Directory service

A central, hierarchical store of identities and resources and their attributes, such as users, groups and devices, that systems query to identify, authenticate and authorise.

A directory service holds information about the people, groups, devices and services in an organisation, arranged in a hierarchy and described by attributes. Systems across the network query it rather than keeping their own user lists, so an account created, changed or disabled in the directory is reflected wherever the directory is consulted, although sessions and tokens already issued can outlive the change. Its data model descends from the X.500 series of standards, and LDAP is the protocol commonly used to read and update it. Enterprise directories commonly pair the store with Kerberos for authentication.

The directory is the backbone of centralised identity. It supports single sign-on inside one organisation, gives groups and roles one authoritative home, and lets deprovisioning happen at one point. The same centralisation makes it a high-value target, because whoever controls the directory can create accounts, change group membership and reset credentials wherever it is trusted. It is protected with tight administrative access, replication for availability, and monitoring of changes to privileged groups.

Exam relevance: a scenario is likely to describe a central store that many systems consult for users and groups, and ask what it is or which protocol reads it. Candidates are expected to link the directory to X.500 and LDAP, and to see it as both the foundation of centralised access control and a potential single point of compromise.