In this blog we will explore adding a child domain to an existing forest. The Active Directory Domain Services (AD DS) design team has finished the design phase for the new AD DS environment and now it is time to add a new child domain to the environment. Using Microsoft’s best practices the Domain Name System (DNS) has been configured to support the new child domain. The following steps have been accomplished:
- A Site named Arizona has been created and configured in AD DS. (see diagram below)
- A static IP Address was configured with the DNS entry pointing to the corporate DNS server.
- The server DNS suffix has been updated on the new DC computer name.
- DNS has been configured with the child domain.
- Verify the server has registered its host record for the new Domain. (see diagram below)
To install AD DS complete the following steps:
Use Server Manager to add the Active Directory Domain Services Role to install the Binaries to support the server becoming a Domain Controller.
- Launch Server Manager, select the Manage drop down menu, select Add roles and features.
- Review the Before You Begin page, Click Next.
- On the Select installation type page ensure Role-based or feature-based installation radial button is selected, click Next.
- On the Select destination server page Select the desired server from the Server Pool.
Note: The 2012 Server Manager allows roles and features to be installed remotely.
- Click on the Active Directory Domain Services box.
- The Add features that are required for Active Directory Domain Service dialog box pops up, select Add Features, click Next.
- Do not add any features on the Select features page, click Next.
- Review the Active Directory Domain Services information page, click next.
- The AD DS Binaries are now being installed, click Close to close the Installation progress dialog box.
10. If you close the above window you can click on the notification flag to check on installation status.
Note: The Binaries are now installed on the server to support this server becoming a Domain Controller. Use DCPROMO to promote this computer to a Domain Controller.
Using Server Manager to make this server a Domain Controller and install the replica domain controller.
- In previous versions of Windows Server you used DCPROMO to create the first Domain Controller. On Window Server 2012 running DCPROMO will result in the following dialog box. DCPROMO is still supported for unattended installations.
- In Server Manager Title bare click on the yellow triangle to perform post-deployment configuration of promote the server to a Domain Controller.
- Click on Promote this server to a domain controller to start the promotion wizard.
4. On the Deployment Configuration page complete the following tasks
- Select the Add a domain to an existing forest radial button.
- On the Select domain type drop down box select Child Domain.
- Fill in the Parent domain name box with the parent AD DS Domain Name.
- Fill in the desired New domain name.
- Click change to supply the credentials for a member of the Enterprise Admins group.
- Verify the entries change if needed, click Next.
- On the Domain Controller Options page De-select DNS or GC during this installation, Enter a desired DSRM Password, click Next.
Note: Because the server’s IP Address is in a different site defined in Active Directory Sites and Services, the site name has been pre-selected for that site.
- Verify the NetBIOS domain name and click Next.
- On the Paths page verify the desired locations of the Database, Log files and SYSVOL folders, change the locations is required, click Next.
- On the Review Options page, click Next.
Note: If an Unattended PowerShell installation script is desired, click view script and then save from the file drop down menu.
- The AD DS Configuration Wizard will perform and Prerequisite check before the installation can continue. After the check is completed successfully click Install.
10. The server will restart once the configuration has completed, the server is now a domain controller for the newly formed domain.
Verifying the installation of AD DS
- Logon to the Parent Domain’s First Domain Controller using the Administrator account credentials.
- Launch the DNS console and verify the creation of Service Records for the newly established domain controller. In the appropriate domain and site.
- Launch Active Directory Sites and Services, verify the new Domain Controller has populated the correct site.
Active Directory Domain Services is now installed and has established the child domain, until next time, RIDE SAFE!
To review the previous blogs visit: