> For the complete documentation index, see [llms.txt](https://www.osdsune.com/home/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.osdsune.com/home/archive/microsoft-configuration-manager/configmgr-lab/part-3/active-directory.md).

# Active Directory

## SETTING UP ACTIVE DIRECTORY

{% hint style="info" %}

#### WHAT IS ACTIVE DIRECTORY?

Active Directory Domain Service (**AD DS**) is a directory service developed by Microsoft for Windows domain network. It is included in most Microsoft Windows Server operating systems as a set of processes and services. Initially, Active Directory was only in charge of centralized domain management.&#x20;

Starting with Windows Server 2008, however, Active Directory became an umbrella title for a broad range of directory-based identity-related services.

Read more about Active Directory Domain Services [here](https://docs.microsoft.com/en-us/windows/win32/ad/about-active-directory-domain-services)
{% endhint %}

Log into the DC server, and we will start setting up the Active Directory server role for my LAB environment.

### Installing Active Directory

**Step 1.** Click "**Add roles and features**" in the Server Manager.

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlEgqvEprF6w9VwChJ%2F16_WinServer2019_Config_AD.JPG?alt=media\&token=f54db15c-fa1f-410c-ab5a-5856ca85be0e)

**Step 2.** Click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlFi2QswQAgXxOHKV1%2F17_WinServer2019_Config_AD.JPG?alt=media\&token=f0abe6e2-fa9a-4f61-8640-e768eb8bb088)

**Step 3.** Leave everything default and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlFq0x4xxD8TrboyaS%2F18_WinServer2019_Config_AD.JPG?alt=media\&token=ecf2ea9a-4f77-4060-b81a-cc03b106dbba)

**Step 4.** Leave everything default and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlFw_Z5OwQ3awVccYc%2F19_WinServer2019_Config_AD.JPG?alt=media\&token=a32e6c21-245f-46bb-a4cd-4ad950094316)

**Step 5.** Select "**Active Directory Domain Services**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlG0fb5xyGh2vQToVg%2F20_WinServer2019_Config_AD.JPG?alt=media\&token=2d7dbfe3-e323-4ee0-817f-5c69fc0ee91e)

**Step 6.** Leave everything default and click "**Add Features**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlG6dFH4gq7kruKV85%2F21_WinServer2019_Config_AD.JPG?alt=media\&token=af3d35e1-adc2-423e-ba0d-8787a91c129d)

**Step 7.** Leave everything default and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlGDkRTzKGnBFHO2CU%2F22_WinServer2019_Config_AD.JPG?alt=media\&token=7fbeae83-c189-4e41-a21c-5e41194b253d)

**Step 8.** Click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlGMCotOHkyYuWGVqZ%2F23_WinServer2019_Config_AD.JPG?alt=media\&token=269d8242-9a0b-413a-ad30-79a34c94b1ad)

**Step 9.** Check the "**Restart the destination server automatically if required**" box and click "**Install**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlGTUQ6FzYumPJ3vYg%2F24_WinServer2019_Config_AD.JPG?alt=media\&token=ae9e17df-324c-4664-a507-92bff844a79d)

**Step 10.** This might take a while, so click "**Close**" and go grab a cup of coffee:sunglasses:&#x20;

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlGZDqpatVuT1SuR3s%2F25_WinServer2019_Config_AD.JPG?alt=media\&token=903a1497-90e6-4c07-8af7-f3c096da007a)

### Configuring Active Directory

**Step 1.** When the server role installation is done, we should now see a yellow triangle with an exclamation mark in the Server Manager, click on it and then click "**Promote this server to a domain controller**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-Lzl9AEk0ZU49SgdxLba%2F-LzlGjSCnjp6PLh-1Cp1%2F26_WinServer2019_Config_AD.JPG?alt=media\&token=e92584f7-f8ce-4d30-95fa-a14e1d292887)

**Step 2.** Check "**Add a new forest**", enter a "**Root Domain Name**" and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlNYpdSWHHDhLxnatZ%2F27_WinServer2019_Config_AD.JPG?alt=media\&token=4a8b7841-6fc3-4dfe-96c9-c400ae967b4d)

**Step 3.** Enter a password for DSRM, leave the rest as default and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlNd70xBW4r4xS8kBy%2F28_WinServer2019_Config_AD.JPG?alt=media\&token=4cc608ba-d282-4973-ac95-8c776afa0f7a)

**Step 4.** Leave everything default and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlNjijFcXpR0iZqcZh%2F29_WinServer2019_Config_AD.JPG?alt=media\&token=1b48d504-6623-434a-b389-7d1c6b1676b9)

**Step 5.** The NetBIOS domain name is populated automatically after a few second, it is possible to change the NetBIOS domain name, but I choose to leave it as default for my LAB environment.

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlNpO-hALLqvfmge0k%2F30_WinServer2019_Config_AD.JPG?alt=media\&token=33b6f5ea-7795-461d-9fba-f7e669a939ea)

**Step 6.** Leave everything default and click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlNvIvzYnNmq_Z9ez-%2F31_WinServer2019_Config_AD.JPG?alt=media\&token=8622dd3a-5c82-45bd-9b84-c12753561f2e)

**Step 7.** Click "**Next**"

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlO03fJfwidS_uKJjE%2F32_WinServer2019_Config_AD.JPG?alt=media\&token=6069e784-33dd-4c9e-9286-ad99aa194c5c)

{% hint style="info" %}

#### BONUS INFO

If you click "**View script**" you can actually save it as a PowerShell script and re-use it the next time you have to create a new Active Directory Forest.
{% endhint %}

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlPEOI5R_MsdOndVRn%2F-LzlR5NBM40p7J7lULuY%2F33_WinServer2019_Config_AD.JPG?alt=media\&token=3fe73667-7978-46ba-8b97-87f03e6830be)

**Step 8.** The system will now verify all the prerequisites, this might take a few seconds to validate. You will see the message "**All prerequisite checks passed successfully.**" if everything went as it should.&#x20;

The yellow triangle with an exclamation mark is okay since this is a new LAB environment. For example, I do not have any existing Windows DNS server in my environment, so I can just ignore that "warning".

Click "**Install**" (*The system should reboot automatically during this process...*)

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlO5jm_4DEpAZrTDi_%2F34_WinServer2019_Config_AD.JPG?alt=media\&token=c6ab89e4-b67f-42e1-985b-1f737f2fb9aa)

**Step 9.** After a reboot the Active Directory installation is done and you should be able to log on to the domain for the first time.

![Windows Server 2019 - Active Directory](https://3347085443-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-L_qpqqoWaR3gQAWE4Lk%2F-LzlNRslFo1wYeMb8Ks9%2F-LzlOAUREmGsm5hukmxn%2F35_WinServer2019_Config_AD.JPG?alt=media\&token=818e3807-7cbd-463f-9364-b0267b4ec429)

Now that we have successfully installed and configured the Active Directory server role on my DC server, let's move on to the DHCP server role installation. Click "**Next**" below or click "**DHCP**" in the menu to the left.
