{"componentChunkName":"component---src-templates-post-template-js","path":"/windows-activedirectory-lab-en","result":{"data":{"markdownRemark":{"id":"a3bcde6f-962a-5f61-9699-bc7c0106837b","html":"<blockquote>\n<p>This page has been machine-translated from the <a href=\"/windows-activedirectory-lab\">original page</a>.</p>\n</blockquote>\n<p>These are my notes from when I built an AD environment in my lab.</p>\n<p>For now, I have summarized the steps and troubleshooting up to configuring the domain controller and joining a client to AD.</p>\n<p>I plan to add more if I try other configurations.</p>\n<!-- omit in toc -->\n<h2 id=\"table-of-contents\" style=\"position:relative;\"><a href=\"#table-of-contents\" aria-label=\"table of contents permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Table of Contents</h2>\n<ul>\n<li>\n<p><a href=\"#build-the-ad-server\">Build the AD Server</a></p>\n<ul>\n<li><a href=\"#ad-basics\">AD Basics</a></li>\n<li><a href=\"#environment-information\">Environment Information</a></li>\n<li><a href=\"#enable-ad\">Enable AD</a></li>\n<li><a href=\"#promote-it-to-a-domain-controller\">Promote It to a Domain Controller</a></li>\n<li><a href=\"#set-a-static-ip\">Set a Static IP</a></li>\n<li><a href=\"#check-ad-and-dns\">Check AD and DNS</a></li>\n<li><a href=\"#add-an-ad-user\">Add an AD User</a></li>\n</ul>\n</li>\n<li>\n<p><a href=\"#join-a-server-to-ad\">Join a Server to AD</a></p>\n<ul>\n<li><a href=\"#set-the-preferred-dns-server-to-the-domain-controllers-ip-address\">Set the Preferred DNS Server to the Domain Controller’s IP Address</a></li>\n<li><a href=\"#join-the-client-to-the-domain\">Join the Client to the Domain</a></li>\n</ul>\n</li>\n<li>\n<p><a href=\"#troubleshooting-when-failing-to-join-ad\">Troubleshooting When Failing to Join AD</a></p>\n<ul>\n<li><a href=\"#if-you-get-the-the-specified-domain-either-does-not-exist-or-could-not-be-contacted-error\">If You Get the “The specified domain either does not exist or could not be contacted” Error</a></li>\n<li><a href=\"#check-dns-events\">Check DNS Events</a></li>\n<li><a href=\"#using-local-in-the-ad-domain-name\">Using .local in the AD Domain Name</a></li>\n<li><a href=\"#disable-ipv6\">Disable IPv6</a></li>\n<li><a href=\"#dns-can-resolve-the-domain-controller-but-you-still-cannot-join-ad\">DNS Can Resolve the Domain Controller, but You Still Cannot Join AD</a></li>\n<li><a href=\"#when-integration-is-not-going-well\">When Integration Is Not Going Well</a></li>\n</ul>\n</li>\n<li><a href=\"#enable-ldaps-and-integrate-applications-with-ad\">Enable LDAPS and Integrate Applications with AD</a></li>\n<li><a href=\"#summary\">Summary</a></li>\n</ul>\n<h2 id=\"build-the-ad-server\" style=\"position:relative;\"><a href=\"#build-the-ad-server\" aria-label=\"build the ad server permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Build the AD Server</h2>\n<h3 id=\"ad-basics\" style=\"position:relative;\"><a href=\"#ad-basics\" aria-label=\"ad basics permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>AD Basics</h3>\n<p>In an AD environment, resources are managed by the domain controller (DC).</p>\n<p>The feature that provides this domain controller functionality is AD DS.</p>\n<p>In the AD DS environment built here, organizational unit resource groups (OUs) are created to manage objects such as users and servers.</p>\n<p>Permissions and settings can also be defined through Group Policy.</p>\n<p>In an AD environment, a collection of domains is called a forest. When creating AD, you always need one forest and one domain.</p>\n<h3 id=\"environment-information\" style=\"position:relative;\"><a href=\"#environment-information\" aria-label=\"environment information permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Environment Information</h3>\n<p>This is the configuration information for the Windows Server used as the AD server.</p>\n<p><em>If the computer name is 15 bytes or longer, it will be shortened when converted to a NetBIOS name.</em></p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 532px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/bc726a41d571759699cef3768eae7d64/89a37/image-28.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 72.91666666666666%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAAAsTAAALEwEAmpwYAAAB6UlEQVQ4y5VT25aiMBD0/z/Pl52XXUXukACCkCBIbVcrDs7MzpxtT0gg6UpVV7tblgVdf8XgJxkzisqhbj1M45DbHqZ26N0Ehhz9MXbzPCMrW0mU5KrD77BGYQckZY8gaRHlHaqzIxxutxtI4Luxm6YryiJHwZHnqGsD7wfcZmG1zC+3M4Gg340dD14uFxz+HBDFMeI4QRSFCI4BEln3lx7DMKCX4cfxZ8l8UHZVWWFX43w+o2ka1NV9zdkaC2srtG37T6lPQNIkAGfGOv9vrOVQhgTMsgzOuycoD1y6DsYYHVleoKkrJEmKsiy13qw7c/MsxXidtA0UkFLe3n4hlQ0CT9PdDCOJQRCg73u5zGMcvawHmUcxzmltp2nS9apMAQdJCIIj9vu9GrMGmYRhKHMhNa6kjlbYCruigJV37p9OJzV1la2AbB3KIv1tdCI5F2lGgYyaZq1BIRfwPU4TBKdALx0fHbAjZd58d7fWdZKmyoRApSSG0kZfNvVDJtfslE0fkkmmAG3b6SYP3Wt4xOFw0L3l0WJfgb9Ids4JqwS5uJYKu2G4u12Lq3EcqVFkXRZG3d3W7FMf8kEXoyhSyUdh1D0SWI7Rj1qf20ae/jasXv7L/EjbWfCPQVPoJA3wzj8BsLw388f4CxXZi9/5rj6cAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/bc726a41d571759699cef3768eae7d64/8ac56/image-28.webp 240w,\n/static/bc726a41d571759699cef3768eae7d64/d3be9/image-28.webp 480w,\n/static/bc726a41d571759699cef3768eae7d64/b5f85/image-28.webp 532w\"\n              sizes=\"(max-width: 532px) 100vw, 532px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/bc726a41d571759699cef3768eae7d64/8ff5a/image-28.png 240w,\n/static/bc726a41d571759699cef3768eae7d64/e85cb/image-28.png 480w,\n/static/bc726a41d571759699cef3768eae7d64/89a37/image-28.png 532w\"\n            sizes=\"(max-width: 532px) 100vw, 532px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/bc726a41d571759699cef3768eae7d64/89a37/image-28.png\"\n            alt=\"image-28.png\"\n            title=\"image-28.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<h3 id=\"enable-ad\" style=\"position:relative;\"><a href=\"#enable-ad\" aria-label=\"enable ad permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Enable AD</h3>\n<p>First, add a server role and enable Active Directory Domain Services.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/d5547c4a678269c9d70b872c0c6e1bfc/0b533/image-13.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 62.916666666666664%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAANCAYAAACpUE5eAAAACXBIWXMAARlAAAEZQAGA43XUAAACNklEQVQ4y3VTy5LTMBD0x3PhzkfshTtUURwo4MJpDyke2U3ixE4kW5b8kmXJj2ZG2V2WLVDV1IylcaunZ5RYo9B/e4dw+xGYPOZlwTzP/7VlYVui8TfWFY9rpTjphhHKzRA2QHfDPwAeLpimGHsf0LQtlKowDA4LgSzLGj2vxA0WumkgTA1BSVWl6YcOWhtUZFpr1MagsQ5SGZwvArKs0DQdvPMEhGhhXuDCjETWFtJ0MMTQNC36tgFmjzXQ7X6AtRajc7AjV2BREVBL4H6aYf21Kt0PGCgew4Lk9Yd7vPmU4tX7HfZlj+1J4ObLL9x8/o63X39AEeNxdCjJF7pGRZVwyVyBpliRl1QZ7/mJNOTkq15T1CnNL7jdpvh5lNhmBYH5CChLRbop5HmG8zlHmqaRfQiBdPXkPbGckEwEwmDs+bCQAqoQWKfw1L2FLhSFghtHnE4n7HY7tMQodpnPqVnc7Z40TXiTwa6AE4QQJPyFfuho79ppPrvIMnYzEJvsxCzPkEJCPOVOsC68BAyQUuL+7g77/YE6zqMxRClEcQXkxSU6Ghk+Y6YjMeecvxiy50QGTA8HbDYbiouok6Mu67qJc8cx5zFILPXZsi8BOSnPc2RZRgz3OB6PUYK6NugJjME7YhSt62gWm6gn/3Mm43FKmPJz46S6rqNnK8sSZVHEYe7pVbG1NHc8Psy6rEyMK9P8Aez7Pt7OxrrwNzN4jI15eDF0Qdf10fhFadofSIKRJWBdqcLfDN7lCNqUKGgAAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/d5547c4a678269c9d70b872c0c6e1bfc/8ac56/image-13.webp 240w,\n/static/d5547c4a678269c9d70b872c0c6e1bfc/d3be9/image-13.webp 480w,\n/static/d5547c4a678269c9d70b872c0c6e1bfc/b0a15/image-13.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/d5547c4a678269c9d70b872c0c6e1bfc/8ff5a/image-13.png 240w,\n/static/d5547c4a678269c9d70b872c0c6e1bfc/e85cb/image-13.png 480w,\n/static/d5547c4a678269c9d70b872c0c6e1bfc/0b533/image-13.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/d5547c4a678269c9d70b872c0c6e1bfc/0b533/image-13.png\"\n            alt=\"image-13.png\"\n            title=\"image-13.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>Proceed as is, start the installation with [Restart the destination server automatically if required] enabled, and wait for a while.</p>\n<p>For more detailed steps, the following site may be helpful.</p>\n<p>Reference: <a href=\"https://ittrip.xyz/soft/windows/ad-setup-ad-easy\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Active Directory サーバー（ADサーバー）の構築手順を初心者にも分かり易く徹底解説 | IT trip</a></p>\n<p>Also, LDAPS cannot be used on a domain controller by default.</p>\n<p>If you want to use another application that integrates with Active Directory over LDAPS, you need a certificate for LDAPS.</p>\n<p>To install a certification server on the domain controller and enable LDAPS with a self-signed certificate, add Active Directory Certificate Services here as well.</p>\n<h3 id=\"promote-it-to-a-domain-controller\" style=\"position:relative;\"><a href=\"#promote-it-to-a-domain-controller\" aria-label=\"promote it to a domain controller permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Promote It to a Domain Controller</h3>\n<p>Once enabling is complete, it will be displayed as shown in the image below.</p>\n<p>Next, click [Promote this server to a domain controller] to create the domain controller.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 625px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/11ca18025b88eb65cab87bde36999afd/80d71/image-15.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 67.91666666666667%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAOCAYAAAAvxDzwAAAACXBIWXMAAAsTAAALEwEAmpwYAAACPElEQVQ4y51T22oTURSdj0qEYB/qQ3wS+xeNBaU/4CVINFTQPvvmj/gkiPhSCcZqTJu0ucxk7pOZc+aWmeXeJxeSUkHcsNjnklln77VXtFqthttQrd5BpVKlXKVc2QGf1et17O/fw8MHddyvUz44wN7eXWiNRgM3cXjYwIvnT/H6VQvNZhOtVgvtdnsHp6fvcPLmLT68b+Hls2M8fnKMo6NH0CIhEEURQUAIBq1FgiwcQAZXGE8MSClxM/LFAmVZIk5y6PoMYThXHFqWpVjkGfIsQ5qmCkkcYz6fw3FsTMdjTAiWacKxbZU914FLcFxX7Q1DR0bfJ0kCbS5TGK6AGyYoikK9yq9nsYBJBJ3eBc4vh7g2TIxMBxPLRm9swHQ8SOrIJVKTSDn4ey3NCwQiRRTnRAYFjr7uo3MxhUmv20Qc+L6SJgxDzIjM8wNEtHYcR91zcDEayi1h6KBUjCWmfowvv0b4+K2LTz/6+NwbEIY4G4xUZUzOmrM0XOWGkCsriiVRuSpP7UlX0zLxtfMdZ91zdPuX6PzsYThZVmxZFjzP22BDOHEEuO31wRpcheUF1LqF31MS3naRSIGYJr50g1DT90kKbntDGIgMRVnuWIIveGJ+EGB4dQ1jNiN7JIhp+lLGKjP4N+FKxy3CFIK8FMYZpq6Ew9Omi4DIeHq6rmNGhNzmbeA7rnJDmC/IJqRZkhVq0jJdrKZdYLEyL9uB13/DdihjL0Hm3jI47/8V6z8EQ1vrIVf6bGv0P/gDsPfvf4wE8WEAAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/11ca18025b88eb65cab87bde36999afd/8ac56/image-15.webp 240w,\n/static/11ca18025b88eb65cab87bde36999afd/d3be9/image-15.webp 480w,\n/static/11ca18025b88eb65cab87bde36999afd/487e2/image-15.webp 625w\"\n              sizes=\"(max-width: 625px) 100vw, 625px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/11ca18025b88eb65cab87bde36999afd/8ff5a/image-15.png 240w,\n/static/11ca18025b88eb65cab87bde36999afd/e85cb/image-15.png 480w,\n/static/11ca18025b88eb65cab87bde36999afd/80d71/image-15.png 625w\"\n            sizes=\"(max-width: 625px) 100vw, 625px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/11ca18025b88eb65cab87bde36999afd/80d71/image-15.png\"\n            alt=\"image-15.png\"\n            title=\"image-15.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>When the configuration wizard opens, select [Add a new forest] and set any domain name you like.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/749bc15be35b1458ec6de23edb25c317/0b533/image-26.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 73.75%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAARlAAAEZQAGA43XUAAACUElEQVQ4y41UXW/TMBTNL+aN38A7vwAJiSceeEQboA4QGwPG2OjWscLSNmVJm2RO4thxbOdw7a5dmDaEpaPr+OP4nuPrBKPxBMOznxj+uMDJ+QQHxyOcnoeYXqaYxekqXt7ETZ/moiQnZAjnCx93D0cItG7Baw6gw03rerivdVCNRFUWSJIYSgo8efoMwcE0x8dfS+yHOT5PGC6ZoLUdjLUwxkDrFVzfoW01fWsopZClGZbLJRaLBcqyxPbgPYLHOxM82hrj4YtTPHg+xOAsQRr/xmQ69Ys5535zXdcQQlwfon3sum6jxyVRK4PAKlpYFYBtaVDDkgWz2QxTIgwvQkRRhDiOEYYhGGMbwtswRiPnDQLVNCgo3aKsoI312SySBFmWYz6fIyIURUlSW5+L9VboHlYHWIoZVwgEXYiT5k5fe5PnOVLyx5FWVUVyOWpJ4wVHwSUESVujvZbvyL1kc02yPsll4r5FLXzf+dRRVo1qSQUHF5JIjIfSpifZgNWUoTOz74UjcZN2c8s3GxzxvySnJXnofFlvWBP+bba54yJMD3pDeMX/k7BPfBfW85VsV4TtLcnojMdd5XEfnHxWU4bOdEUk7gW4UxTFtJRImKQy6mViV7Cd85cOc/75MfK1s3QVFsUqQ9esrzHdKv8aXHmkrIKUEg3BxVYoKNGiLNz7bWAaqg7RQFI1cMYhK4El/TSC1+/2sbWzh5eDPYzDCDkrkV0x5IRlzpASYqrJr7Nj7E+PsP19F29Gn/AtPsEwOsN4PsGrowHenn7Al9kh/gAEHoFhtySIewAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/749bc15be35b1458ec6de23edb25c317/8ac56/image-26.webp 240w,\n/static/749bc15be35b1458ec6de23edb25c317/d3be9/image-26.webp 480w,\n/static/749bc15be35b1458ec6de23edb25c317/b0a15/image-26.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/749bc15be35b1458ec6de23edb25c317/8ff5a/image-26.png 240w,\n/static/749bc15be35b1458ec6de23edb25c317/e85cb/image-26.png 480w,\n/static/749bc15be35b1458ec6de23edb25c317/0b533/image-26.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/749bc15be35b1458ec6de23edb25c317/0b533/image-26.png\"\n            alt=\"image-26.png\"\n            title=\"image-26.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>The default settings are fine, so set a password under Domain Controller Options.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/3ff8d86206a1469719ab33792915db67/0b533/image-17.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 73.75%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAARlAAAEZQAGA43XUAAACe0lEQVQ4y2VU227UMBDNp8MTb/wH4gVRipBKq74hEKAWdVG6hVV3u5vLxrk6Tpw4zmHG2fRGpCN7bc+ZmTMz6yUiQxQL7GkVaY7NNkBCa6M7Qg9FqNvuPyhC0xl3X9YN+mHEx8/n8GSr6YIOmxaFat2+oj2j63tYO8AOz0BnA62NUqjKAmEQQIiEbDp4Y6dgCYAlDBitQUukujcwZjJ0sBZ2HInMOhhjkGWUlRBICKlIUSoifHl0hRdHC7w+X+PVyQpfVwKqKpAkiXssK0l7kmSfYLfbuXNFkfUUPTsaycn0jai1gXfqxzi+2OBkEeJsKbBOJIosxWZzh6IoXTRsVJYlFlcL+L6P5XKJIAwRErTWLlqGZEKYFjDaeXB+ht4Zp2lK+pSopERd1w5ZliPPCUXhomQw0STLgbAgoyiOsae0zGDRNA122y2iKMJ6vcbN8oZED50T55CiHR9pyWQzqSNU5LmqKrRt6y66rrsn45RYeElRZmnmnM0E93hOOIs7e2NCjoZJCkqtJB0zSp+J+TdLwekzCdtOxFMnuKI89sh7FpkryVEyaUctxF9MVT46/oR37z/gy7cf1FYDNXfvenVurVLpB8J55QecPsvAkXAU3MyKGn0bRLjbhYiT1BEy+kdFqXrLhOapJoYiGi2r79ZpKiajh298akNDMNBbsVrDm7UbDiOlKcVcajev8gCemofKznrb+0rbg7PbN2/had26FPUBXMlSKtSqoR5UkDVB1iio/7jF8rJ2aOkdzzJ3CZ9LshVRAk9kNGYz6F9G5AX1ZOp0yrjCRYVoL3D128f131t8/+Xj0l8hFjmCaI+A735e4PL0DH92Mf4BVDN+QZmP+qcAAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/3ff8d86206a1469719ab33792915db67/8ac56/image-17.webp 240w,\n/static/3ff8d86206a1469719ab33792915db67/d3be9/image-17.webp 480w,\n/static/3ff8d86206a1469719ab33792915db67/b0a15/image-17.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/3ff8d86206a1469719ab33792915db67/8ff5a/image-17.png 240w,\n/static/3ff8d86206a1469719ab33792915db67/e85cb/image-17.png 480w,\n/static/3ff8d86206a1469719ab33792915db67/0b533/image-17.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/3ff8d86206a1469719ab33792915db67/0b533/image-17.png\"\n            alt=\"image-17.png\"\n            title=\"image-17.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>Leave the following DNS Options and Additional Options at their defaults.</p>\n<p>In Additional Options, the NetBIOS domain name will contain the root domain name you set earlier.</p>\n<p>Leave the path and option confirmation screens at their defaults as well, and finally run the installation.</p>\n<p>The installation takes a while, so enjoy a coffee break until it is finished.</p>\n<p>When the installation finishes, the server restarts, and the domain name is shown on the login screen instead of the workgroup.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/4e218a4b5bfe6ef10e04522480f1bd66/0b533/image-27.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 80.41666666666667%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAQCAYAAAAWGF8bAAAACXBIWXMAARlAAAEZQAGA43XUAAAEIElEQVQ4yzWS/U+TVxSA34oIKCozU4NGPoTWFqGllJbW8tEP2r5AkYrQL8pboJQKrAWL0FIQiOC3Wcw23dymS4xsRkUxccuWxe1Pe3Zx2w9Pzs3JyXPPOfdKkiTxP0X7VJTsV1EqKCkuoljkjlRU0OpXCKdXiF9dYSC1RJldQWqJoDJHkVojgjCSaY8Qkkql+iQ6sH8fpUJSXrqfgyXFHFBJHDp2AmMgRXdyHf9UnsCVPLFMAd/4VSqcE0I0gmQR7InNkX/lZUKy11FZsZAWSRQLUZHo7NCJM1gnrjO68YT07e9J3XiEOZbHODyHL7FES3COzz2TFNnjSLZRJKugLYZUKiRlpaWUHSqnpPwIRyurqNTbsYwukrr7jOVHP7P541sWHm4TX/uGpuEsVf402ksZDENpKntTSF3jSJ2C9jGkph6FluEMzeJmvYgmJYdBydOfvUP6/lO2nr3l4S+/UXj8krm7P+BIrnLaP8u5wQzH+2Ypl69Q7E2h8kwhuSeRvF/coHt6HcfUGvbECtbxJUyxLL1zm+S+fs6DF7tC+pqbP+2QFKPrRxbRhBaoDl6jSkhPBdKcvDjLZ/0zHO6bRuqdXaFH4JlexZG6TmdyWZCnQzB95zFrT7bFuM8ofPuCwfw9DGMFGgLjNMoBNJEs6vA8dWKftcEMNcNppIH5Vfoyq7hTy3Qoc7inV0THOVzTS7hnlggWNkncuEckt4ErtYhR9tBQf5DWc6WoA5M0iF3rR+fRx+dpVDJIl7IFlPX7JBYW8TrbUPJbzD74juTWA6Zu3Wdi6y5jm3dI3vwSZTGH7FDjtJ3HadYghxS6F77CKr6TOTmPJTWHFFoqEFm9RTY3Q7zPhM1ipMvnYSibI5QvCJaJLK+Impv0X3ZjrDuGrVmHy6wj6jMQH/Hjm8niy1wTzCNNXN8gurJJMtaFXXOQxpqTrC+m2d7dZefjX+z8+ZE3gld//M3bl4/ZWEjga62ht/koXkMFV+UKBmQTsfwa4VweyT8WpycYoMepwdRSj63dytPtF+x8+MDr9+959e4db97v8npXxF9/59HT53hkGWtbC8ZWI3a7mfPNzZi8PVj8F5F8wcs4A4PorHaqmy2cNV3guKaJemsnjS4fWoeLBqeH1m4PFy40UaeuQ6PVoW88j7FJR0+7kQ5bGw5PH17ZhxSdmmJwRMFtM6Cvr0JbW4225jT+PplwNEgwMshQeIhIaJC4bKC94RRmdSUdInYbzhBqV9Nv1TDYpSfq1olH6TaRumhmXBQnxJITchOTciMTHg3j7rOCWsZctSjOs0QdGkZdOmKCsENLsFPLJbuGgK2OQFsVA5YzSCcPH2C4vZ4ZfyOTPi2TXg0JIZv0nvvvrP7ExB7d9UJeR1zIFUctsa4aoh3VRNqrCAuC9ir+AfmVYeWhb82fAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/4e218a4b5bfe6ef10e04522480f1bd66/8ac56/image-27.webp 240w,\n/static/4e218a4b5bfe6ef10e04522480f1bd66/d3be9/image-27.webp 480w,\n/static/4e218a4b5bfe6ef10e04522480f1bd66/b0a15/image-27.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/4e218a4b5bfe6ef10e04522480f1bd66/8ff5a/image-27.png 240w,\n/static/4e218a4b5bfe6ef10e04522480f1bd66/e85cb/image-27.png 480w,\n/static/4e218a4b5bfe6ef10e04522480f1bd66/0b533/image-27.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/4e218a4b5bfe6ef10e04522480f1bd66/0b533/image-27.png\"\n            alt=\"image-27.png\"\n            title=\"image-27.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>This completes the AD environment setup.</p>\n<p>After this, the other machines built in the lab environment will be added to AD and managed with Group Policy.</p>\n<h3 id=\"set-a-static-ip\" style=\"position:relative;\"><a href=\"#set-a-static-ip\" aria-label=\"set a static ip permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Set a Static IP</h3>\n<p>When joining a server to the AD you created, you need to configure the preferred DNS server on the joining server to use the domain controller’s IP address.</p>\n<p>To make this easier, set a static IP address on the domain controller side.</p>\n<p>When I opened the network properties, the preferred DNS server was set to localhost by default.</p>\n<p>With that setting left as is, all that remains is to set a static IP address.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 473px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/294c5eb1b8546188cedf978fd7ae6b39/c7c3c/image-20.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 111.25%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAWCAYAAADAQbwGAAAACXBIWXMAAAsTAAALEwEAmpwYAAADK0lEQVQ4y5VUiW7iMBTk/39sj6pSu0C7XIGQEnI6NzlImH3jkBSWaqWN9LBD7PGbeeM3+fBjuH4IR+JwdLG3HbiBwtELcHA8WPK+2VnYfdgwJYr6jKYD6vaiozp3+r2oarhxgYkTRnCOsrAokMQR4ihCmiYyj5EmjESP/J/f8yz7jPxzXmQpgiTHxI9ShGGAum5kQaGB8zwf54xMNpxOJx3Dt36U4Hquk7knWJMgzuF7LmzJ0rIszOczTGczrFdLbLdb7HY7rJYLLNdrzN/mmE2neHl5xfv7G15fOS6w3W2hwhBJUWPiqQTLxTvMvalp+b6HIAhwlANc10WkqYrOnofNZoPD4YAPCSbB+cG2YUsw2ygvMXEFsGvPKKsKfz+XywX/86j0xAxTnJsanmTgOo6muVqtYJp7GIYhmR5F33o84Kvo9MGXHtCPM02Vmx0B9H0fW2ODnWniVFb9hq7D+Sx2aZqHaNtWf79I9BlKZVqhTCDqV1b1Hd1hpJWoab/OH+dpml7XdQhT8aEbJoLearBQKV0QCnxLkU8ifjyK+J4AaXlkDKWytFW/+AHQRyyblAoFOEQtdIg1AEaR0noGga8PJSgPeQD0xYesskdAsQddzw1KAG4fUiYI/RaEPSDByrLsmXQjYKY3sJJN0wtfiYUaeac+pJ9luXgxGa01ZM1i9KGp9EWJMjlFrhTNyVOpC4MV580xpdrUi9eOMnzlzzvbxEWl6VjWXkBEIwEjdVLOrvQ5dqIz6ZHJEIN1ulvKcU56lQZkQQjGag9mHp5YOg2LouTbwEJrfnXEWJQoK8W0jW4CpKaU3GfJqjgVo07aNrKZspAF5TgcPnSVCXhXFP4QfaBA5/NWMD5F78b/ObbX8f7iX28Kf5ghT2b32EsReJ+NjaEzamTzVw/9+P37N/x8esJMWh57qgZkhrw2zTUrZslmy7i9q23b39ehwifxoCtJ9DIpVOWpp+wEETJp8Ylu9Y+RsP1TfHHC3gnxsrbxNFthatjYHBVs0XIpDdgw1rCOHiZ2ECNQMfx/hCcRRgkMAXheO/gx3+F5ZWNuStPdmvj19huLtaEP/ANQCJMLbUYznQAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/294c5eb1b8546188cedf978fd7ae6b39/8ac56/image-20.webp 240w,\n/static/294c5eb1b8546188cedf978fd7ae6b39/7124e/image-20.webp 473w\"\n              sizes=\"(max-width: 473px) 100vw, 473px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/294c5eb1b8546188cedf978fd7ae6b39/8ff5a/image-20.png 240w,\n/static/294c5eb1b8546188cedf978fd7ae6b39/c7c3c/image-20.png 473w\"\n            sizes=\"(max-width: 473px) 100vw, 473px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/294c5eb1b8546188cedf978fd7ae6b39/c7c3c/image-20.png\"\n            alt=\"image-20.png\"\n            title=\"image-20.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<h3 id=\"check-ad-and-dns\" style=\"position:relative;\"><a href=\"#check-ad-and-dns\" aria-label=\"check ad and dns permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Check AD and DNS</h3>\n<p>From [Tools] in Server Manager, open [Active Directory Users and Computers] and confirm that the combination of the computer name you set and the root domain name is correctly configured as the DNS name in [Domain Controllers].</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 774px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/cb0974d2618b05ae87e6354b11811391/41d3b/image-21.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 97.08333333333334%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAATCAYAAACQjC21AAAACXBIWXMAAAsTAAALEwEAmpwYAAAC+0lEQVQ4y31UCW7bMBDU/99R9DUJiqSIcyq2bMmURN0HRV2ezlJIC6dBCCxoW/Ls7MyQ3ilOEadnhHGMROcozhGKPEdrejTdiMF0WOcBxjSwo8F3y9oRXhgdcDrt8XoIEKoEar9HEJygEoVznKEocpwCH2lyQp6niMIIVVWhris0TYO+65BlGYbBouN3b3c44Og/4P39gHG0uLDTyzGFH4SIzgpl3eJ0jpGVNbrechpN5gapzhCRQFZUyKuGU0x4OGp4qmhQqEc87nZkUGC0FgOpR7Em88iBZkXJcScCGrdP8+KqN4MraXAhk7eUDAVZh3e4vb3B/d09/DcfJTs2XQudxm68JEkQU2Npqs5nShKw2QnH4xEHTphTczPOwLrAs2RkGkWtCkzTBNP37GrwHmgCW9ihd2ACvK4rhMpkBzeirHmeKdUEO5H1NAvg+MmrC3oKrIsWXcdmdLuj8IZNlmXGvKxo7IpqWDCQ1UUaEGgDnAg4boDyQHQQFh11qehY2zZ0s3bsHcsyR1Qa/LzJ8OMmx071MNOK2owY5xUy7RWgLAHsjXVGSGRkpWnqNIuVcsCpgPPZMNAUGiUlgAOncBp+BhSGRVUTKHEaiehKbToLARlt5C7/lVQYvj8uFyeNJw+vFLyIhiM0IzRQfFmZ1tAscTsnqOjZ0zzZt8/GAUqOPUEV6tJxITtpULcdCgZZfhfey7JclbzzUTKBGNvbjbUnmkiuZJeR5Bid44TBXa+k+G7NbBKnuYuWJyxcFkldzqYIr5LUxeCzFF/VB6BKM3Rtu5nyAdryhyPZBjxyhjr2feeayGjfAS7MplwsTVP/Y7hFYBNaXJZLIQpDJ4fcLF+tDzFmnuuy2cJ/BSgGaWZODLFM/1+NKKcYdsXM7auDFWPqtucxHf4HTCS4vGh1UZNZg9dQ49dzgKcgxpvv49Xfw3/f4/fDDv7+gKfnFzy/vCHNS7RyH34GFKcFSO6/vKygshLHOEeYZO4uVKyYBqhk22P3XTOfJcqyxB+OeLO9nuPK1QAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/cb0974d2618b05ae87e6354b11811391/8ac56/image-21.webp 240w,\n/static/cb0974d2618b05ae87e6354b11811391/d3be9/image-21.webp 480w,\n/static/cb0974d2618b05ae87e6354b11811391/9b58d/image-21.webp 774w\"\n              sizes=\"(max-width: 774px) 100vw, 774px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/cb0974d2618b05ae87e6354b11811391/8ff5a/image-21.png 240w,\n/static/cb0974d2618b05ae87e6354b11811391/e85cb/image-21.png 480w,\n/static/cb0974d2618b05ae87e6354b11811391/41d3b/image-21.png 774w\"\n            sizes=\"(max-width: 774px) 100vw, 774px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/cb0974d2618b05ae87e6354b11811391/41d3b/image-21.png\"\n            alt=\"image-21.png\"\n            title=\"image-21.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>Next, open [DNS] from [Tools] in Server Manager and confirm that the zones related to the AD you created are configured in Forward Lookup Zones.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 859px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/3f5feec02117af80f2fe0a7abb61b426/39a20/image-22.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 63.74999999999999%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAANCAYAAACpUE5eAAAACXBIWXMAAAsTAAALEwEAmpwYAAAB1ElEQVQ4y51S2W7cMAz0/39XX7pBgjRAgKZNduNTPtaHbEm2ZFtTUtuiCdAg2BIgSOoYajiKulGh7UcoM8OuHm7bYckppdxT/rnPboNZHPSyIopFgyR9QZyXEHWO10ygbjrIcYJzDvu+Y982itv7+CbftpXiCusYsCgRJyekFJVROLc9NcgwSAmlFLTWECXtKQ1jDEZqxHtaG2iq+2FAXTfh3KgMIjMbnOsEz88/0HUDyvyEx4cbbLuH90R9pc7WhvgvZxYXJkzbIlrsgqb4icPhK/KiQiNe8Hj/BVJqLMuCa2yxRFkpCdkmgdbuPc5NibvbA+I4Rtf34aCaJvT9QE0k5nkm2iMGojpSLSlfaY5sMwkTWbe961KRIDe335BnKc5dF9aKooAQAobAGPB4PCJLU2rS0/xqVHVFeUf7RFmbCy1Wk60+d7i7f0D8ekKe5zRHHwDLqoSjmbEwT0/fA4O2bVGWAhXtMeDMM9SEysYX2TT9x47oTUSTKTEdBuGaRdio5hFwzcqy/3mMW3dW+S8gu7UO/oOhX858tE53141Ups/41hzV3nv8j4UXDvRRp1EGeqxeiCG/wuk8Y8hJIUrp78VZQS5CzESNJBe/167zrGzwC+Ck6PlVm3NNAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/3f5feec02117af80f2fe0a7abb61b426/8ac56/image-22.webp 240w,\n/static/3f5feec02117af80f2fe0a7abb61b426/d3be9/image-22.webp 480w,\n/static/3f5feec02117af80f2fe0a7abb61b426/4e068/image-22.webp 859w\"\n              sizes=\"(max-width: 859px) 100vw, 859px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/3f5feec02117af80f2fe0a7abb61b426/8ff5a/image-22.png 240w,\n/static/3f5feec02117af80f2fe0a7abb61b426/e85cb/image-22.png 480w,\n/static/3f5feec02117af80f2fe0a7abb61b426/39a20/image-22.png 859w\"\n            sizes=\"(max-width: 859px) 100vw, 859px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/3f5feec02117af80f2fe0a7abb61b426/39a20/image-22.png\"\n            alt=\"image-22.png\"\n            title=\"image-22.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>Finally, start PowerShell and confirm that the domain controller’s address can be resolved correctly for the domain you created.</p>\n<div class=\"gatsby-highlight\" data-language=\"powershell\"><pre class=\"language-powershell\"><code class=\"language-powershell\">$ nslookup hackroom<span class=\"token punctuation\">.</span>lab\nサーバー:  localhost\nAddress:  ::1\n名前:    hackroom<span class=\"token punctuation\">.</span>lab\nAddresses:  2001:f71:81a0:3a00:3086:3ad5:664d:d4e0\n          192<span class=\"token punctuation\">.</span>168<span class=\"token punctuation\">.</span>100<span class=\"token punctuation\">.</span>50</code></pre></div>\n<p>The preferred DNS server on the AD server is defined as localhost by default after promotion to domain controller.</p>\n<p>This confirms that it can resolve its own address under the name <code class=\"language-text\">hacklab.local</code>.</p>\n<h3 id=\"add-an-ad-user\" style=\"position:relative;\"><a href=\"#add-an-ad-user\" aria-label=\"add an ad user permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Add an AD User</h3>\n<p>Immediately after configuring AD, only the default users are registered, so add a user.</p>\n<p>Open [Active Directory Administrative Center] from [Tools] in Server Manager.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/1a300755d0412ad4b2b1e1ef749b1af1/0b533/image-23.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 83.75%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAARCAYAAADdRIy+AAAACXBIWXMAARlAAAEZQAGA43XUAAACoUlEQVQ4y31T21LTUBTNr+kLyEVahw9w9Av8AwUffGF8cEZ/gicckZsoWguITBGndQBLbBoa0uba3Jom7XLvQ1PunJk1O+ec7HXWvkmL6wUsr6zh/YePWFlbR6G4ha+ForDFrR/Cfvu+KVAoboo92+zsKqTHT55ibOwBRkdGkM/lMDU1RXiIfD6P6enpwd0oHuXyyNHd5OQEJsbHcf/+vRshLRRK2N4sokiv/trfx97eHnZ2drC7u4tSqYRKpYJyuTy0Ahe/r0ByXBf9NEG2Op0OwjBCt5sgSc7g+T5ctw3HceF5HqIouhXS8/ltvFj8g2fz+5hbPQQ/YLd9xAPCth/Ccj349EgUd5GmqTiP45ge7V6DdCQr0E0bqm7AJEdFqREUBEEgFIdhCF3Xxd4yTViWJRTftiRN02DTj924g6Qbo9FoQCPoepPCdOGTM5MwoWG0YBqmCJtXv9+/BimgUDoUe0jgMJrNJjkalMtYOPEZ548t55fBoZEvUwqSSwoFIf0UDQhZoaqqsG1b7FmZaVpUEIeUnxA0cXe7wogJoyEhk8myLJQKwkHILhGqal08aFKKztdVhdFlhWq9DqVWEyngxeeWZSOg4likzLad4d0dhGc5TKkoCz+rmKE24laaXTrE3GcZr5YO8PpTFW+/VPFuQ8abjRpmlo8JVbxclTGbYeX4BoWnLfxVmziqayhXFVRVHWrLwT+1gd+VA9RONJxQi+lOgFPHh9xoQWnaAqrhQvIvFIWtZRqwqD1sy4R+qtG3gTDwxZ6Lwrn02jRdvURMWBh4iKNQIKHWk/wgHBIyuCV6VK1YdD5NC01GNgVxfD4RSZIK9Ho9mp4MKaQw6ohQM3Az83TweJ07J9dw09iJ0bOoahwGtwJXMWveu5zuwn/CG9iu3nJD2AAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/1a300755d0412ad4b2b1e1ef749b1af1/8ac56/image-23.webp 240w,\n/static/1a300755d0412ad4b2b1e1ef749b1af1/d3be9/image-23.webp 480w,\n/static/1a300755d0412ad4b2b1e1ef749b1af1/b0a15/image-23.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/1a300755d0412ad4b2b1e1ef749b1af1/8ff5a/image-23.png 240w,\n/static/1a300755d0412ad4b2b1e1ef749b1af1/e85cb/image-23.png 480w,\n/static/1a300755d0412ad4b2b1e1ef749b1af1/0b533/image-23.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/1a300755d0412ad4b2b1e1ef749b1af1/0b533/image-23.png\"\n            alt=\"image-23.png\"\n            title=\"image-23.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>Here, as shown above, right-click Users in the registered domain and create a new user.</p>\n<p>Here, I created a user named TESTUSER.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/887ea5efbb3dca1d1e42e668912a2c1a/0b533/image-24.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 55.00000000000001%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAARlAAAEZQAGA43XUAAAB00lEQVQoz41SSW7cQAzU/59iGMg3cgiCADkYSBwHGEUzrV29b9JUSGrsa3Igml3gUiyyUUqh73us64plWTAMA6ZxFP9fNk+T5HofkGPAn8mgsfSp+45SKzbjoF2A9REu/IdRrg8JZT8Qc0UpFU3btrDOIecsLLWxMBToKJDfzXmElHEchzTeH3b6h+RZayl3w7IRw67rsG0bYorycvGBRmbfGCN/H4L4tTKLgpwS3IME44wlwtQworkQQ01gJpC7zMuKkbRRNyWMAxUL3kNrTQXORE//kZpyMW7s6M8TjNOM5ta18EYDR0UKDkZT0XmRRGYxU9BKC+CxHMVdr1cpeLlc8Pr6C0r1sqAYT02b588/8fRN4dP3AU9fWjx/vWE0EcBdWI209ffxIzXh8Zg1X4MlvbkQa8q4p0U1L787vLQjflxnvPUb3gYDnwruNAIzvPWjSLCQHCzLh46k38eCCKuECcMUPArd0J4jjpKw1yInxIGikT6ZcfDOiWRcLAnbs/g765ViG96g3GE57yjmIi/ud9HOkXYh8FI2wrMY68lHXSszTcLu2CusMHzowp2ZQam73JPlAydzdOSJGiQ63EhScEPWSlsnfiBMzRodSaOGCX8BMGdNJAG5sGQAAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/887ea5efbb3dca1d1e42e668912a2c1a/8ac56/image-24.webp 240w,\n/static/887ea5efbb3dca1d1e42e668912a2c1a/d3be9/image-24.webp 480w,\n/static/887ea5efbb3dca1d1e42e668912a2c1a/b0a15/image-24.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/887ea5efbb3dca1d1e42e668912a2c1a/8ff5a/image-24.png 240w,\n/static/887ea5efbb3dca1d1e42e668912a2c1a/e85cb/image-24.png 480w,\n/static/887ea5efbb3dca1d1e42e668912a2c1a/0b533/image-24.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/887ea5efbb3dca1d1e42e668912a2c1a/0b533/image-24.png\"\n            alt=\"image-24.png\"\n            title=\"image-24.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>Finally, join another server to AD using this TESTUSER.</p>\n<h2 id=\"join-a-server-to-ad\" style=\"position:relative;\"><a href=\"#join-a-server-to-ad\" aria-label=\"join a server to ad permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Join a Server to AD</h2>\n<h3 id=\"set-the-preferred-dns-server-to-the-domain-controllers-ip-address\" style=\"position:relative;\"><a href=\"#set-the-preferred-dns-server-to-the-domain-controllers-ip-address\" aria-label=\"set the preferred dns server to the domain controllers ip address permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Set the Preferred DNS Server to the Domain Controller’s IP Address</h3>\n<p>First, open the network settings and change the preferred DNS server destination to the domain controller’s IP address.</p>\n<h3 id=\"join-the-client-to-the-domain\" style=\"position:relative;\"><a href=\"#join-the-client-to-the-domain\" aria-label=\"join the client to the domain permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Join the Client to the Domain</h3>\n<p>From System in Control Panel, select change computer name/domain and join the <code class=\"language-text\">hackroom.lab</code> domain.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 897px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/d75eba38d172da144032ebb11eb3de41/3a737/image-29.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 70%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAOCAYAAAAvxDzwAAAACXBIWXMAAAsTAAALEwEAmpwYAAADVklEQVQ4y0WU22okVRSG+wWUeQPvfBDvvFFEGBCcG70aFG9GEII3vsAoqCC5EcIgKCKSOCbTmZk4OU3SnelOVzp9ru6uqq5zVdexu9M5+LlSXkzBz9qw9/73v9a/VpVK723wxr0tfvpb4XFlwNaJytO6ypOTAeWaxFcDnp6O2FHGPGuM2K6P2JS9zZO+nBFUe6wfNNmutHn42yGl0sc73Plsn3LDQLUCBpZPW3cZuQFhluHFMW6cCjKCLCe/XBDmWYF4LjGN5cyU7GLO77stIbxf4c2VOgddneHEoavZ1AYORpgSxCGW7+FFiVySy0J4cX1RYHmzLOLr74Y/95qU7nyj8Pa3TR7XOpwODBqqQccOGfqiLPQYGRqaqWP7NvNlxmyRCkRdHpMv55TLmzz8YRXN0otylXbPVF40uhyddXjZaHNQa1LrqFSbXY6bKoeyv3faY6/WpqdPGExsycIgnUU8r55z9933+fzLt/h05WvKJxqlkW5juR5Kr8/LepPDmkJFabFXrbPX6HHUHrMvpLd4diIPdiz2jxVRPRFVHh+srPHg+3v8+POvbNWE0HA8qVNARx3R6g6oK+e8apxxcFShNTQ47TlEaUiUTckl3UyULa8XWGIWXKOFITsdneubBRsVSTlMI3Fqimk7OI6N6zqEYYAra1secsNYapb/j4ucaJYTznNU6YIoi1kscy4vcyG/YL0ypGT5LuOJLup69Ad9HM8VFVL0JGZs+/ixODxNcIIIW3CsB+wMfVqmS5pHxLOEaZ4I4ZKN6oiSbpv0xyraxMT3PKbTiCgSSLS9gFZfpX52LulrdEYjVENnoGuMrQlhEhZue5HP1VXGenVMyQ68oj3GhomiKOiGQZKmRKIwSROCwC9KoVk2E9cklMuWZxJnEelcelVITenVSyH8q6ZTShZz5tKgth/SUwe0e12CaEosExAnklJ6a8SMoWljuDYzmZTbaZldLYrmDvMUbZqLPUuenDmUlrOUS2nUSNxKxYxEajqXCXGDQNwPmXo2vqnhCVkYmCznUWEA/y4KZ4t1gSUv2kK4bQTsGj77Y4dDic+1gPIoYK3lsar4PDo1+UN+CKtVi0+2fO5vT3nwT8JXOxFfbE358BePu48cPlqb8M53ff4DMuvmsRgqHe8AAAAASUVORK5CYII='); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/d75eba38d172da144032ebb11eb3de41/8ac56/image-29.webp 240w,\n/static/d75eba38d172da144032ebb11eb3de41/d3be9/image-29.webp 480w,\n/static/d75eba38d172da144032ebb11eb3de41/10735/image-29.webp 897w\"\n              sizes=\"(max-width: 897px) 100vw, 897px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/d75eba38d172da144032ebb11eb3de41/8ff5a/image-29.png 240w,\n/static/d75eba38d172da144032ebb11eb3de41/e85cb/image-29.png 480w,\n/static/d75eba38d172da144032ebb11eb3de41/3a737/image-29.png 897w\"\n            sizes=\"(max-width: 897px) 100vw, 897px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/d75eba38d172da144032ebb11eb3de41/3a737/image-29.png\"\n            alt=\"image-29.png\"\n            title=\"image-29.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>For authentication, I used the credentials of the <code class=\"language-text\">TESTUSER</code> created earlier.</p>\n<h2 id=\"troubleshooting-when-failing-to-join-ad\" style=\"position:relative;\"><a href=\"#troubleshooting-when-failing-to-join-ad\" aria-label=\"troubleshooting when failing to join ad permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Troubleshooting When Failing to Join AD</h2>\n<h3 id=\"if-you-get-the-the-specified-domain-either-does-not-exist-or-could-not-be-contacted-error\" style=\"position:relative;\"><a href=\"#if-you-get-the-the-specified-domain-either-does-not-exist-or-could-not-be-contacted-error\" aria-label=\"if you get the the specified domain either does not exist or could not be contacted error permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>If You Get the “The specified domain either does not exist or could not be contacted” Error</h3>\n<p>First, check whether you changed the preferred DNS server destination to the domain controller’s IP address and whether you can reach the domain controller server with the <code class=\"language-text\">ping</code> command.</p>\n<p>Next, check from the command prompt on the domain controller side that the DNS server is running.</p>\n<div class=\"gatsby-highlight\" data-language=\"powershell\"><pre class=\"language-powershell\"><code class=\"language-powershell\">$ <span class=\"token function\">sc</span> queryex dns\nSERVICE_NAME: dns\n        <span class=\"token function\">TYPE</span>               : 10  WIN32_OWN_PROCESS\n        STATE              : 4  RUNNING\n                                <span class=\"token punctuation\">(</span>STOPPABLE<span class=\"token punctuation\">,</span> PAUSABLE<span class=\"token punctuation\">,</span> ACCEPTS_SHUTDOWN<span class=\"token punctuation\">)</span>\n        WIN32_EXIT_CODE    : 0  <span class=\"token punctuation\">(</span>0x0<span class=\"token punctuation\">)</span>\n        SERVICE_EXIT_CODE  : 0  <span class=\"token punctuation\">(</span>0x0<span class=\"token punctuation\">)</span>\n        CHECKPOINT         : 0x0\n        WAIT_HINT          : 0x0\n        PID                : 2800\n        FLAGS</code></pre></div>\n<p>If the problem still occurs after confirming this, use <code class=\"language-text\">nslookup</code> to confirm whether the domain controller for the domain you want to join can be resolved.</p>\n<div class=\"gatsby-highlight\" data-language=\"powershell\"><pre class=\"language-powershell\"><code class=\"language-powershell\">$ nslookup hackroom<span class=\"token punctuation\">.</span>lab\nサーバー:  UnKnown\nAddress:  2404:1a8:7f01:b::3\n<span class=\"token operator\">*</span><span class=\"token operator\">*</span><span class=\"token operator\">*</span> UnKnown が hackroom<span class=\"token punctuation\">.</span>lab を見つけられません: Non-existent domain</code></pre></div>\n<p>If the output looks like this, the domain controller’s DNS is not being referenced properly, so AD joining will fail.</p>\n<p>First, try disabling the firewall on the domain controller side and see whether DNS lookups start working.</p>\n<p>Next, on the client side (the server you want to join to AD), enter the following command in Command Prompt, clear the DNS cache, and then try <code class=\"language-text\">nslookup</code> again.</p>\n<div class=\"gatsby-highlight\" data-language=\"powershell\"><pre class=\"language-powershell\"><code class=\"language-powershell\">ipconfig/flushdns</code></pre></div>\n<p>If this still fails, check the DNS events on the domain controller side.</p>\n<h3 id=\"check-dns-events\" style=\"position:relative;\"><a href=\"#check-dns-events\" aria-label=\"check dns events permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Check DNS Events</h3>\n<p>Open the DNS tab in Server Manager and you can confirm events like the ones below.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/7d4dd945a94499e44e58e11ad7c35444/0b533/image-25.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 50.83333333333333%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAARlAAAEZQAGA43XUAAABxUlEQVQoz6WRaXPSUBSG84MBKYv9P45fndGOpR+1VmynaElbaFlkSQIhK0tCNqB9vIkbWr+ZmWeec96ce+bOXOn54SH5QoGDUolcLs+zYpHiwQG5fD7L/0UuX8jmKtUqlUqVUrlMqVSmKDJpbpvs4hB4xDENQm/JQxIJQpLAZxP6WZ3OpN5nFwdsouC7Aw/XtpBenrZ48WnAkaxxrbqcD13qX20uBjYfugbvOwaXQ4fGyOFj3+JU9HXhd/czznomn0Ve79uc9V3uxzrSnWbTHJm0FIu+seJq4tEUyFOfpiDtr4VvZ+tfmbxHmjdUj3PFZ6A7SOw28LDlcZtk/p9vt4mRwigiI4xYeT6evyYQdRDt8XcfxU/w1wG+OCtFYiCOI6I4ZrmYE4hHScKAaO3hL+esV4usDv3VHssntbdwWYjz2cKURCwc6C4tbc6NQFYc2hOXtpZmLjeqQ3Ns05mt6Jr+H/RSGz7OfPl74XaT0OhqvLroc/RlzJvGkNeXfd5ejThuKhzLKjVZoXarc3JncdI2qQl+utYymVrO3g2ThImqMOx10NUxU2WENhpgTFQsfZLZ/GFb2NI1zPTfVGOmKZjCjuPwDaQdzygvRMNoAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <picture>\n          <source\n              srcset=\"/static/7d4dd945a94499e44e58e11ad7c35444/8ac56/image-25.webp 240w,\n/static/7d4dd945a94499e44e58e11ad7c35444/d3be9/image-25.webp 480w,\n/static/7d4dd945a94499e44e58e11ad7c35444/b0a15/image-25.webp 500w\"\n              sizes=\"(max-width: 500px) 100vw, 500px\"\n              type=\"image/webp\"\n            />\n          <source\n            srcset=\"/static/7d4dd945a94499e44e58e11ad7c35444/8ff5a/image-25.png 240w,\n/static/7d4dd945a94499e44e58e11ad7c35444/e85cb/image-25.png 480w,\n/static/7d4dd945a94499e44e58e11ad7c35444/0b533/image-25.png 500w\"\n            sizes=\"(max-width: 500px) 100vw, 500px\"\n            type=\"image/png\"\n          />\n          <img\n            class=\"gatsby-resp-image-image\"\n            src=\"/static/7d4dd945a94499e44e58e11ad7c35444/0b533/image-25.png\"\n            alt=\"image-25.png\"\n            title=\"image-25.png\"\n            loading=\"lazy\"\n            style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n          />\n        </picture>\n  </a>\n    </span></p>\n<p>In my environment, there was an error saying that the DNS server could not open a socket on <code class=\"language-text\">192.168.100.50</code>.</p>\n<h3 id=\"using-local-in-the-ad-domain-name\" style=\"position:relative;\"><a href=\"#using-local-in-the-ad-domain-name\" aria-label=\"using local in the ad domain name permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Using .local in the AD Domain Name</h3>\n<p>I messed this up in my environment.</p>\n<p>I had to rebuild AD.</p>\n<p>Reference: <a href=\"https://asohiroblog.net/active-directory-domain-name-local/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Active Directoryのドメイン名に「.local」を使ってはいけない件 - asohiroblog</a></p>\n<h3 id=\"disable-ipv6\" style=\"position:relative;\"><a href=\"#disable-ipv6\" aria-label=\"disable ipv6 permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Disable IPv6</h3>\n<p>It seems that joining AD can fail if name resolution uses IPv6.</p>\n<p>Reference: <a href=\"https://vamdemicsystem.black/windows/%E3%80%90activedirectory%E3%80%91%E3%83%89%E3%83%A1%E3%82%A4%E3%83%B3%E5%8F%82%E5%8A%A0%E6%99%82%E3%81%AB%E3%80%8C%E3%83%89%E3%83%A1%E3%82%A4%E3%83%B3xxx%E3%81%AEactivedirectory%E3%83%89%E3%83%A1\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">【Active Directory】ドメイン参加時に「ドメインxxxのActiveDirectoryドメインコントローラ(AD DC)に接続できませんでした。」メッセージが出力され失敗する | 株式会社ヴァンデミックシステム</a></p>\n<h3 id=\"dns-can-resolve-the-domain-controller-but-you-still-cannot-join-ad\" style=\"position:relative;\"><a href=\"#dns-can-resolve-the-domain-controller-but-you-still-cannot-join-ad\" aria-label=\"dns can resolve the domain controller but you still cannot join ad permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>DNS Can Resolve the Domain Controller, but You Still Cannot Join AD</h3>\n<p>If you get an error like the following, it seems that DNS successfully resolves the domain controller name, but the connection to the domain controller itself fails.</p>\n<div class=\"gatsby-highlight\" data-language=\"bash\"><pre class=\"language-bash\"><code class=\"language-bash\">クエリによって、次のドメイン コントローラが識別されました。\n\n<span class=\"token operator\">&lt;</span>DC<span class=\"token operator\">></span>\n\nこのエラーの一般的な原因:\n\n- ドメイン コントローラの名前を IP アドレスに割り当てるための Host <span class=\"token punctuation\">(</span>A<span class=\"token punctuation\">)</span> レコードが見つからないか、正しくないアドレスを含んでいる。\n- DNS で登録されているドメイン コントローラがネットワークに接続されていないか、実行中でない。</code></pre></div>\n<p>In my environment, this problem occurred when I created AD with multiple NICs. Recreating AD with only one NIC assigned to the AD server resolved it.</p>\n<h3 id=\"when-integration-is-not-going-well\" style=\"position:relative;\"><a href=\"#when-integration-is-not-going-well\" aria-label=\"when integration is not going well permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>When Integration Is Not Going Well</h3>\n<p>Try checking the following.</p>\n<p>Reference: <a href=\"http://niyodiary.cocolog-nifty.com/blog/2009/09/pc-499b.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ドメイン参加時にクライアントPC・サーバー設定で気をつけること: niyoな日記</a></p>\n<p>I also referred to the following article.</p>\n<p>Reference: <a href=\"https://validationmemo.blogspot.com/2019/01/active-directory.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ValidationMemo: Active Directoryのドメイン名を検討するときに考えるべきこと</a></p>\n<h2 id=\"enable-ldaps-and-integrate-applications-with-ad\" style=\"position:relative;\"><a href=\"#enable-ldaps-and-integrate-applications-with-ad\" aria-label=\"enable ldaps and integrate applications with ad permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Enable LDAPS and Integrate Applications with AD</h2>\n<p>If you want to use LDAPS to integrate AD with other applications, the following articles were helpful.</p>\n<p>If you only need to install Active Directory Certificate Services and use a self-signed certificate for authentication, it can be configured very easily.</p>\n<p>Reference: <a href=\"https://kmmr.jp/post-413/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Active DirectoryのLDAPS通信を有効化する | KMMR Note</a></p>\n<p>Reference: <a href=\"https://blog.putise.com/windows-ad%E3%81%AEldaps%E6%9C%89%E5%8A%B9%E5%8C%96%E3%81%AE%E6%A7%8B%E7%AF%89%E6%96%B9%E6%B3%95/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Windows ADサーバーのLDAPS有効化の構築方法 | puti se blog</a></p>\n<h2 id=\"summary\" style=\"position:relative;\"><a href=\"#summary\" aria-label=\"summary permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Summary</h2>\n<p>I had a hard time resolving the issues, and troubleshooting took quite a while.</p>\n<p>As expected, if your understanding of AD integration itself is insufficient, troubleshooting also takes more time.</p>","fields":{"slug":"/windows-activedirectory-lab-en","tagSlugs":["/tag/active-directory/","/tag/windown-server/","/tag/備忘録/","/tag/english/"]},"frontmatter":{"date":"2021-12-05","description":"","tags":["ActiveDirectory","WindownServer","備忘録","English"],"title":"Notes on Building an Active Directory Lab Environment: Steps and Troubleshooting","socialImage":{"publicURL":"/static/94f7e08e2e22c344b8817a31b1bc027d/windows-activedirectory-lab.png"}}}},"pageContext":{"slug":"/windows-activedirectory-lab-en"}},"staticQueryHashes":["251939775","401334301","825871152"]}