Excerpt
Excerpt
INSTALLING AND
CONFIGURING DOMAIN
CONTROLLERS
AL
RI
TE
MA
THIS LAB CONTAINS THE FOLLOWING EXERCISES AND ACTIVITIES:
ED
1
2 70-742: Identity with Windows Server 2016
Table 1-1
Computers required for Lab 1
In addition to the computers, you will also require the software listed in Table 1-2 to complete Lab 1.
Table 1-2
Software required for Lab 1
Software Location
Lab 1 student worksheet Lab01_worksheet.docx (provided by instructor)
SCENARIO
After completing this lab, you will be able to:
3. On the Control Panel System page, in the Computer name, domain, and workgroup settings
section, click Change settings.
5. In the Computer Name/Domain Changes dialog, click Workgroup and then type Workgroup in
the text box. Click OK.
6. When you are prompted to confirm that you want to continue, click OK.
10. When a message indicates you must restart your computer to apply these changes, click
Restart Now.
12. Click Start, then click the Server Manager tile. In Server Manager, click Manage > Add Roles
and Features.
16. On the Select server roles, click Active Directory Domain Services. When you are prompted to
confirm that you want to add some features, click Add Features.
22. On Server Manager, click the yellow triangle with the black exclamation point and then click
Promote this server to a domain controller.
23. In the Active Directory Domain Services Configuration Wizard, on the Deployment
Configuration, click Add a New Forest.
24. In the Root domain name text box, type contoso.com, as shown in Figure 1-1. Click Next.
Figure 1-1
Creating a new forest
25. On the Domain Controllers Options page, type Pa$$w0rd in the Password text box and the
Confirm password text box. Click Next.
26. On the DNS Options page, answer the following question and then click Next.
Question
What is the message displayed in the warning?
1
Lab 1: Installing and Configuring Domain Controllers 5
27. On the Additional Options page, after CONTOSO appears in the NetBIOS domain name text
box, click Next.
29. On the Review Options page, answer the following question and then click Next.
Question
Which additional options will be installed?
2
31. On TOR-DC1, when Windows reboots, log on as contoso\administrator with the password
of Pa$$w0rd.
32. Open Server Manager and then click Tools > Active Directory Users and Computers. If a
dialog box displays, indicating that the Naming information cannot be located, you may need to
close the dialog box, close Active Directory Users and Computers, and try again in about 10
minutes so that DNS can create the DNS Application Directory Partition for the
DomainDNSZones.contoso.com domain.
33. Expand the contoso.com node and then click the Domain Controllers node.
34. Take a screen shot of Active Directory Users and Computers showing the coontoso.com domain
controllers by pressing Alt+PrtScr and then paste it into your Lab01_worksheet file in the page
provided by pressing Ctrl+V.
1. On TOR-DC1, using Server Manager, click Manage > Remove Roles and Features.
4. On the Remove server roles, deselect Active Directory Domain Services.When a message
displays, indicating that you have to remove features, click Remove Features.
5. In the Validation Results dialog box (as shown in Figure 1-2), click Demote this domain
controller.
Figure 1-2
Demoting a domain controller
6. On the Credentials page, click to select Force the removal of this domain controller and then
click Next.
7. When a message indicates that the current roles include Domain Name System (DNS) Server and
Global Catalogs, click to select the Proceed with removal and then click Next.
8. On the New Administrator Password page, for the Password text box and the Confirm password
text boxe, type Pa$$w0rd and click Next.
9. On the Review options page, click Demote. Windows will reboot when done.
11. Right-click the network status icon on the taskbar and choose Open Network and
Sharing Center.
14. In the Ethernet Properties dialog box, double-click Internet Protocol Version 4 (TCP/IPv4).
Lab 1: Installing and Configuring Domain Controllers 7
Question
Which DNS server is configured for TOR-DC1
3
15. Change the Preferred DNS Server to 172.16.0.10 and then click OK.
20. On the Control Panel System page, in the Computer name, domain, and workgroup settings
section, click Change settings.
22. In the Computer Name/Domain Changes dialog box, click Domain and then type adatum.com
in the text box. Click OK.
23. In the Windows Security dialog box, log on as administrator with the password of Pa$$w0rd
and then click OK.
24. When a welcome to the adatum.com domain message appears, take a screen shot by pressing
Alt+PrtScr and then paste it into your Lab01_worksheet file in the page provided by press-
ing Ctrl+V.
28. When a message indicates that you must restart your computer to apply these changes, click
Restart Now.
8 70-742: Identity with Windows Server 2016
2. On Server Manager, click the yellow triangle with the black exclamation point and then click
Promote this server to a domain controller.
Question
Which site name is assigned to the domain controller?
4
4. On the Domain Controller Options, page, in the Password text box and the Confirm password
text box, type Pa$$w0rd. Click Next.
6. On the Additional Options page, answer the following questions and then click Next.
Question Which option should be selected when the server is not connected
5 to the network and other domain controllers?
8. On the Review Options page, take a screen shot by pressing Alt+PrtScr and then paste it into
your Lab01_worksheet file in the page provided by pressing Ctrl+V.
10. After the prerequisite check, click Install. After the DC promotion, the system reboots.
11. On TOR-DC1, when Windows reboots, log on as adatum\administrator with the password
of Pa$$w0rd.
12. In Server Manager, click Tools > Active Directory Users and Computers.
Lab 1: Installing and Configuring Domain Controllers 9
13. Expand the adatum.com node and then click the Domain Controllers node.
14. Take a screen shot of Active Directory Users and Computers showing the coontoso.com domain
controllers by pressing Alt+PrtScr and then paste it into your Lab01_worksheet file in the page
provided by pressing Ctrl+V.
16. In Server Manager, click Tools > Active Directory Sites and Services.
17. In Active Directory Sites and Services, expand the Default-First-Site-Name > Servers >
TOR-DC1. Right-click NTDS Settings and choose Properties.
Question
Is the Global Catalog option checked or unchecked?
6
2. In Server Manager, click Tools > Active Users and Computers. The Active Directory Users and
Computers console opens.
Figure 1-3
Transferring the RID Operations Master role
Question Which Operations Master acts as the master time server and is
7 considered authorative for account passwords?
10. In Server Manager, click Tools > Active Directory Domains and Trusts. The Active Domains
and Trusts console opens.
11. Right-click Active Directory Domains and Trusts and choose Change Active Directory
Domain Controller. Click TOR-DC1.Adatum.com. Click OK.
12. Right-click Active Directory Domains and Trusts and choose Operations Master. The
Operations Master dialog box showing current Domain Naming Operations Master opens.
13. To change the Operations Master, click Change. When you are prompted to confirm this action,
click Yes. When the transfer is successful, click OK.
Lab 1: Installing and Configuring Domain Controllers 11
14. Take a screen shot of Active Directory Domains and Trusts by pressing Alt+PrtScr and then
paste it into your Lab01_worksheet file in the page provided by pressing Ctrl+V.
17. Right-click the Start button and choose Run. In the Run dialog box, in the Open text box, type
cmd and then click OK.
18. At the command prompt, execute the following command so that you can use the Schema
Management console.
Regsvr32 schmmgmt.dll
20. At the command prompt, execute the mmc command. The MMC console opens.
21. Click File > Add/Remove Snap-in. The Add or Remove Snap-ins dialog box opens.
22. Select Active Directory Schema and then click Add. Click OK to close the Add/Remove
Snap-ins dialog box.
23. Right-click Active Directory Schema and choose Connect to Schema Operations Master.
24. Right-click Active Directory Schema and choose Change Active Directory Domain
Controller. Click TOR-DC1.Adatum.com and then click OK. When a warning dis-
plays, click OK.
25. Right-click Active Directory Schema and choose Operations Master. The Change Schema
Master dialog box opens.
26. To change the Schema Master to TOR-DC1, click Change. When you are prompted to confirm
this action, click Yes. When the Operations Master is transferred, click OK.
27. Take a screen shot of the Change Schema Master dialog box by pressing Alt+PrtScr and then
paste it into your Lab01_worksheet file in the page provided by pressing Ctrl+V.
28. Click Close to close the Change Schema Master dialog box.
29. Close the MMC console. When you are prompted to save the console, click No.
Leave the Command Prompt window open for the next exercise.
12 70-742: Identity with Windows Server 2016
7. To see the available options, press the ? key and then press Enter, as shown in Figure 1-4.
Figure 1-4
Using ntdsutil
Lab 1: Installing and Configuring Domain Controllers 13
8. To seize the roles, at the fsmo maintenance prompt, type the following commands, clicking Yes
each time you’re prompted to confirm:
seize PDC
9. Take a screen shot of the MMC by pressing Alt+PrtScr and then paste it into your Lab01_work-
sheet file in the page provided by pressing Ctrl+V.
End of lab.