Building an AD DS Structure

To get the best foundation for the rest of this chapter, much as we did in Chapter 4, let's actually build an AD DS forest, tree, and domain. In this section, I'll walk you through the process of creating a domain, promoting a domain controller, adding another domain controller to the domain, adding a second child domain, and then adding a few users and groups to the mix.

The First Domain

The first domain in an AD DS setup is special for a few reasons. For one, the setup process for a new domain automatically adds the first domain controller to that domain—the machine on which you run the Active Directory Domain Services Installation Wizard becomes the first domain controller for the new domain. Second, this new domain becomes the root of the entire forest, meaning that it has special powers over other domains you create within the forest, even if their names aren't the same. We'll go over that in a bit.

To start the process, from the machine you want to become the first domain controller for the new domain, select Run from the Start menu, type DCPROMO, and click OK. You might also access this screen after adding the AD DS role within Server Manager; there is a link on the final screen to launch wizard.

The Active Directory Domain Services Installation Wizard starts, as shown in Figure 5-2.

Beginning AD DS installation

Figure 5-2. Beginning AD DS installation

Click Next, and you'll see the ...

Get Windows Server 2008: The Definitive Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.