In this tutorial we’ll create and configure:
- a Windows Server 2019 Domain Controller
(using a Hyper-V VM)
- Install and configure the AD Domain services, DNS and DHCP server roles
- Set up a new domain
- Additional: A sample VM to join the new domain
- Creating your virtual machines in Hyper-V
- Promote a Domain Controller
- Configure the server roles
- Additional: Join a server to the domain
Azure AD Connect: This domain environment will be used later to sync a couple domain users to Azure with Azure AD Connect.
Windows Admin Center: We’ll use these VMs to connect them to Azure and configure the hybrid cloud services with Windows Admin Center.
Let’s start, Set up your Hyper-V VMs:
Download Windows Server 2019 Evaluation:
https://aka.ms/windowsserver (choose Windows Server on-premises) and download the ISO-file.
=> Tech Tip: If you encounter any problems during the Hyper-V installation, please check your Computers’ BIOS settings and enable Virtualization.
After the installation, open the Start Menu, search Hyper-V and open the Hyper-V Manager console. On the right is the Actions Pane, click on Virtual Switch Manager. Click on Internal and Create Virtual Switch. Create the Switch with the following settings:
Click on Apply to create it.
Click on Apply to create it. Explanation: The internal switch is used for our lab network, the external switch is used to provide internet connections for our servers.
=> Production Tip: This is a lab (test) environment. In a production environment you shouldn’t open internet connection for your Domain Controller and think about different VLANs (networking concept).
As you can see, we’re using the Standard Network Adapter for internal connections (InternalSwitch1). Now click finish to create the VM. When the VM is created, right-click it and choose Settings. On start page, click on Network Adapter and choose Add to create a second Network adapter:
Now you’re DC1 has 2 network adapters, for internal and external connections.
Installing and Configuring Server 2019:
Click on Connect and Start it. Press a key to boot from your ISO-file. Click through the installation wizard, don’t forget to choose Windows Server 2019 Datacenter Evaluation (Desktop Experience x64) to install your VM with au GUI:
It’ll take some time and several reboots to install your new Server 2019. After the installation choose a password. Now it’s time to set a static IP address. Click the lens next to the Start Button and enter ncpa.cpl. It should look like this:
In my case, the internal network adapter was “Ethernet 2”. Double click it, Properties, Internet Protocol Version (TCP/IPv4) and set the following settings. Rename the adapters to Internal and External for better recognition, use a static IP address:
No changes to the External adapter. Close all windows with clicking Ok and restart your VM. The new IP address is now applied.
=> Tech Tip: If the network sign (next to the clock) shows an exclamation mark after the reboot, you’ve entered the static IP for the wrong adapter. You have to switch them. For this lab we use a 172.16. IP. You can also use an IP of your range.
Installing AD, DNS and DHCP roles:
=> Production Tip: In a productive environment you should now update your Domain Controller through Control panel (if an Internet connection is open) or through WSUS. You don’t want to update your new DC after 2 weeks in production. Next step, give your DC a decent name, this is the last chance to change it (Control Panel, System). Also very important: You should use separate servers for Domain Controller, DNS and DHCP services and build them redundant.
Click on Next until the end of the wizard and select Auto-Reboot, then install. It’ll take quite some time to install these 2 roles. If your server doesn’t reboot at least one time, please reboot it manually when the installation is complete.
Promote your VM to a Domain Controller
Click on next. Check if the Forest and Domain functional level is Windows Server 2016. Your DC is a Server 2019, but you can’t create a domain with the functional level 2019 yet. There’s no information from Microsoft when a 2019 forest will be possible. Make sure DNS server and GC is checked and choose a DSRM password:
The domain settings are now configured. Now we should configure the reverse DNS lookup zone for a correct name resolution. Click on the lens symbol and enter DNS. Open up the DNS Manager console. Double-click your Computername and right-click Reverse Lookup Zones. Choose New zone:
Configure Advanced DNS Settings
Click on OK and on the next window OK again.
Configure DHCP settings
The next step is to configure the DHCP settings. Every new server will automatically get an address in your range. Anyway, it’s really important that you set a static IP address for every new server you create. This step will be made further down in this tutorial, when we create the next server.
Now we need to define a Scope for new servers. Our DC1 IP address is 172.16.10.10. It’s better to separate your addresses, that’s why we choose 172.16.10.30 to 100. Use 255.255.255.0 as Subnet Mask. It’ll automatically set a Length of 24, you can leave that:
Congratulations, your domain is now configured and ready to join for new servers. Please see the additional steps to Create a New VM to join your Domain.
Additional steps: Create a new VM for joining the domain
Now start your VM and install Windows Server 2019 again. For details check the first steps on top of this Tutorial. After the installation is finished, open the Startmenu and click on Control Panel. Click on System. Under Computername section, click on Change settings:
Now we need to create a new user in Active Directory on the Domain Controller, before you can login.