Active Directory uses Lightweight Directory Access Protocol (LDAP) as an access protocol, which relies on the TCP/IP stack. The LDAP supports Kerberos authentication.
This protocol uses an inverted-tree hierarchical structure, so every entry has a defined position. This structure is called the Directory Information Tree (DIT). The Distinguished Name (DN) represents the full path of the entry.
The following diagram represents the different interaction between the users (Common Name (CN)). Filter groups are restricted to some applications: