Advertisements

Active Directory Domain Services: Installation & Configuration

-

|

What is Active Directory Domain Services?

Active Directory Domain Services (AD DS) is at the core of Microsoft’s Directory Services implementation – Active Directory. So we can define AD DS as a Microsoft Directory service that manages objects and manages access to them. Examples of objects are users, computers, printers.

This step by step guide will discuss the requirements for installing AD DS in Windows Server 2016. It will then show you how to install Active Directory Domain Services. Finally, the guide will discuss some important AD DS configurations and administration.

Prerequisites for Installing AD DS

  • The Server MUST be configured with a static IP address.
  • Existence of a DNS Server that support the service (SRV) resource record type and dynamic update protocol.

How to Install Active Directory Domain Services

Before I show you how to install AD DS, first I will show you how to set static IP address on your server. Then I will show you how to install and configure DNS.

How to Configure Static IP Address in Windows Server 2016.

As I said earlier, one of the requirements of installing Active Directory Domain Services is that the server must be configured to use a static IP address. Below are the steps to complete this task:

  • Open Server Manager (the quickest way to open server manager is to click the search icon on the task bar then search server manager.
  • Beside “Ethernet” click “IPv4 address assigned by DHCP, IPv6 enabled”. This will open available NICs.

Advertisements



AD DS Configure Static IP Address
  • Click the NIC you wish to set static IP address for. Mine is Ethernet Network 3….
Active Directory Domain Services Nic
  • The NIC status page will open (see image below). Click Properties (the highlighted portion of the image).
  • The image below will open. Highlight “Internet Protocol Version 4 (TCP/IPv4)” then click Properties.
  • The page to configure IP address appears (see sample image below). Select “Use the following IP address” then enter an IP address, a Subnet Mask and a Default Gateway. Also, select “Use the following DNS Servers”. When you finish, to save your changes click Ok.
AD DS - set static IP addres
  • To close the opened dialogue boxes, click Close twice.

The first requirement for installing AD DS is now complete. Next, I will show you how to install and configure DNS for Active Directory Domain Services.


Install DNS and Active Directory Domain Services Roles

The next prerequisite for installing Active Directory Domain Services is DNS. To make it faster we will install DNS and AD DS roles at the same time. But we will configure DNS before promoting the server to a Domain Controller.

  • From Server Manager, click Manage then select Add Roles and Features.
Active Directory Domain Services - install DNS Role
  • On the “Before you begin” page, click Next.
  • On the “Select Installation type” select “Role-based or feature-based installation” and click Next.
  • Next, on the “Select Destination server page”, select the server you wish to install DNS and AD DS and click Next.
  • Next page presents option to select the roles you wish to install. Check the boxes beside Active Directory Domain Services and DNS Server. Click Next.
Select AD DS and DNS Server
  • On the “Select features” page, click Next. Note the information provided in the “DNS Server” page then click Next.
  • Also note the information provided in the AD DS page and click Next to continue.
  • Finally, you are on the “Confirm your installation selection” page. Check the box “Restart the destination server automatically if required”, review your selected feature then click Install.

Wait for the roles to install. When the installation completes move to the next step.

Configure DNS For Active Directory Domain Services (Forward Look up Zone)

The next step is to configure Forward Lookup DNS Zone. To complete this task, follow the steps below:

  • From Server Manager, click Tools, then select DNS.
Configure DNS For AD DS
  • Next, create a Forward Look up Zone. On the DNS Manager console, expand your server name (mine is DCSRV1).
  • Right-click Forward Lookup Zones and click New Zone.
Create Forward Look up zone
  • The New Zone wizard will open. To proceed, click Next.
Configure DNS For Active Directory Domain Services - New Zone welcome screen
  • On the Zone Type page, select Primary zone and click Next.
  • Next, enter the DNS zone name in Fully Qualified Domain Name (FQDN) format. In my example, iTechGuides.local – it could also be .com. To proceed, click Next.

Advertisements



  • Accept the suggested zone file name and click Next.
Configure DNS for AD DS - zone file name
  • On the Dynamic Updates page, accept the default, Do not allow dynamic updates. To proceed, click Next.
After promoting your server to a Domain Controller, you will convert your DNS zones to Active Directory integrated then configure them for secure dynamic updates.
  • To create your primary zone, click Finish.

Configure DNS For Active Directory Domain Services (Reverse Look up Zone)

Next, you need to create a reverse look up zone. The steps below will guide you through this task.

  • Still on the DNS Manager right-click Reverse Lookup Zones and click New Zone. On the welcome screen, click Next.
  • On the Zone Type page, ensure that Primary Zone is selected then click Next.
  • Select IPv4 reverse Lookup Zone then click Next.
  • Enter the Network ID portion of your IP address. The wizard will automatically create the reverse lookup zone name. To Proceed, click Next.
  • Review the reverse lookup zone file name then click Next.
Create Reverse lookup DNS zone for Active Directory Domain Services
  • On the Dynamic Updates page, accept the default, Do not allow dynamic updates. To proceed, click Next.
  • To create your reverse lookup zone, click Finish.

Configure Additional Prerequisites

Before you promote your server you need to compete two more tasks. First, update the server to use its own DNS. To complete the task, open the NIC and change the DNS settings to the local server IP.

Next, create an A record for the server. Open DNS Manager, right-click iTechGuides.local zone and select New Host (A or AAAA…).

AD DS
  • The New Host dialogue box opens. Enter the name of the server then its IP addres. Finally, check the box Create associated pointer (PTR) record. To create the record, click Add Host.

Promote Your Server to a Domain Controller

Now that you have configured the prerequisites for AD DS, it is time to promote your server to a Domain Controller. The steps below will guide you through this task.

  • Back to Server Manager, on the top right corner of the page, click the yellow amber notification. Then click Promote this server to a domain controller.
  • On the Deployment Configuration page, select Add a new forest. Then on the Root domain name enter the exact name of the forward lookup zone you created earlier. To Proceed, click Next.

However, I selected Windows Server 2016 for Forest and Domain Functional levels because I am in a test environment.

  • Finally, for this page, enter the Directory Services Restore Mode (DSRM) password. Then click Next.
Active Directory Domain Services - Promote a Server to a DC.
  • Ignore the warning message on the DNS Options page. Click Next. However if you are adding a domain to an existing domain, read the warning message.
  • On the Additional Options page, accepts the suggested NetBIOS domain name and click Next.
  • Accept the suggested Paths and click Next. However, if you are in a production environment, you may want to move the paths to a drive other than drive C.

Advertisements



AD DS Database, logfile and SYSVOL Paths
  • Review your options then click Next. The wizard will run some prerequisite checks. Finally, review the results of the check then click Install.
Active Directory Domain Services - promote server to Domain Controller. Prerequisite check

Once the server promotion is completed, the server will reboot.

Convert DNS Zones to Active Directory Integrated

Before we move on to AD DS configuration, let’s convert the DNS zones we created earlier to Active Directory integrated zones. The steps below will guide you through the task.

  • From Server Manager, Open DNS. Expand the Server Name, then expand Forward Lookup Zones. Finally, right-click your forward lookup zone name and select Properties.
  • Beside Primary, click Change. Check the box Store the zone in Active Directory...Then click Ok. Click Yes to confirm.

Repeat the task for the Reverse Lookup Zone.

Next, configure Secure Dynamic updates. On the Properties of the zone, General tab, click the drop-down beside Dynamic updates. Select Secure Only. Finally, to save your changes click Ok.

Configure AD DS

Now that we have installed Active Directory Domain Services and promoted the server to a DC, next step is to perform some AD configurations.

Transferring RID, Infrastructure, PDC Operations Master Roles

If you want to learn about Operations Master Roles, read my articles on
What is Active Directory (Top 50 AD Questions Answered) and Active Directory: Concepts, Installation & Administration

To transfer RID, Infrastructure and PDC Emulator FSMO Roles open Active Directory Users and Computers. You can access AD Users and Computers via Server Manager, Tools. Then follow the steps below:

  • First, connect to the Domain Controller you wish to transfer the roles to. Then right-click Active Directory Users and Computers and click Change Domain Controller.
  • Next, Select “This Domain Controller or AD LDS instance”. Then select the DC you wish to transfer the role to and click Ok.
I have just one DC in my lab. However, in production AD environment, there should be other DCs in the list below.
  • To change the Operations Master Roles, right-click the domain name then click Operations Masters.
  • To transfer the RID, PDC or Infrastructure Master roles, click the RID, PDC or Infrastructure tabs. Next, click Change.

Advertisements



Transferring Domain Naming Master

To transfer the Domain Naming Master, open Active Directory Domains and Trusts.

Tip
Change to the DC you wish to transfer to before proceeding to the next task.
  • Right-click Active Directory Domains and Trust, then select Operations Masters.
  • Then to transfer the role, click Change.

Transferring the Schema Master Role

  • Open command prompt as Admin and run the command below
 regsvr32 schmmgmt.dll 

See result below:

  • Next step, open MMC. Then click File, Add or Remove Snap-in.
  • The AD Schema MMC loads

There are so many more configurations you can perform in Active Directory.

That is it for this tutorial. If you have any questions or comments kindly use the “Leave a Reply” below.

Advertisements



Quick Links to Related Tutorials

Additional Resources and References


LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST DEALS

Exclusive Student Offer_Save 10% on selected Surface devices

FEATURED POSTS

How to Change Administrator Name in Windows 10 (4 Methods)

How to Change Administrator Name in Windows 10

Introduction This guide demos how to change administrator name in Windows 10. There could be...
How to Setup WhatsApp Auto Reply in an Android Phone

How to Setup WhatsApp Auto Reply in an Android Phone

Introduction This guide demos how to setup Whatsapp auto reply in an Android phone. Steps...
How to Set Out of Office Auto Reply in Outlook, Outlook.com and Gmail

How to Set Out of Office Auto Reply in Outlook, Outlook.com and Gmail

Introduction This guide demos how to set out of office auto reply in Outlook, Outlook.com and Gmail.
How to Take Ownership of Folder in Windows 10

How to Take Ownership of Folder in Windows 10 (2 Methods)

Introduction This guide demos 2 methods to take ownership of folder in Windows 10. Options to...
How to Install Windows Server 2019 from USB

How to Install Windows Server 2019 from USB

Introduction This guide demos how to install Windows Server 2019 from USB. Steps to Install...

ADVERTISEMENTS

TRENDING POSTS

Remote Desktop Connection

Remote Desktop Connection an Internal Error Has Occurred [Fixed]

Introduction I recently received the error message "Remote Desktop Connection an Internal Error Has Occurred". It was strange because...

Find My Samsung: Register and Use Samsung Find my Mobile

Introduction Ever wondered how you could find your Samsung phone if you lost it? Find my Samsung or Samsung...
What is the Difference Between PowerShell and CMD?

Windows Powershell vs CMD: Differences and Similarities

Introduction This short guide compares Windows PowerShell vs CMD (Windows command prompt). I will cover the history and nature...
Spotify No Longer Supports this Version of Microsoft Edge

Spotify No Longer Supports this Version of Microsoft Edge [Fixed]

Introduction When you open Spotify web player on Microsoft Edge, you may receive the error message "Spotify No Longer...
Windows 10 Won't Boot

Windows 10 Won’t Boot With Black Screen? 3 Ways to Fix It

Why Won't Windows 10 Boot Up? If your Windows 10 stops with a black screen, the first question in...

BEST OF ITECHGUIDES

RSAT Tools in Windows 10 Explained: Plus How to Install RSAT

RSAT Tools in Windows 10 Explained: Plus How to Install RSAT

Introduction Starting from October 2018 (1809) update, RSAT Tools became part of Windows 10. From this version of Windows...
powershell try catch

Powershell Try Catch Finally and Error Handling

Introduction Powershell Try Catch blocks are used to handle terminating errors in PowerShell scripting. When use Powershell Try Catch...
How to Change Time Zone in Windows 10 (4 Methods)

How to Change Time Zone in Windows 10 (4 Methods)

Introduction This guide demos how to change time zone in Windows 10. Options to Change Time...
WhatsApp PC

How to Use WhatsApp on Your PC

Introduction Wondering whether you can use WhatsApp on your PC? Yes you can! Since I started using WhatsApp on...
Websites Like Craigslist for Apartments

Top 5 Websites Like Craigslist for Apartments

Craigslist is a local classified Ads website with 7 sections including apartment rent. It is a brilliant site but using other websites...

RECENT POSTS

C:\G-Drive\Work Tools\Products Portal\1. New Business\2. Content Sites\1. iTechGuides.com\Posts\1. HOW TO\Microsoft\MS Office\Microsoft Word\how to add more rows to a table in word

How to Add More Rows to a Table in Word and Google Docs

Introduction This guide demos how to add more rows to a table in Word. It also has a...
How to Create a Bar Chart in Excel and Google Sheets

How to Create a Bar Chart in Excel and Google Sheets

Introduction This guide demos how to create a bar chart in Excel and Google Sheets. A bar chart is...
How to Change Administrator Name in Windows 10 (4 Methods)

How to Change Administrator Name in Windows 10

Introduction This guide demos how to change administrator name in Windows 10. There could be...
How to Create a Pie Chart in Excel and Google Sheets

How to Create a Pie Chart in Excel and Google Sheets

Introduction This guide demos how to create a pie chart in Excel and Google Sheets. A pie chart is...

iTechGuides’ Top 10 Online Games

The gaming world is getting bigger day by day. Many people are getting engaged to play online games worldwide.

How to Open Local Security Policy in Windows 10 (5 Methods)

Introduction This guide demos how to open local security policy in Windows 10. Options to...

How to Change Network from Public to Private in Windows 10

Introduction This guide demos 2 methods to change network from public to private in Windows 10.
How to Disable Touchpad in Windows 10 for Dell or HP Laptop

How to Disable Touchpad in Windows 10 for Dell or HP Laptop

Introduction This guide demos how to Disable Touchpad in Windows 10 for a Dell or HP laptop.

How to Change Account Picture in Windows 10 (2 Methods)

Introduction This guide demos 2 methods to change account picture in Windows 10. Windows 10...
How to Create Xbox Live Account

How to Create Xbox Live Account (2 Methods)

Introduction This guide demos 2 methods to create Xbox Live account. Options to Create Xbox...

ADVERTISEMENTS

MUST READ

powershell sleep

PowerShell Start-Sleep Command: Syntax, Examples

Introduction Powershell Sleep (Start-Sleep) Cmdlet is a very useful scripting tool. There may be instances when you want to...
How to Set Default Programs in Windows 10

How to Set Default Programs in Windows 10 (2 Methods)

Introduction This guide demos 2 methods to set default programs in Windows 10. As an...
dism /online vs /image

The Difference Between DISM /Online and DISM /Image Commands

What is DISM /Online vs /Image? In comparing DISM /online vs /image, while DISM /online targets the running operating...
Amazon Merch

Amazon Merch: Your Definitive Guide to Merch by Amazon

What is Amazon Merch? Merch by Amazon (MbA or Amazon Merch) is a T-shirt Print-On-Demand platform that allows you...
WhatsApp PC

How to Use WhatsApp on Your PC

Introduction Wondering whether you can use WhatsApp on your PC? Yes you can! Since I started using WhatsApp on...

LATEST DEALS

Exclusive Student Offer_Save 10% on selected Surface devices

By using this website you agree to accept our Privacy Policy and Terms & Conditions