Skip to main content
AD Academy
From Zero: Network, Server and Domain
Beginner18 minLast updated: Topic 4 of 4

Setting up the first Domain Controller

From a clean Windows Server to an active Domain, step by step.

Not read

What you will learn here

  • 1. Preparing the server
  • 2. Installation and promotion
  • 3. Verifying everything is OK

Worth reading first:Workgroup vs Domain

The process consists of three stages: preparing the server, installing the DS role, and promoting the server to a .

1. Preparing the server

# Permanent name for server
Rename-Computer -NewName "DC01" -Restart

# Static IP address + self-pointing DNS
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 192.168.10.10 `
  -PrefixLength 24 -DefaultGateway 192.168.10.1
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 127.0.0.1
powershell

2. Installation and promotion

Install-WindowsFeature AD-Domain-Services -IncludeManagementTools

Install-ADDSForest -DomainName "lab.local" `
  -DomainNetbiosName "LAB" `
  -InstallDns `
  -SafeModeAdministratorPassword (Read-Host -AsSecureString "DSRM password")
powershell

3. Verifying everything is OK

Get-ADDomain
Get-ADDomainController
dcdiag /v
powershell
Architecture and Theory — Under the Hood

Setting up the first DC builds a new forest: creates the schema, the NTDS.dit file, establishes integrated DNS, and transfers all 5 FSMO roles to this server. This is a one-time operation in each forest — choosing the name and version is critical.

  • name: Not single-label, not .local in new projects (recommended subdomain of a public domain, e.g., ad.example.com).
  • Functional level: The highest that all DCs support.
  • DSRM Password — recovery password in Safe Mode. Store it in a safe.
  • After setup: Second DC immediately, backup, and no Snapshot of a production DC.
Practical Configuration (PowerShell / GUI)
# New Forest Setup
Install-WindowsFeature AD-Domain-Services,DNS -IncludeManagementTools
Install-ADDSForest -DomainName 'corp.local' -DomainNetbiosName 'CORP' \
  -ForestMode Win2016 -DomainMode Win2016 -InstallDNS \
  -SafeModeAdministratorPassword (Read-Host -AsSecureString) -Force

# Verification
Get-ADForest
Get-ADDomain
Get-ADDomainController
netdom query fsmo
powershell
Real-world Scenarios in an Organization
  • New forest for a new company — always at least 2 DCs with distributed FSMO roles.
  • Lab — Single DC + Snapshot allowed.
  • Company merger — New neutral forest and then ADMT to migrate objects.
Troubleshooting
dcdiag /v
repadmin /replsummary
Get-ADReplicationFailure -Target DC01
bash
  • Event 4013/4015 = DNS issue on DC. Event 2042 = DC not replicated for a long time (Tombstone Lifetime).
Glossary and Quick Command Line
  • 5 FSMO roles: Schema, Naming, RID, PDCe, Infrastructure.
  • DSRM = recovery mode.
  • SYSVOL = Shared folder with GPOs, replicated by DFSR.

Check yourself

Which DNS address should the first DC point to?

Was this page helpful?