Penn State Mark Windows Active Directory Service at Penn State banner Information Technology Services

 

How To: Installing an additional Domain Controller in a child domain


Prerequisites:

  1. You have contacted the Win-AD team to inform them that you are adding a DC (without notification, your new DC will not be able to communicate correctly with the ACCESS DCs).
  2. You have a server that meets Microsoft's minimum requirements.
  3. You have the administrative account and password provided by an ACCESS administrator.
  4. You have an existing Child Domain.

Step 1: Patch the machine and setup the machine name.

Patching the Machine

It is extremely important to have an updated machine prior to installing the machine into Active Directory. You can use the Windows® Software Update Service to patch and update the machine, or another method of your choice.

Setting Up the Machine Name:

  1. Right-click My Computer and choose Properties.
  2. Choose Computer Name.
  3. Click <Change>.
  4. Ensure that the Computer name text box has the correct machine name and that the machine name is correctly prefix with your organization's designated two- or three-letter prefix.
  5. Computer Name Changes window

  6. Click <More>.
  7. Click the Change primary DNS suffix when domain membership changes check box to disable this option.
  8. Enter the DNS suffix of the machine where YourDNSsuffix.psu.edu is the the DNS suffix of the Fully Qualified Domain Name (FQDN) for the machine.
  9. DNS Suffix and NetBIOS Computer Name

  10. Click <OK> for the next four windows.
  11. Click <Yes> to restart the computer.
  12. After rebooting, right-click My Network Places and choose Properties. Choose the connection used to access the network.
  13. Right-click and choose Properties.
  14. Double-click Internet Protocol (TCP/IP).
  15. Click Advanced.
  16. Choose the DNS Tab.
  17. Ensure that the DNS servers listed are the DNS servers you generally use to resolve DNS names; you may use the two listed or DNS servers run by your organization.
  18. In the Append, these DNS suffixes (in order) text box replace your DNSsuffix.psu.edu with your organization's DNS suffix and be sure to include aset.psu.edu as well.
  19. Click the Register the connection's addresses in DNS check box to disable this option.
  20. TCP/IP Settings

  21. You can also set a WINS server. (optional)
  22. Under Advanced TCP/IP Settings, select the WINS tab.
  23. Click <Add>.
  24. You may use the WINS server provided by us or a WINS server of your choice.
  25. Click <Add>.
  26. WINS Settings

  27. Click <OK>.
  28. Click <OK>.
  29. Click <OK>.

Step 2: Start the DC Promotion.

  1. Choose Start –>Run.
  2. Enter dcpromo and click <Enter>.
  3. Click <Next> and click <Next> again.
  4. Click the Additional Domain Controller for a new domain radio button.
  5. Click <Next>.
  6. Domain Controller Type screen

  7. Using the administrator account or an administrative account in your child domain, enter the appropriate account information in the fields provided.
  8. Click <Next>.
  9. Network Credentials screen

  10. Enter the name of your child domain.
  11. Additional Domain Controller screen

  12. Click <Next>.
  13. Choose the location for the Active Directory® database (choosing a drive or a partitioned drive is recommended).
  14. Database and Log Folders screen

  15. Click <Next>.
  16. Choose a location for the SYSVOL.
  17. Shared System Volume screen

  18. Click <Next>.
  19. Choose a restore mode password.
  20. Directory Services Restore Mode Administrator Password screen

  21. Click <Next>. This may take time to process. Please be patient.
  22. Review the information.
  23. Click <Next>. This may take time to process. Please be patient.
  24. Click <Finish>.
  25. Click <Restart Now>.

Setting Up the Registry Entries for the K5 KDCs

  1. Click here to run the Registry setup file.
  2. Test the configuration by using your Penn State Access Account userid and password to log on. In this case, you will enter (for example) xyz123@dce.psu.edu and the password, where xyz123 represents your Access Account userid.
  3. If the message, local policy of this system does not permit you to log on interactively, appears or the machine allows you to log in, then the trust works.

The Pennsylvania State University ©2006. All rights reserved.
Alternative Media - Nondiscrimination Statement
This site maintained by Academic Services and Emerging Technologies, a unit of Information Technology Services.

Problem reports and requests for assistance should be directed to ITS Help Desk staff.

Last revised: Tuesday, March 14, 2006.