Skip to main content
AD Academy
DHCP and Network Preparation
Intermediate16 minLast updated: Topic 1 of 5

DHCP and Integration with Active Directory

Authorization in AD, Scopes, Options and Dynamic DNS Updates.

Not read

What you will learn here

  • The DORA Process
  • DHCP Authorization in AD
  • Scope and Options

DHCP (Dynamic Host Configuration Protocol) assigns clients an IP address, Subnet Mask, Gateway, and DNS addresses. In a environment this is critical: if the client receives an incorrect DNS, it simply won't find the and won't be able to join the Domain or log in.

The DORA Process

הלקוח ללא כתובת IP משדר Discover ב־Broadcast. שרת ה־DHCP, שמאושר (Authorized) ב־Active Directory, מחזיר Offer עם כתובת פנויה. הלקוח שולח Request על ההצעה, והשרת מסיים ב־Acknowledge עם Lease לזמן מוגדר. יחד עם ה־ACK מגיעות Options: 003 שער ברירת מחדל, 006 שרתי DNS פנימיים, ו־015 שם ה־DNS Domain.

  • Discover — the client broadcasts and looks for a DHCP server.
  • Offer — the server offers an available IP address.
  • Request — the client formally requests the offer.
  • Acknowledge — the server confirms and grants a Lease for a set time.

DHCP Authorization in AD

A Windows-based DHCP server that is part of the must be Authorized in . The server checks the NetServices object in the Configuration Partition, and if it isn't authorized — the DHCP service simply won't assign addresses. This is a basic protection mechanism against unapproved servers.

Scope and Options

  • Scope — the range of addresses the server is allowed to assign on a given network.
  • Exclusion Range — addresses reserved for servers and network equipment.
  • Reservation — a fixed address for a client based on its MAC address.
  • Option 003 — Default Gateway.
  • Option 006 — DNS Servers (must point to the internal DC/DNS).
  • Option 015 — DNS Name, for example lab.local.

Dynamic DNS Updates

DHCP can update A and PTR records in DNS on behalf of the client. In an environment, it's recommended to configure dedicated Credentials (a regular service account, not a Admin) for performing the updates, and to enable Secure Dynamic Updates on the DNS zone so only the record owner can change them.

לאחר סיום DORA וקבלת Lease, שרת ה־DHCP פונה לשרת ה־DNS שרץ על ה־Domain Controller בזון AD-Integrated ומעדכן עבור הלקוח רשומת A (למשל PC01 לכתובת 10.0.0.25) ורשומת PTR בזון ההפוכה. העדכון מתבצע עם DHCP Credentials — חשבון שירות רגיל ולא Domain Admin — ובזון מופעל Secure Dynamic Updates כך שרק בעל הרשומה יכול לשנות אותה. הגדרת DNS חיצוני ב־Option 006 שוברת את איתור ה־Domain Controller דרך רשומות SRV.

Architecture and Theory — Under the Hood

The DHCP server in Windows Server integrates two security mechanisms with : Authorization (server approval with AD so that only authorized DHCPs respond) and DNS Dynamic Updates with service authentication.

  • Authorization is written in the Configuration Naming Context and is only performed by Enterprise Admin.
  • Built-in groups: DHCP Administrators (management), DHCP Users (read-only).
  • DHCP + DNS Credentials — Dedicated service account for DDNS registration, not Network Service.
  • DHCP Failover (Hot Standby / Load Balance) from Server 2012 onwards.
Practical Configuration (PowerShell / GUI)
# Authorization with AD
Add-DhcpServerInDC -DnsName dhcp01.corp.local -IPAddress 10.0.0.5

# Configure dedicated DDNS account
Set-DhcpServerDnsCredential -Credential (Get-Credential CORP\svc_dhcp)

# Failover between two servers
Add-DhcpServerv4Failover -Name 'HQ-Failover' -ScopeId 10.0.10.0 \
  -PartnerServer dhcp02.corp.local -SharedSecret 'S3cret!' -Mode HotStandby
powershell
Real-world scenarios in an organization
  • Split-Scope between two branches for load distribution.
  • Separate Scope for guests (Guest VLAN) with a short lease of one hour.
  • Reservations for servers and printers to get a static IP via DHCP.
Diagnosis and Troubleshooting
Get-DhcpServerInDC              # Authorized Servers
Get-DhcpServerv4Scope           # Active Scopes
Get-DhcpServerv4Failover        # Failover Status
Get-DhcpServerv4Statistics      # Address Usage
powershell
  • Event 1059 = Rogue DHCP.
  • Event 1046 = Server is not authorized with .
  • Event 20073 = DDNS failed — password or permissions.
Glossary and Quick Command Line
  • Authorized DHCP + DDNS Credentials + Failover = minimal professional deployment.

Check yourself

What happens to a DHCP server in the Domain that hasn't been Authorized in AD?

Which DHCP Option sets the DNS servers for a client?

Was this page helpful?