A beginner-friendly guide to understanding Active Directory and building a domain controller with Microsoft Windows Server
Active Directory (AD) is Microsoft's identity and directory service. At its heart it is a giant, centralised phone book for your network: it stores every user, computer, group, and policy, and it answers the two questions every IT system needs β "Who are you?" (authentication) and "What are you allowed to do?" (authorization).
| Scenario | Without AD | With AD |
|---|---|---|
| A new employee joins | Admin creates accounts on the PC, the printer, the email server, the file serverβ¦ separately | Create one user in AD β access flows to every joined system |
| An employee leaves | Hunt down every system they could log into | Disable one account β their access dies everywhere |
| Force password changes for 200 PCs | Walk to every computer | One Group Policy pushes to all of them |
| Concept | What it is |
|---|---|
| Domain | A logical group of users/computers managed together, e.g. corp.example.com |
| Domain Controller (DC) | A server that hosts AD and handles logins β the "source of truth" |
| Forest | The top-level container holding one or more domains under a shared namespace |
| Organisational Unit (OU) | A folder inside a domain for grouping users/computers, e.g. "Sales", "IT". OUs are the natural target for Group Policy |
| User / Computer | Objects in AD β every identity and endpoint in the domain |
| Group | A collection of users used to grant permissions (e.g. "HR-ReadOnly") |
| LDAP | The protocol/interface AD exposes for reading and writing the directory |
| Kerberos | The authentication protocol β issues "tickets" proving you logged in, so services trust you |
| Group Policy (GPO) | Central rules applied to computers and users (policies, software, security) |
| Workgroup | Active Directory (Domain) |
|---|---|
| Small networks, no central server | Central server(s) manage everything |
| Each PC logs in locally (SAM database) | Each PC trusts the domain for logins |
| Account exists only on that one machine | One account works on every joined machine |
| No central policy or reuse | GPOs, centralised AD, single sign-on |
Install a Windows Server VM (e.g. Windows Server 2022), give it a static IP address and a fixed hostname. A domain controller's identity must never change (DHCP leases are unreliable for it).
hostname # e.g. DC-01
Open Server Manager β Add roles and features, tick Active Directory Domain Services, or use PowerShell in an admin console:
> Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
Click the flag β Promote this server to a domain controller. Choose Add a new forest and type the root domain name (e.g. corp.example.com). Set the Directory Services Restore Mode (DSRM) password.
Open Active Directory Users and Computers (dsa.msc). Right-click the domain β New β Organisational Unit. Build for example:
corp.example.com βββ Users β user accounts live here βββ Groups β e.g. "Sales-ReadOnly", "IT-Admins" βββ Computers β domain-joined machines
Right-click the Users OU β New β User. Fill in name and logon name, set (and enforce) a password. Done β that user can now log into any joined PC.
| Group | Purpose |
|---|---|
Sales-ReadOnly | Access to shared sales folder (read only) |
IT-Admins | Admin rights on department computers |
Select a user β Properties β Member Of β Add the group. Group membership is how you grant permissions once and change them everywhere later.
On the Windows PC: Settings β System β About β Rename this PC (advanced) β Change β Member of: Domain. Enter corp.example.com and an admin account name. Reboot β now the PC trusts AD for logins.
Group Policy lets you control hundreds of computers at once. Policies apply to OUs, so structure your OUs to match the rules you want to enforce β e.g. a "Kiosk-PCs" OU for the lobby machines.
Using the Group Policy Management console (gpmc.msc): right-click your OU β Create a GPO in this domain... and Link it here.
| Tool / Command | What it does |
|---|---|
dsa.msc | Active Directory Users and Computers (main console) |
gpmc.msc | Group Policy Management |
dns.msc | DNS snap-in β DCs also host DNS |
dsadd user / dsrm | Create / delete users from CLI |
Get-ADUser, Set-ADUser | PowerShell read / modify users |
Get-ADGroupMember <group> | List members of a group |
New-ADUser -Name ... | Create a user in PowerShell |
Active Directory turns a thousand passwords and per-PC setups into one directory that runs the network.
Build it once, and identity, policy, and security become a single connected system.
Created by jcmatira