Special Offer 

Jumpstart your hiring with a $75 credit to sponsor your first job.*

Sponsored Jobs posted directly on Indeed with Urgently Hiring make a hire 5 days faster than non-sponsored jobs.**
  • Visibility for hard-to-fill roles through branding and urgently hiring
  • Instantly source candidates through matching to expedite your hiring
  • Access skilled candidates to cut down on mismatched hires

Active Directory Interview Questions

Our mission

Indeed’s Employer Resource Library helps businesses grow and manage their workforce. With over 15,000 articles in 6 languages, we offer tactical advice, how-tos and best practices to help businesses hire and retain great employees.

Read our editorial guidelines

Whether you are preparing to interview a candidate or applying for a job, review our list of top Active Directory interview questions and answers.

  1. Name three new features of AD in the latest Windows Server. See answer
  2. Explain Mixed Mode. See answer
  3. What is TOMBSTONE lifetime (TSL)? See answer
  4. Define KCC. See answer
  5. Explain Kerberos. See answer
  6. What are the components of system state data? See answer
  7. What is LDAP? See answer
  8. What’s the reason for replication in 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory? See answer
  9. What is a Relative Identifier? See answer
  10. How do admins use group policy to manage the work environment? See answer
  11. Name and define AD containers.
  12. Define PDC Emulator.
  13. What does gpupdate /force do?
  14. What are the elements that make up the DFS namespace?
  15. Explain the differences between forests and trees.
  16. Define ACE.
  17. Name the different groups and how they differ.
  18. Define and describe lingering objects.
  19. Explain what PPP is and its derivatives.
Show more questions Show fewer questions

Hire your next Active Directory today.

Post a job

Hire your next Active Directory today.

Post a job
Our mission

Indeed’s Employer Resource Library helps businesses grow and manage their workforce. With over 15,000 articles in 6 languages, we offer tactical advice, how-tos and best practices to help businesses hire and retain great employees.

Read our editorial guidelines
Create a Culture of Innovation
Download our free step-by-step guide for encouraging healthy risk-taking
Get the Guide

10 Active Directory Interview Questions and Answers

Name three new features of AD in the latest Windows Server.

The main purpose of 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory is to control access to the network, and many organizations use Windows Server as the framework. Microsoft goes through several iterations and updates that include necessary security updates. It’s important for candidates to stay current on these new features and how they affect an organization. What to look for in an answer:

  • Active Directory functionality

  • Ability to stay proactive

  • Understanding of new features and their impact

Example:

“There are a few that Microsoft calls improvements that apply to AD in Windows, and they are:

  • Privileged access management mitigates credential theft attacks in AD.
  • Microsoft Passport that enables logins to use key-based authentication, such as One Time Password.

  • Azure Active Directory Join that allows devices that are already on the domain to join AD."

Explain Mixed Mode.

When you’re deploying Windows Server, this is a common scenario. Usually, there isn’t any further configuration needed, but an admin with enough experience will understand how to tweak 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory to enable certain types of communication. Depending on the answer, you can ask the applicant to elaborate to get a deeper understanding of their experience level. What to look for in an answer:

  • Understanding of Mixed Mode

  • How mixed mode affects AD

  • Knowing when to make necessary adjustments

Example:

“Mixed Mode allows two domain controllers to coexist on a server. For example, when Windows Server 2000 was deployed, it was set to Mixed Mode by default. This allowed the previous versions, Windows NT, and 2000, to peacefully coexist. This applies to subsequent versions of Server. When it comes to running Active Directory, you may need to make some tweaks to facilitate communication.”

What is TOMBSTONE lifetime (TSL)?

When it comes to deletions in 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory, it’s never immediate or instantaneous. Replications in this environment have to be timed as per the company’s security policy. Candidates should know the default settings and how they can be changed. Applicants who understand this as well as what happens to deleted objects have a solid knowledge base. What to look for in an answer:

  • What TOMBSTONE lifetime is

  • Standard deleted objects protocol

  • Changing TSL

Example:

“TOMBSTONE lifetime dictates how long deleted objects stay in Active Directory. When objects are deleted, they don’t just disappear. They linger for a certain time in a TOMBSTONE object, which is usually about 60 days. However, the duration can be changed in the forest configuration to any time frame dictated by the company’s security policy.”

Define KCC.

This is one of the standard 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory interview questions about certain built-in functions that manage database integrity. Candidates should know what KCC is and when it’s used. However, candidates looking to impress interviewers will talk more about the replication topology between domain controllers. What to look for in an answer:

  • What KCC is

  • When it’s used

  • Relationship to AD topology

Example:

“The Knowledge Consistency Checker, or KCC, is built-in and checks database consistency every three hours throughout an organization. Modifications to the database trigger it as well. In Active Directory, the objective is to decrease latency between sites by creating connections between the trees using AD Replication Topology."

Explain Kerberos.

Understanding how parties are authenticated is an important part of why 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory is vital to an organization. Without the ability to verify the identity of a user or host, the company becomes vulnerable to attacks. Applicants will have a basic idea of how it works, but the ideal candidate will go into detail about the steps that occur from the time the ticket and session key are assigned. What to look for in an answer:

  • What is Kerberos

  • How it works

  • What it’s used for

Example:

“Kerberos is a network authentication protocol, just like TCP or UDP. It’s a powerful tool that uses secret-key cryptography to verify server/client/third-party relationships. How it works is that those who want to establish a connection with the server get a ticket and session key from the Kerberos Key Distribution Center (KDC). It sends the encrypted ticket to... ”

What are the components of system state data?

This is an important part of the Windows File System because it deals with recovery. If anything were to go wrong, understanding how to mitigate the loss makes this one of the more important 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory interview questions to ask. Solid candidates will not only provide a definition but will name some of the more popular components and describe them. What to look for in an answer:

  • What system state data is

  • Its components

  • Definition of components

Example:

“The system state data enables backup of the operating system and critical components, including Registry and Active Directory. Components include:

  • SYSVOL is the system volume files that are shared throughout the domain.

  • Cluster service information for servers with that service involved.

  • System boot files.

  • AD-integrated DNS zones.

  • Active Directory Database, including transaction logs.

  • COM+Class Registration Database.

  • Registry contents, such as hive files in %systemroot%repairregback, which is key to executing a quick registry restore.“

What is LDAP?

There are different ways to communicate with 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory and this question is a way for applicants to show they understand. It’s also a way for candidates to show their knowledge of how flexible AD is overall. The door is open for the interviewer to ask about the differences between LDAP and Kerberos to see just how deep a candidate's understanding is. What to look for in an answer:

  • Definition of LDAP

  • How it interacts with Active Directory

  • Basic authentication knowledge

Example:

“LDAP stands for Lightweight Directory Access Protocol and it's the credential repository. It stores the username and password information so it can be accessed later. The LDAP protocol speaks to Active Directory by using certain guidelines to exchange information, however, it’s not considered secure enough to be used by itself, which is why it’s paired with Kerberos.”

What’s the reason for replication in 105058active directory9.78system administrator6.55systems engineer2.62it2.53information technology2.42105521031817.7055.38200.00HOURLY10210412025-09-012025-09-302025-08-012025-08-312025-10-05Active Directory?

What makes this one of the most important Active Directory interview questions is that it allows the candidate to showcase their experience. When things go right, everything is fine, but if the candidate describes how this affects users when things go wrong, it shows they're more detail-oriented, which is a valuable characteristic in this technical role. What to look for in an answer:

  • What is replication

  • Its effect on AD

  • How it affects users

Example:

“Replication is a way to exchange information between domain controllers and get the status of Active Directory. Replication failures are important indicators that shouldn’t be ignored. Things like sporadic login issues or constant account lockouts are clues that something’s up and you need to get ahead of it. If you can catch small issues before they become major problems, you save a lot of time for yourself and users.”

What is a Relative Identifier?

Whenever anything is creative, it has a unique identifier. In Active Directory, each object must be unique or it will create collisions in the system. This is a straightforward question that any candidate should be able to answer, even if they don't go into the details. What to look for in an answer:

  • What is a relative identifier

  • Role of RID Master

  • Types of identifiers objects need

Example:

“When objects are created in Active Directory, they have a security identifier (SID) composed of a domain SID and a relative identifier, known as an RID. The domain controller has a pool of unique RIDs that it can assign and does so through the RID Master.”

How do admins use group policy to manage the work environment?

Whether an organization is small or large, keeping things organized is crucial. This question is about the specific ways Active Directory helps admins organize the various highways of information in addition to automating mundane tasks. Candidates should be able to provide insight into how they've used group policies, which offers a gateway to scenario-based questions that further test their knowledge. What to look for in an answer:

  • What group policy objects are

  • Benefits to the office environment

  • Data security options

Example:

“When working with a group policy object, there are several options available for managing the environment. They can be used to define which networked printers appear as available to specific users in certain departments. Users in these departments can see their specific home pages when they open a browser. But the most important use is to provide security measures, such as forcing users to change passwords periodically to prevent vulnerabilities and automatically deploying patches to keep the network healthy."

Create a Culture of Innovation
Download our free step-by-step guide for encouraging healthy risk-taking
Get the Guide

A group of five people in a modern office setting, two of them appear to be giving a presentation while the other two are seated at a wooden conference table with laptops and a coffee cup in front of them. They all seem engaged in a discussion. The room has a bright atmosphere with natural light streaming in from the side window.

Hire your next Active Directory today.

Post a job

Explore Interview Questions by Title & Skill

No search results found