How To: Installing the first Domain Controller in a Child Domain
Prerequisites:
- You have completed the application process.
- You have a server that meets Microsoft's minimum requirements.
- Your have the administrative account and password provided by an ACCESS administrator
Step 1: Patch the Machine and Setup the Machine Name
Patching the Machine
It is extremely important to have an updated machine prior to installing the
machine into Active Directory. You can use the Windows® Software
Update Service to patch and update the machine, or another method of your
choice.
Setting Up the Machine Name:
- Right-click My Computer and choose Properties.
- Choose Computer Name.
- Click <Change>.
- Ensure that the Computer name text box has the correct machine name and that
the machine name is correctly prefix with your organization's designated two-
or three-letter prefix.

- Click <More>.
- Click the Change primary DNS suffix when domain membership changes check box to disable this option.
- Enter the DNS suffix of the machine where YourDNSsuffix.psu.edu is the the DNS suffix of the Fully Qualified Domain Name (FQDN) for the machine.

- Click <OK> for the next four windows.
- Click <Yes> to restart the computer.
- After rebooting, right-click My Network Places and choose Properties.
Choose the connection used to access the network.
- Right-click and choose Properties.
- Double-click Internet Protocol (TCP/IP).
- Click Advanced.
- Choose the DNS Tab.
- Ensure that the DNS servers listed are the DNS servers you generally use
to resolve DNS names; you may use the two listed or DNS servers run by your
organization.
- In the Append, these DNS suffixes (in order) text box replace your DNSsuffix.psu.edu
with your organization's DNS suffix and be sure to include aset.psu.edu as
well.
- Click the Register the connection's addresses in DNS check box to disable this option.

- You can also set a WINS server. (optional)
- Under Advanced TCP/IP Settings, select the WINS tab.
- Click <Add>.
- You may use the WINS server provided by us or a WINS server of your choice.
- Click <Add>.

- Click <OK>.
- Click <OK>.
- Click <OK>.
Step 2: Start the DC Promotion
- Choose Start –>Run.
- Enter dcpromo and click <Enter>.
- Click <Next> and click <Next> again.
- Click the Domain Controller radio button for a new domain.
- Click <Next>.

- The Create New Domain screen appears. Click the radio button for Child domain in an exsisting domain tree to choose this option.
- Click <Next>.

- Click <Next>.
- The Network Credentials screen appears. Enter your administrative account information.

- Click <Next>.
- The Child Domain Installation screen appears. Enter the parent domain (access.psu.edu) and the child domain names in the fields provided.

- Click <Next>. This may take time to process. Please be patient.
- The next screen appears. Choose the NetBIOS name.

- Click <Next>
- Choose the location for the SYSVOL.

- Click <Next>. This may take time to process. Please be patient.
- Click the Install and configure the DNS server on this computer, and set this computer to use this DNS server as its preferred DNS server radio button. Note that this error is expected.

- Click <Next>. This may take time to process. Please be patient.
- The Permissions screen appears. Click the Permissions compatible only with Windows® 2000 or Windows® Server 2003 operating systems radio button.

- Click <Next>.
- Choose a restore mode password.

- Click <Next>
- Review the information you provided and click <Next>. It will take several minutes to install a DNS server.

- Click <Finish>, and then click <Restart>. Then, continue
setting up the DNS server.

- Click <Next>
- Enter a Restore Mode Password for the Directory Services Restore Mode Administrator Password in the fields provided. Click <Next>.
Step 3: Configure DNS
- Log on to the same Domain Controller as in the previous step.
- Choose Start –>Run.
- Enter dnsmgmt.msc and click <Enter>.
- Expand the direectory tree to Forward Lookup Zones.

- Right-click Forward Lookup Zones.
- Choose New Zone and click <Next>.
- Click the Primary Zone radio button and click <Next>.

- Click <Next>.
- Click the To all DNS servers in the Active Directory domain radio button.
- Click <Next>.

- In the Zone name: field, enter _tcp.yourdomainname.access.psu.edu.
- Click <Next>.


- Choose the method you would like to use to allow dynamic updates.

- Click <Next>.
- Review your information and click <Finish>.
- Repeat this process until the following zones are defined:
- _msdcs.yourdomain.access.psu.edu
- _tcp. yourdomain.access.psu.edu
- _udp. yourdomain.access.psu.edu
- _sites.yourdomain.access.psu.edu
- DomainDnsZones. yourdomain.access.psu.edu

- Next, right-click yourdomain.access.psu.edu.
- Choose Delete.
- Choose Yes. (A warning message appears; disregard it).
- Choose Yes to remove the zone from both Active Directory® and the DNS server.

Setting Up the Registry Entries for the K5 KDCs
- Visit https://downloads.its.psu.edu/. Upon successful authentication, click "File Transfer". Then, click the "Windows" link for the Registry key for PASS Access. Once it has been downloaded simply run the file and it will handle the addition of information into your registry.
- Test the configuration by using your Penn State Access Account userid and password to log on. In this case, you will enter (for example) xyz123@dce.psu.edu and the password, where xyz123 represents your Access Account userid.
- If the message, local policy of this system does not permit you to log on interactively, appears or the machine allows you to log in, then the trust works.