Synology Directory Server
DSM Version
7.4 7.3 7.2

Synology Directory Server

Overview

  • Centrally secures and manages identities of users, groups, and devices within an organization
  • Automates and integrates identity and access control into IT operations
  • Domain functional level: equal to Windows Server 2008 R2
  • Samba version: 4.10
  • Supports a single domain only
  • Supports custom NetBIOS domain names
  • After a domain is created, SMB signing will be enabled automatically, which may reduce read/write performance during SMB file transfer

User & Group Management

  • Maximum objects support: 100,000
    • The actual figure depends on the capability of your Synology NAS
  • Maximum groups that a user can join: 50
  • Supports roaming user profiles and home folder creation (Learn more)
  • Limitations: User and group names do not support special characters: {}|^[]?=:+/*()$!"#%&',;<>@\~`

Domain Controller Architecture

  • Supports setting up one primary domain controller and secondary domain controllers
    • The primary domain controller must be a read-write domain controller (RWDC)
    • A secondary domain controller can be either a RWDC or a read-only domain controller (RODC)
      • Supports up to one RWDC
      • Supports up to ten RODCs
  • The secondary domain controller only works with domains created by Synology Directory Server
  • Windows Servers that are deployed as RWDCs synchronize data to RODCs every five minutes
  • The list of user accounts authenticated on a RODC can only be displayed when the RODC is joined to a Windows AD

Domain Migration

  • Supports domain migration from Windows Server 2012 R2 or earlier versions

Client Support

  • Supports domain clients on
    • Microsoft Windows 7 and above
    • macOS
    • Linux (via Samba Winbind module)
  • Limitations: Binding of LDAP client accounts is not supported

Authentication & Security

  • Adopts Kerberos-based authentication
  • Supports TLS domain controller certification
  • Supports account single sign-on and Windows NTLM
  • Supports Active Directory group-based access controls
  • Increases account security via account lockout policies and password strength policies (e.g., expiration period, password length, and historical record comparison)

Management & Integration

  • Sets group membership and policies via RSAT (Learn more)
  • Integrated with DNS Server to register DNS settings upon domain creation
  • Supports audit logging in Log Center
  • Supports Synology High Availability for failover and continuous service availability
  • Limitations
    • The Active Directory module for Windows PowerShell is not supported
    • Distributed File System Replication (DFSR) is not supported

Backup & Restore

  • Supports scheduled backup and restoration of directory server configurations via Hyper Backup
  • Limitations
    • Backups of Synology Directory Server 4.10.15-0244 and above versions cannot be restored on DSM 6.2
    • Backups of Active Directory Server 4.4.5-0077 or earlier versions cannot be restored once the package is updated to Synology Directory Server 4.4.5-0086 or above. We recommend creating a new backup task for the updated package in Hyper Backup and running the task immediately