The process consists of three stages: preparing the server, installing the DS role, and promoting the server to a .
1. Preparing the server
# Permanent name for server
Rename-Computer -NewName "DC01" -Restart
# Static IP address + self-pointing DNS
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.10.10 `
-PrefixLength 24 -DefaultGateway 192.168.10.1
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 127.0.0.1powershell2. Installation and promotion
Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
Install-ADDSForest -DomainName "lab.local" `
-DomainNetbiosName "LAB" `
-InstallDns `
-SafeModeAdministratorPassword (Read-Host -AsSecureString "DSRM password")powershell3. Verifying everything is OK
Get-ADDomain
Get-ADDomainController
dcdiag /vpowershellArchitecture and Theory — Under the Hood
Setting up the first DC builds a new forest: creates the schema, the NTDS.dit file, establishes integrated DNS, and transfers all 5 FSMO roles to this server. This is a one-time operation in each forest — choosing the name and version is critical.
- name: Not single-label, not .local in new projects (recommended subdomain of a public domain, e.g., ad.example.com).
- Functional level: The highest that all DCs support.
- DSRM Password — recovery password in Safe Mode. Store it in a safe.
- After setup: Second DC immediately, backup, and no Snapshot of a production DC.
Practical Configuration (PowerShell / GUI)
# New Forest Setup
Install-WindowsFeature AD-Domain-Services,DNS -IncludeManagementTools
Install-ADDSForest -DomainName 'corp.local' -DomainNetbiosName 'CORP' \
-ForestMode Win2016 -DomainMode Win2016 -InstallDNS \
-SafeModeAdministratorPassword (Read-Host -AsSecureString) -Force
# Verification
Get-ADForest
Get-ADDomain
Get-ADDomainController
netdom query fsmopowershellReal-world Scenarios in an Organization
- New forest for a new company — always at least 2 DCs with distributed FSMO roles.
- Lab — Single DC + Snapshot allowed.
- Company merger — New neutral forest and then ADMT to migrate objects.
Troubleshooting
dcdiag /v
repadmin /replsummary
Get-ADReplicationFailure -Target DC01bash- Event 4013/4015 = DNS issue on DC. Event 2042 = DC not replicated for a long time (Tombstone Lifetime).
Glossary and Quick Command Line
- 5 FSMO roles: Schema, Naming, RID, PDCe, Infrastructure.
- DSRM = recovery mode.
- SYSVOL = Shared folder with GPOs, replicated by DFSR.