Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An Active Directory domain tree is a group of related domains that share a schema and configuration, form a contiguous hierarchical name space, and are connected by trust relationships. A forest can contain one or more trees, making the forest the broader logical structure.

How an Active Directory tree is structured

Microsoft defines a domain tree as several domains that share a common schema and configuration while forming a contiguous namespace. In practical terms, each child domain extends the DNS-style name of its parent.

For example, contoso.com could be a root domain and sales.contoso.com a child domain. This is an illustrative naming example: the child name continues the parent’s namespace, so the domains belong to the same tree. Microsoft’s Domain Trees documentation describes Active Directory as a set of one or more trees.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where a tree fits in the AD DS hierarchy

  • Forest: The broadest logical structure. It can contain one or more domain trees. Domains in a forest share schema, configuration, and a global catalog, and are connected by automatic two-way transitive trusts.
  • Domain tree: A grouping of domains with a contiguous namespace and trust relationships.
  • Domain: A directory partition and administrative unit within the forest.
  • Organizational unit (OU): A container within a domain, commonly used to organize objects and support administration or delegation.

Microsoft’s Active Directory logical model describes these structures for Windows Server 2025, 2022, 2019, and 2016. A tree is not the same thing as a forest: a tree groups domains by their namespace and trust links, while the forest encompasses the trees and shared directory structure.

#1 Best Overall
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

How names and trusts relate

The namespace and trust relationships are two connected ways to understand a tree. The names show how domains fit hierarchically; trusts establish relationships between domains. Microsoft describes the Windows 2000 trust model as hierarchical and transitive, and domains within a forest are automatically linked by two-way transitive trusts.

A contiguous name does not, by itself, grant a user permission to access a resource in another domain. Trusts provide a path for authentication relationships; resource permissions still determine what an authenticated user may access.

Why DNS matters

Active Directory Domain Services (AD DS) relies on DNS name resolution. DNS lets clients locate domain controllers and enables domain controllers hosting the directory service to communicate. DNS provides the name-resolution foundation; AD DS defines the directory objects, domains, and trust relationships. See Microsoft’s DNS overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A tree is logical, not a physical network diagram

The tree describes the logical organization of domains, not the number or placement of domain controllers. AD DS is distributed: domain controllers in a domain store and replicate that domain’s directory information. Their locations, replication arrangements, and the organization’s network topology are separate physical deployment considerations. Microsoft’s Active Directory Domain Services overview explains the directory service and domain-controller role.

The definition does not mean an organization needs multiple domains or trees. Whether to use additional domains is a design decision tied to administrative and operational requirements, including replication needs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.