Home › Deploying domain controllers › Step 1
Installing a domain controller from Server Manager
Step 1 of 6 in Deploying domain controllers · video 3:44
What you will learn
- The two stages: adding the AD DS role, then promoting the server
- Which answers the configuration wizard needs for a new forest or domain
- Default locations of the NTDS database, logs and SYSVOL folder
- What DSRM is and why its password matters
About this lesson
Promoting a server to a domain controller happens in two stages. First, Server Manager adds the Active Directory Domain Services (AD DS) role, which only puts the binaries on the disk. Second, the Active Directory Domain Services Configuration Wizard, opened from the link in Server Manager, turns the server into a domain controller for an existing domain, a new domain in an existing forest, or a new forest. The lesson goes through the decisions to make before running the wizard: the fully qualified DNS name and NetBIOS name of a new domain, the forest and domain functional levels, whether the server also runs DNS, hosts the global catalog or becomes a read-only domain controller (RODC), and the Directory Services Restore Mode (DSRM) password. It also gives the default locations of the database and logs (C:\Windows\NTDS) and SYSVOL (C:\Windows\SYSVOL), explains what DSRM is for, and notes that dcpromo.exe is obsolete from Windows Server 2012 onwards.
bcdedit /set safeboot dsrepair, and bcdedit /deletevalue safeboot to go back to a normal start.Check yourself
1. After you add the AD DS role in Server Manager, is the server already a domain controller?
No. Adding the role only installs the AD DS files; the server becomes a domain controller only after the Active Directory Domain Services Configuration Wizard has promoted it.
2. What happens to the global catalog option when you promote the first domain controller in a new forest?
It is ticked by default and cannot be cleared, because a forest needs at least one global catalog server for forest-wide searches and logons.
3. What does the forest functional level chosen in the wizard control?
It decides which forest-wide features are available and which operating systems domain controllers may run. It also sets the lowest domain functional level any domain in that forest can use.
4. You must restore the AD DS database from a backup and have restarted the domain controller into DSRM. Which credentials do you sign in with?
The DSRM password set during promotion. In DSRM the AD DS services are not running, so domain accounts cannot be checked and only the local restore-mode account works.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.