes quiet, the usual symptom on a workstation is a failure to reach the domain, including the secure channel message our trust relationship error guide covers. The cause is often a DC outage or a DNS record, and rejoining the machine to the domain does not fix it.
Virtual Domain Controllers, Snapshots and Backups
Running a DC as a virtual machine is routine. The risk is the snapshot. Each DC numbers its changes with an update sequence number (USN) and identifies its database with an InvocationID. Replication partners use both to track what they have already received.
Roll a DC back to a snapshot and it reuses USNs for different changes. Other DCs believe they already have those updates, so the change is silently skipped. Microsoft calls this USN rollback and notes that no replication errors are reported, which is what makes it dangerous.
Since Windows Server 2012, a virtual DC on a hypervisor that exposes VM-GenerationID detects the rollback. It resets its InvocationID and discards its RID pool, so replication converges instead of splitting. Microsoft's own worked example is below, with its numbers.
The safeguard is for accidents. Microsoft states that restoring a DC by applying a VM snapshot is not recommended as an alternative to backing it up, and points to Windows Server Backup or another VSS-writer based backup instead. If you are picking one, our guide to backup software for servers covers what to test, and a system state backup is the piece that matters for a DC.
Keeping Domain Controllers Secure
A domain controller holds every credential in the domain, so it is the most valuable server on the network. Microsoft's guidance on securing Active Directory says plainly that an attacker with privileged access to a DC can modify, corrupt and destroy the AD database. Domain controllers appear on Microsoft's list of the targets credential thieves go after.
The practical rules are short. Keep DCs physically secure and patched. Administer them from secure administrative hosts that do not run email or a web browser. Microsoft also lists application allowlists on domain controllers.
Lifecycle belongs on that list. A DC on an unsupported Windows Server is a patching gap on the most sensitive box you have, and our post on Windows Server 2016 EOL covers the January 2027 date.
The fastest way to weaken a DC is to give it other jobs. File shares, print queues, backup agents and the line-of-business app that "only needs a small server" all widen what an attacker can reach. The meme below is a Server Manager screen many admins will recognize.
Do You Still Need a Domain Controller
A cloud-only company can run without one. Devices join Microsoft Entra ID directly, Intune handles settings and apps, and users sign in with cloud credentials. Group Policy gives way to Intune configuration profiles, and Kerberos gives way to modern tokens over SAML and OpenID Connect.
The holdouts are what keep a DC in place. A legacy app that only speaks LDAP or Kerberos, an on-premises file server that authenticates domain users, a printer that binds to AD, and internal DNS are the four to check first. If none of them applies, a cloud-only design is realistic.
Microsoft offers a bridge for the middle case. Entra Domain Services is a managed domain: Microsoft deploys two Windows Server domain controllers into an Azure region, runs them for you, and syncs users one way from Entra ID. It supports domain join, Group Policy, LDAP and Kerberos and NTLM authentication. Microsoft describes it as a stand-alone domain and a transitional capability, not a general replacement for on-premises Active Directory.
Internal DNS is the holdout people forget. In a September 2026 r/sysadmin thread, an admin whose company ran without domain controllers, on Entra and Intune, described standing up BIND9 on a Linux VM purely for internal DNS, and asked for something cheaper.
The choice sits inside a larger identity decision, covered in our guide to IAM solutions. A full Entra ID vs Active Directory comparison is planned as its own post.
Checking Your Domain Controllers
Run these from an elevated prompt on a DC, or from a management host with the AD tools installed. They answer four questions: which controllers exist, who holds the roles, is replication healthy and is the clock right.
Get-ADDomainController -Filter *lists every DC in the domain with its site, OS and global catalog status.netdom query fsmoshows which DC holds each of the five roles.repadmin /replsummarysummarizes replication and shows partners that have not replicated recently.dcdiagruns a battery of health tests, including DNS and connectivity.w32tm /query /statusshows the time source and last sync, which is where a 5-minute Kerberos failure starts.
Inheriting a network is where this matters most, and a DC nobody listed is the one that turns up after a migration. Our network assessment checklist covers finding every server.
Need the management console first? Follow the ADUC install guide.
For a fleet, run the commands as a script rather than from one RDP session at a time. OpenFrame can run a script across a client's devices and collect each machine's output, so the replication summary and FSMO owner for every client land in one place. Ship the Directory Service and System logs from the DCs to your log management pipeline, because replication and Kerberos errors show up there first.
The Short Version
A domain controller is the Windows Server that runs Active Directory Domain Services: it verifies passwords, issues Kerberos tickets and holds a replicated copy of the directory. Five FSMO roles cover the jobs that cannot be shared, and the PDC emulator is the one you will notice. Run two DCs, back them up with VSS-based backups rather than snapshots, keep other roles off them and check replication on a schedule. Drop them only when no legacy app, file server or internal DNS depends on them.
For the protocol side, start with our guide to what LDAP is. The Entra ID vs Active Directory comparison will cover the cloud decision in depth once it is published.
FAQ
What is a domain controller in simple terms?
A domain controller is a Windows Server that runs Active Directory Domain Services and decides who may sign in to a network. It checks passwords, issues Kerberos tickets and keeps a copy of the directory of users, computers and groups. Every DC in a domain holds a full copy, so more than one can serve sign-ins.
What is the difference between a domain controller and Active Directory?
Active Directory is the directory service and its data. A domain controller is a server that runs that service. A domain can have many domain controllers sharing one Active Directory domain, and a server stops being a domain controller when the AD DS role is removed.
How many domain controllers does a small business need?
Two. One controller means any reboot or failure takes sign-in, DNS and Group Policy refresh offline. A second DC, placed on separate hardware or a separate host, lets clients carry on while the first is patched or repaired. Neither should be restored from a VM snapshot as a substitute for a backup.
What are FSMO roles?
FSMO stands for Flexible Single Master Operation. Microsoft lists five roles: schema master and domain naming master once per forest, and RID master, PDC emulator and infrastructure master once per domain. They cover the jobs that cannot safely be handled by several DCs at once, and all five usually sit on the first DC in a small domain.
Do I need a domain controller if I use Microsoft 365?
Not necessarily. Microsoft 365 runs on Entra ID, and devices can join Entra ID and be managed through Intune. You keep a DC when something on-premises still needs LDAP, Kerberos or domain join, such as a legacy app, a file server or internal DNS. Entra Domain Services offers a managed domain for those cases.
Can a domain controller run as a virtual machine?
Yes. Microsoft supports virtual domain controllers, and Windows Server 2012 and later add VM-GenerationID protection against snapshot rollback on supporting hypervisors. Microsoft still advises against using a snapshot as the way to back up or restore a DC, and recommends Windows Server Backup or another VSS-based backup.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
