10 ready-to-implement PowerShell scripts to make AD management easy!

Active Directory Objects

AD object classification

Active directory objects can be classified into two broad types.

1. Security principal objects

2. Resources

Security principal objects

The objects that can be authenticated by AD are called security principal objects. These objects have unique identifiers across the domain called SIDs (security Identifier). User accounts, computer accounts and security groups are the security principal objects in AD.


Objects that are used by the security principal objects such as printers etc. are called resources in AD.

Active Directory Hierarchy: Container and Leaf Objects

Active Directory is, in fact, a hierarchical arrangement of objects. Such an arrangement is possible because AD allows some of its objects to contain other AD objects.

In other words, an AD object can either be a container or a leaf.

  • Container objects: These Roles are objects that encapsulate other objects e.g.  OU, Domain etc.
  • Leaf objects: These objects do not encapsulate other objects. e.g. User, computer etc.
Related posts
Active Directory Objects

Active Directory User properties – General tab

Active Directory Objects

Active Directory (AD) Computer Object

Active Directory Objects

Active Directory Computer Objects Tabs

Active Directory Objects

Active Directory Computer Object Management


There are over 8,500 people who are getting towards perfection in Active Directory, IT Management & Cyber security through our insights from Identitude.

Wanna be a part of our bimonthly curation of IAM knowledge?

  • -Select-
  • By clicking 'Become an insider', you agree to processing of personal data according to the Privacy Policy.