Understanding directory-based security features
Both AD and AAD have several identity and security features built in to help prevent or mitigate threats. In this section, we'll look at some core security features of AD, as well as features available with both AAD Premium Plan 1 and AAD Premium Plan 2, that can be used to help protect organizations.
Active Directory
AD is an on-premises identity store service. It's used to authenticate and authorize computers and internal applications. The core functional container for a security boundary in AD is called a domain. A domain contains all of an organization's related security principals, groups, and other objects. Domains are grouped into trees, which are logical collections of related objects from either a security or organizational perspective. At the top level, forests are made up of one or more trees. The domains in a tree share a contiguous namespace. Each tree in a forest has a namespace, as shown in the following...