Penn State Mark Windows Active Directory Service at Penn State banner Information Technology Services

 

How To: Installing the first Domain Controller in a Child Domain


Prerequisites:

  1. You have completed the application process.
  2. You have a server that meets Microsoft's minimum requirements.
  3. Your have the administrative account and password provided by an ACCESS administrator

Step 1: Patch the Machine and Setup the Machine Name

Patching the Machine

It is extremely important to have an updated machine prior to installing the machine into Active Directory. You can use the Windows® Software Update Service to patch and update the machine, or another method of your choice.

Setting Up the Machine Name:

  1. Right-click My Computer and choose Properties.
  2. Choose Computer Name.
  3. Click <Change>.
  4. Ensure that the Computer name text box has the correct machine name and that the machine name is correctly prefix with your organization's designated two- or three-letter prefix.
  5. Computer Name Changes window

  6. Click <More>.
  7. Click the Change primary DNS suffix when domain membership changes check box to disable this option.
  8. Enter the DNS suffix of the machine where YourDNSsuffix.psu.edu is the the DNS suffix of the Fully Qualified Domain Name (FQDN) for the machine.
  9. DNS Suffix and NetBIOS Computer Name

  10. Click <OK> for the next four windows.
  11. Click <Yes> to restart the computer.
  12. After rebooting, right-click My Network Places and choose Properties. Choose the connection used to access the network.
  13. Right-click and choose Properties.
  14. Double-click Internet Protocol (TCP/IP).
  15. Click Advanced.
  16. Choose the DNS Tab.
  17. Ensure that the DNS servers listed are the DNS servers you generally use to resolve DNS names; you may use the two listed or DNS servers run by your organization.
  18. In the Append, these DNS suffixes (in order) text box replace your DNSsuffix.psu.edu with your organization's DNS suffix and be sure to include aset.psu.edu as well.
  19. Click the Register the connection's addresses in DNS check box to disable this option.
  20. TCP/IP Settings

  21. You can also set a WINS server. (optional)
  22. Under Advanced TCP/IP Settings, select the WINS tab.
  23. Click <Add>.
  24. You may use the WINS server provided by us or a WINS server of your choice.
  25. Click <Add>.
  26. WINS Settings

  27. Click <OK>.
  28. Click <OK>.
  29. Click <OK>.

Step 2: Start the DC Promotion

  1. Choose Start –>Run.
  2. Enter dcpromo and click <Enter>.
  3. Click <Next> and click <Next> again.
  4. Click the Domain Controller radio button for a new domain.
  5. Click <Next>.
  6. Domain Controller Type screen

  7. The Create New Domain screen appears. Click the radio button for Child domain in an exsisting domain tree to choose this option.
  8. Click <Next>.
  9. Create New Domain screen

  10. Click <Next>.
  11. The Network Credentials screen appears. Enter your administrative account information.
  12. Network Credentials screen

  13. Click <Next>.
  14. The Child Domain Installation screen appears. Enter the parent domain (access.psu.edu) and the child domain names in the fields provided.
  15. Child Domain Installation screen

  16. Click <Next>. This may take time to process. Please be patient.
  17. The next screen appears. Choose the NetBIOS name.
  18. Create New Domain screen

  19. Click <Next>
  20. Choose the location for the SYSVOL.
  21. NetBIOS Domain Name screen

  22. Click <Next>. This may take time to process. Please be patient.
  23. Click the Install and configure the DNS server on this computer, and set this computer to use this DNS server as its preferred DNS server radio button. Note that this error is expected.
  24. Database and Log Folders screen

  25. Click <Next>. This may take time to process. Please be patient.
  26. The Permissions screen appears. Click the Permissions compatible only with Windows® 2000 or Windows® Server 2003 operating systems radio button.
  27. Shared System Volume screen

  28. Click <Next>.
  29. Choose a restore mode password.
  30. DNS Registration Diagnostics

  31. Click <Next>
  32. Review the information you provided and click <Next>. It will take several minutes to install a DNS server.
  33. Permissions screen

  34. Click <Finish>, and then click <Restart>. Then, continue setting up the DNS server.
  35. Directory Services Restore Mode Administrator Password

  36. Click <Next>
  37. Enter a Restore Mode Password for the Directory Services Restore Mode Administrator Password in the fields provided. Click <Next>.

Step 3: Configure DNS

  1. Log on to the same Domain Controller as in the previous step.
  2. Choose Start –>Run.
  3. Enter dnsmgmt.msc and click <Enter>.
  4. Expand the direectory tree to Forward Lookup Zones.
  5. Summary screen

  6. Right-click Forward Lookup Zones.
  7. Choose New Zone and click <Next>.
  8. Click the Primary Zone radio button and click <Next>.
  9. Forward Lookup Zones window

  10. Click <Next>.
  11. Click the To all DNS servers in the Active Directory domain radio button.
  12. Click <Next>.
  13. Zone Type screen

  14. In the Zone name: field, enter _tcp.yourdomainname.access.psu.edu.
  15. Click <Next>.
  16. Active Directory Zone Replication Scope screen

    Create New Domain screen

  17. Choose the method you would like to use to allow dynamic updates.
  18. Dynamic Update screen

  19. Click <Next>.
  20. Review your information and click <Finish>.
  21. Repeat this process until the following zones are defined:
  22. Choosing your domain window

  23. Next, right-click yourdomain.access.psu.edu.
  24. Choose Delete.
  25. Choose Yes. (A warning message appears; disregard it).
  26. Choose Yes to remove the zone from both Active Directory® and the DNS server.
  27. Forward Lookup Zones window


Setting Up the Registry Entries for the K5 KDCs

  1. Click here to run the Registry setup file.
  2. Test the configuration by using your Penn State Access Account userid and password to log on. In this case, you will enter (for example) xyz123@dce.psu.edu and the password, where xyz123 represents your Access Account userid.
  3. If the message, local policy of this system does not permit you to log on interactively, appears or the machine allows you to log in, then the trust works.

The Pennsylvania State University ©2006. All rights reserved.
Alternative Media - Nondiscrimination Statement
This site maintained by Academic Services and Emerging Technologies, a unit of Information Technology Services.

Problem reports and requests for assistance should be directed to ITS Help Desk staff.

Last revised: Tuesday, March 14, 2006.