- Centrally secures and manages identities of users, groups, and devices within an organization
- Automates and integrates identity and access control into IT operations
- Domain functional level: equal to Windows Server 2008 R2
- Samba version: 4.10
- Supports a single domain only
- Supports custom NetBIOS domain names
- After a domain is created, SMB signing will be enabled automatically, which may reduce read/write performance during SMB file transfer
Synology Directory Server
Overview
User & Group Management
- Maximum objects support: 100,000
- The actual figure depends on the capability of your Synology NAS
- Maximum groups that a user can join: 50
- Supports roaming user profiles and home folder creation (Learn more)
- Limitations: User and group names do not support special characters: {}|^[]?=:+/*()$!"#%&',;<>@\~`
Domain Controller Architecture
- Supports setting up one primary domain controller and secondary domain controllers
- The primary domain controller must be a read-write domain controller (RWDC)
- A secondary domain controller can be either a RWDC or a read-only domain controller (RODC)
- Supports up to one RWDC
- Supports up to ten RODCs
- The secondary domain controller only works with domains created by Synology Directory Server
- Windows Servers that are deployed as RWDCs synchronize data to RODCs every five minutes
- The list of user accounts authenticated on a RODC can only be displayed when the RODC is joined to a Windows AD
Domain Migration
- Supports domain migration from Windows Server 2012 R2 or earlier versions
Client Support
- Supports domain clients on
- Microsoft Windows 7 and above
- macOS
- Linux (via Samba Winbind module)
- Limitations: Binding of LDAP client accounts is not supported
Authentication & Security
- Adopts Kerberos-based authentication
- Supports TLS domain controller certification
- Supports account single sign-on and Windows NTLM
- Supports Active Directory group-based access controls
- Increases account security via account lockout policies and password strength policies (e.g., expiration period, password length, and historical record comparison)
Management & Integration
- Sets group membership and policies via RSAT (Learn more)
- Integrated with DNS Server to register DNS settings upon domain creation
- Supports audit logging in Log Center
- Supports Synology High Availability for failover and continuous service availability
- Limitations
- The Active Directory module for Windows PowerShell is not supported
- Distributed File System Replication (DFSR) is not supported
Backup & Restore
- Supports scheduled backup and restoration of directory server configurations via Hyper Backup
- Limitations
- Backups of Synology Directory Server 4.10.15-0244 and above versions cannot be restored on DSM 6.2
- Backups of Active Directory Server 4.4.5-0077 or earlier versions cannot be restored once the package is updated to Synology Directory Server 4.4.5-0086 or above. We recommend creating a new backup task for the updated package in Hyper Backup and running the task immediately