This is because AD-integrated zones cannot function as secondary zones...
Active Directory service is used to store information about the network resources across a domain and also centralize the network.
Windows 2000 Active Directory data store, the actual database file, is %SystemRoot%\ntds\NTDS.DIT
NTDS.DIT
At Active Directory configuration partition
The role of ESE in an active directory is to store and retrieve data through indexed and sequential access.Its the data storage technology from Microsoft.
The schema is the Active Directory component that defines all the objects and attributes that the directory service uses to store data.
Ad lds
Verizon Directory Store. has written: 'Vienna (WP) Item #0AXWIEAXWP'
Active Directory will represent a major advance over NT 4.0's simple domain model, since the domains within Active Directory will be able to form a multi-level tree structure.Users will be able to establish two-way transitive trust relationships among these domains. Lower-level domains trust all the higher-level domains within the hierarchical tree. This arrangement will make trust relationships easier to manage and will make possible the delegation of administrative authority from higher to lower levels within the tree.Active Directory will bear on security in two ways.First, Active Directory will be the repository for security policy information for the enterprise. For example, Active Directory will be able to store domain-wide password restrictions and system access privileges.Second, Active Directory will incorporate the object-based security model, controlling each user or group's right to read or update objects within the directory. The directory will therefore be able to hold such important items as encrypted passwords and user certificates with the assurance that only authorized users will be able to read or change them.
There are many components within Exchange that require access to Active Directory services, such as the information store and the message categorizer. The DSAccess component optimizes the communication between these components and Active Directory. The Exchange components that need to interact with Active Directory use DSAccess to retrieve Active Directory information rather than communicating directly with domain controllers and global catalog servers. As a result, DSAccess is therefore a very important part of Exchange. DSAccess is good for system performance, since it maintains a cache that effectively reduces the number of LDAP queries that these Exchange server components make to Active Directory. This is good for query speed as well as load reduction on both domain controllers and global catalog servers.
1. Click Start, Administrative Tools, and then click DNS to open the DNS console. 2. In the console tree, select the DNS server that you want to create a new DNS zone. 3. From the Action menu, click the New Zone option. 4. On the initial page of the New Zone Wizard, click Next. 5. Select the zone type that you want to create. The options are Primary, to create a new standard primary zone; Secondary, to create a copy of the primary zone; and Stub, to create a copy of zone but for only the NS record, SOA record, and the glue A record. 6. Select the default selected option - Primary zone. 7. To integrate the new zone with Active Directory, and if the DNS server is a domain controller; then you can select the Store the zone in Active Directory (available only if DNS server is a domain controller) checkbox. 8. Click Next. 9. On the Active Directory Zone Replication Scope page, accept the default setting for DNS replication: To all domain controllers in the Active Directory domain. Click Next. 10. Select the Forward lookup zone option on the following page which is displayed by the New Zone Wizard, and then click Next. 1 11. Enter a zone name for the new zone. Click Next. 1 12. The options that you can select on the following page pertain to dynamic updates. The Allow only secure dynamic updates (recommended for Active Directory) option is only available if you are using Active Directory-integrated zones. Click Next. 1 13. Click Finish to add the new zone to your DNS server.
15 custom attributes used to track information not store with active directory objects.