Active Directory Diagram

Mastering the Foundation: Step-by-Step Active Directory Setup

AM

Assistant Technical Manager

Infrastructure & Cloud Solutions Expert

⏱️ 15 Min Read 📅 Last Updated: Jan 23, 2026 🏷️ Infrastructure

In the modern IT landscape, Active Directory Domain Services (AD DS) remains the definitive backbone of enterprise identity management. Beyond just a directory, AD DS is the engine that facilitates secure access, centralized control, and organizational scalability.

A poorly configured Domain Controller can lead to persistent DNS issues, replication failures, and security vulnerabilities. This guide provides a detailed walkthrough for installing and configuring AD DS, ensuring your environment is built on a rock-solid foundation.

The Goal

By the end of this post, you will have a fully functional Domain Controller (DC) that handles:

  • Centralized Authentication: Managing users, computers, and groups in one database.
  • DNS Resolution: Vital for service location and internal networking.
  • Group Policy Management: For enforcing security standards across your environment.

Prerequisites: The Golden Rules

Skipping these "Day Zero" tasks is the leading cause of promotion failures. Before the installation, verify your server's local configuration.

NETWORK Static IP Address Configuration

DCs must never have dynamic IPs. Set a static IPv4 and set the Preferred DNS to 127.0.0.1 (Loopback).

SECURITY Administrator Password Complexity

The local admin becomes the Domain Admin. Use at least 12-15 characters with symbols and numbers.

IDENTITY FQDN Naming Convention

Avoid .local. Use a sub-domain of a domain you own, such as maharjan.com.np.

Active Directory Pre-Setup Configuration

Step 1: Install AD DS Roles

Open Server Manager > Add roles and features. Select Role-based or feature-based installation and check Active Directory Domain Services. Confirm adding features and install.

Server Manager - Role Installation Selection Server Manager - Role Installation Selection
Reboot the Server.

Step 2: Promote to Domain Controller

Click the Notifications Flag > Promote this server to a domain controller. Select Add a new forest and enter your Root Domain Name. Set your Functional Levels and enter a strong DSRM Password.

Deployment Configuration Screen - New Forest Setup Deployment Configuration Screen - New Forest Setup Deployment Configuration Screen - New Forest Setup

Step 3: DNS and NetBIOS Configuration

Proceed through the DNS delegation options. Verify the NetBIOS name and confirm the paths for the NTDS database, log files, and SYSVOL.

Paths Selection for NTDS and SYSVOL Paths Selection for NTDS and SYSVOL

Step 4: Review and Install

Review your selections and wait for the Prerequisites Check. Ensure you receive the green "All prerequisites checks passed successfully" message before clicking Install. The server will reboot.

Prerequisites Check - Successful Review Screen Prerequisites Check - Successful Review Screen Prerequisites Check - Successful Review Screen

Step 5: Verify Netlogon and Sysvol Shares

Post-reboot, log in as maharjan.com.np\Administrator. You must verify that the DC is sharing the required folders for authentication and Group Policy.

Verifying SYSVOL and NETLOGON Shares
net share
Verifying SYSVOL and NETLOGON Shares

Step 6: Verify Name Server Lookup

Resolve DNS with Host and Reverse DNS Record

nslookup maharjan.com.np
Resolve DNS with Host and Reverse DNS Record

To resolve the IP Address to Host Record, Create Reverse Zone:

Open DNS Manager Console: dnsmgmt.msc
Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone Create Reverse Zone

Reverse Zone Created for 192.168.0 Subnet. Pointer Record has been updated.

Resolved IP Address to Hostname: nslookup 192.168.0.2
Verify DNS with Host and Reverse DNS Record

To Resolved Hostname to IP address change localhost IP 127.0.0.1 to Static DNS IP (Self)

Verify DNS with Host and Reverse DNS Record
Resolved Hostname to IP Address : nslookup maharjan.com.np.
Verify DNS with Host and Reverse DNS Record

Step 7: AD Health Check & Diagnostics

Use dcdiag to verify the DNS health and service connectivity. All tests should return a "Passed" status.

# Check Core Services Get-Service -Name ntds,adws,dns,kdc,netlogon,lanmanserver,lanmanworkstation,dfsr,w32time | Select-Object DisplayName,Name, Status
Check AD Related Services - Status
# Comprehensive Health Test: dcdiag /v # Quick Health Check test: $results = dcdiag /v $results | Select-String "passed test|failed test"
Check DC Diagnosis Report - Status

"Struggling with deeper DC issues? I'm putting together a detailed breakdown of error codes and fixes over in the FAQs section to help you troubleshoot like a pro."

Conclusion

Deploying your first Domain Controller is a significant milestone in systems architecture. A successful installation provides the security and management framework required to scale your infrastructure securely. Moving forward, remember that Active Directory is a living database—regular health checks and a clean OU structure are essential to maintaining a stable environment.

#ActiveDirectory #WindowsServer #SysAdmin #CyberSecurity