Adding a Windows Server 2012 R2 Domain Controller to a New Forest

Adding a Windows Server 2012 R2 Domain Controller to a New Forest

It doesn't come as a surprise that most IT teams are still running domain controllers (DC) on Windows Server 2008 and Windows Server 2008 R2. It is reliable and secure when it comes to Active Directory Domain Services (AD DS). However, a certain wave of change is crashing down on the IT industry as enterprises are now shifting from older to newer versions of Windows Server. This wave of change has gained strong traction, primarily based on the features offered by the upgrade. It includes system benefits like hybrid cloud support, storage enhancements, and Virtual Machine (VM) portability. Apart from these upgrades, Windows 2012 R2 DC is also being incorporated as a response to the constant advancements in technology and to keep the operations of AD up to date for smooth and swift functionality. 


RECOMMENDED INFORMATION TO KNOW 

Before starting the process of set-up and installation, the user needs to be aware of the minimum system requirements for Windows Server 2012.

 

Requirement

Value

Processor

1.4 GHz, 64-bit processor

RAM

512 MB

Free disk space requirements

32 GB

Screen resolution

800 x 600 or higher

Miscellaneous

DVD drive, keyboard, Internet access

The user must also be aware of a handful of prerequisites in order to execute the installation of AD DS properly. Knowing the following information before starting the installation of AD DS, and/or adding a Windows Server 2012 R2 DC is substantial:

 

To have more than one writable DC

Any process can sometimes fail for various reasons. A failed DC can impose multiple problems for the users on different levels. Therefore, having an extra DC will enable users to log on and perform their routine tasks. 

 

Knowing the fully qualified domain name

During the planning of the deployment of the first DC in a new forest, it is highly recommended to know the fully qualified domain name (FQDN) for the root domain of a new forest in Active Directory.

 

Denoting the forest and domain functional levels

The available AD DS domain or forest capabilities is determined by functional levels. The user is prompted to set the forest functional levels and then set the domain functional levels when they deploy a new forest. An important fact to know is that the user can set a domain functional level with a higher value than the forest functional level, but it is not possible to set the value of the domain functional level lower than the forest functional level.

 

Knowing the app location, log files, and SYSVOL folder

These three requisites are mandatory to know when planning the deployment of the first DC in a new forest in Active Directory as they determine where your AD DS is going to be operated from and the storage of log files (record of events like usage patterns and communication between principals).

 

A static IP address

The user needs to make sure that a static IP address is assigned to a server before the server can be promoted.

 

PROCESS OF ADDING A WINDOWS 2012 R2 DC TO A NEW FOREST 

Before the process of adding the DC begins, there are two mandatory steps that need to be performed:

 

    1.  The user needs to set up and install the Windows Server 2012 machine.
    1.  The IP address of the new server needs to be configured in order to correspond to the target domain.

 

STEP 1: INSTALL AD DS AND SET UP FUNCTIONALITY (TAB LABEL: ADD ROLES AND FEATURES WIZARD)

 

Open the server management console and click on Add Roles and Features. The wizard window should open. In this window, here's what the user needs to do under each section:

 

  • Before You Begin: Click Next.

  • Installation Type: On this page, choose Role-Based of Featured-Based Installation, and then click Next.

  • Server Roles: A pop-up should appear. In that pop-up, click on Add Features to accept the default features required for AD DS, and then click Next.

  • Features Page: The features page does not need any configuration for a new domain controller and, therefore, can be left unchanged by simply clicking on Next.

  • AD DS: This page is purely informative and does not pose any requirements. Simply click Next.

  • Confirmation: The Confirm Installation Selections page should now appear. Click Install to proceed. The installation will take a couple of minutes. (Note: Check the box that states Restart the destination server automatically if required if the user wants to automate the task of resetting the target server.)

  • Results: The progress bar and the text below lets the user know if the installation was completed. Click on the Close button once the installation is complete.

 

STEP 2: PROMOTE THE SERVER TO DC (TAB LABEL: AD DS CONFIGURATION WIZARD)

 

A yellow-colored triangle highlighted by an exclamation mark should appear on the dashboard after the installation is complete and the user has clicked the close button. Click on this notification to open a drop-down menu.

 

In the drop-down menu, select Promote this server to a domain controller. Once the AD DS Configuration Wizard tab is open, here's what the user needs to do under each section.

 

  • Deployment Configuration: As this is the first Windows 2012 R2 DC being added to the forest, the user should select Add a new forest, and enter the Root Domain Name. Click Next to proceed further.

  • Domain Controller Options: The user can leave the forest and domain functional level at Windows Server 2012 R2 as this is the first 2012 R2 DC.

  • DNS Options: The user will probably face an error with a yellow exclamation mark that says, "A delegation for this DNS server cannot be created because..." There is no need to worry as this just means that the wizard is unable to make a delegation for the sub-domain by attempting to reach the nameservers for the domain entered by the user (Note: The user should ignore this error message if they do not require systems outside of the network to determine names within the user's domain). 

  • Additional Options: The user now needs to type in the NetBois domain name on this page. It is recommended to make the NetBois domain name the same as the user's root domain name.

  • Paths: On this page, the user needs to enter the coveted folder settings, and subsequently click Next. Most users usually go with the default folder settings.

  • Review Options: The user can take a look at the options selected, and if satisfied, can proceed to click Next.

  • Prerequisites Check: The user should see a green check on the top. This green check indicates that the prerequisites have passed and the wizard is ready for installation. Click Install to begin the process.

 

STEP 3: REBOOT AND VERIFICATION

 

  • Reboot: The user will be required to reboot their system once the AD DS installation and configuration is completed. This step effectively finishes the installation and configuration of adding a Windows Server 2012 R2 DC to a new forest.

  • Verify: The command mentioned below can be run from the command line if the user wishes to verify the installation and/or health (status) of the DC:

            dcdiag /v

 

While it is a matter of fact that there are a certain number of steps that need to be followed by any user to achieve their goal, the process is straightforward and has been broken down into simpler terms for the user's convenience. Once the user understands how the process works, it becomes relatively easy to create a domain controller, add a domain to an Active Directory, or add a new domain to an existing forest. 


    • Related Articles

    • Raise Active Directory Domain and Forest Functional Levels | Step-by-step guide

      What are Functional Levels in Active Directory? Active Directory functional levels help to determine the features that available for the domain or forest. There are two types of functional levels in Active Directory; they are the Domain Functional ...
    • How to Migrate Users and Computers to a New Domain

      How to Move Active Directory Users and Computers from one Domain to another   In Active Directory, users and computers can be moved or migrated from one domain to another for various purposes. In intra-forest migration, objects are migrated between ...
    • Transitioning your Active Directory to Windows Server 2008 R2

      Transitioning AD to Windows Server 2008 R2  Introduction  Active Directory (AD), a service provided by Microsoft, functions as a central database for securely storing and managing information about user accounts, user groups, applications, and other ...
    • Seizing FSMO Roles from a Dead Domain Controller | Step-by-step guide

      A quick introduction to Flexible Single Master Operation (FSMO) Active Directory uses the multi- master model for replicating changes between domain controllers. This multi-master enabled database allows changes to occur on any domain controller ...
    • Domain Controllers

      Computers that function as servers in a domain can be a member server or a domain controller. A member server belongs to a particular domain but does not authenticate the users of that domain. There is no Active directory data installed in it. Domain ...