Home › Deploying domain controllers › Step 5

Cloning virtual domain controllers

Step 5 of 6 in Deploying domain controllers · video 9:28

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Since Windows Server 2012, a virtualised domain controller can be cloned instead of built from scratch, which helps when adding DCs quickly, recovering from a disaster, scaling a private cloud, building test labs or supplying branch offices. Cloning needs a hypervisor that supports the virtual machine generation identifier, such as Hyper-V from Windows Server 2012, guest DCs on Windows Server 2012 or later, and a PDC emulator on 2012 or later that is online, with a global catalog server, when clones first start. Both a domain admin and a Hyper-V admin are involved. The source DC is added to the Cloneable Domain Controllers group, its software is checked with Get-ADDCCloningExcludedApplicationList (with -GenerateXml to build CustomDCCloneAllowList.xml), DCCloneConfig.xml is created with New-ADDCCloneConfigFile, and the VM is exported and imported as copies. The lesson also covers automatic clone names, offline configuration of mounted VHDX files, and how the generation identifier decides between a normal start, cloning and DSRM.

Good to know: cloning needs a PDC emulator running Windows Server 2012 or later, not necessarily 2016, and other hypervisors such as VMware vSphere also provide the VM-generation identifier. Check each parameter of New-ADDCCloneConfigFile with Get-Help New-ADDCCloneConfigFile before you run the example.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which group must the source domain controller belong to before it can be cloned?

The Cloneable Domain Controllers group. Adding it there is how an AD DS administrator authorises that DC to be cloned.

2. What does Get-ADDCCloningExcludedApplicationList tell you, and what do you do with the result?

It lists apps and services on the source DC that are not known to support cloning. You remove them, or test them and, if they work after cloning, add them to CustomDCCloneAllowList.xml.

3. What happens if DCCloneConfig.xml specifies no computer name and no IP settings?

The clone gets an automatic name built from the first eight characters of the source name plus a CLnnnn suffix, and dynamic IP settings, so a DHCP server is needed and the clone stays in the source DC's site.

4. A clone with a DCCloneConfig.xml file starts on a hypervisor that provides no virtual machine generation identifier. What happens?

Cloning cannot be done safely, so the machine renames DCCloneConfig.xml and restarts in Directory Services Restore Mode as a safeguard until an administrator fixes the problem.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← Upgrading domain controllers to a newer Windows ServerNext: Best practices for virtualising domain controllers →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.