Home › Deploying domain controllers › Step 1

Installing a domain controller from Server Manager

Step 1 of 6 in Deploying domain controllers · video 3:44

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Promoting a server to a domain controller happens in two stages. First, Server Manager adds the Active Directory Domain Services (AD DS) role, which only puts the binaries on the disk. Second, the Active Directory Domain Services Configuration Wizard, opened from the link in Server Manager, turns the server into a domain controller for an existing domain, a new domain in an existing forest, or a new forest. The lesson goes through the decisions to make before running the wizard: the fully qualified DNS name and NetBIOS name of a new domain, the forest and domain functional levels, whether the server also runs DNS, hosts the global catalog or becomes a read-only domain controller (RODC), and the Directory Services Restore Mode (DSRM) password. It also gives the default locations of the database and logs (C:\Windows\NTDS) and SYSVOL (C:\Windows\SYSVOL), explains what DSRM is for, and notes that dcpromo.exe is obsolete from Windows Server 2012 onwards.

Good to know: pressing F8 at start-up is rarely practical on current servers. To start a domain controller in Directory Services Restore Mode, use System Configuration (msconfig, Boot tab, Safe boot, Active Directory repair) or bcdedit /set safeboot dsrepair, and bcdedit /deletevalue safeboot to go back to a normal start.

Check yourself

Answer in your head first, then open each question to see the answer.

1. After you add the AD DS role in Server Manager, is the server already a domain controller?

No. Adding the role only installs the AD DS files; the server becomes a domain controller only after the Active Directory Domain Services Configuration Wizard has promoted it.

2. What happens to the global catalog option when you promote the first domain controller in a new forest?

It is ticked by default and cannot be cleared, because a forest needs at least one global catalog server for forest-wide searches and logons.

3. What does the forest functional level chosen in the wizard control?

It decides which forest-wide features are available and which operating systems domain controllers may run. It also sets the lowest domain functional level any domain in that forest can use.

4. You must restore the AD DS database from a backup and have restarted the domain controller into DSRM. Which credentials do you sign in with?

The DSRM password set during promotion. In DSRM the AD DS services are not running, so domain accounts cannot be checked and only the local restore-mode account works.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← About this pathNext: Installing a domain controller on Server Core →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.