πŸͺŸ Active Directory on Windows Server

A beginner-friendly guide to understanding Active Directory and building a domain controller with Microsoft Windows Server

1. What is Active Directory?

Active Directory (AD) is Microsoft's identity and directory service. At its heart it is a giant, centralised phone book for your network: it stores every user, computer, group, and policy, and it answers the two questions every IT system needs β€” "Who are you?" (authentication) and "What are you allowed to do?" (authorization).

πŸ“’ Analogy β€” The Office Building Badge System
Imagine a company office where every door is locked. Active Directory is like the central HR office plus the badge system combined: it keeps a master list of every employee (users), every room (computers), and every team (groups). When you tap your badge, the system checks who you are and which rooms you're allowed to enter. You get ONE badge that opens every door you're permitted to β€” no separate key for every room.

🎯 Real-World Examples

ScenarioWithout ADWith AD
A new employee joinsAdmin creates accounts on the PC, the printer, the email server, the file server… separatelyCreate one user in AD β€” access flows to every joined system
An employee leavesHunt down every system they could log intoDisable one account β€” their access dies everywhere
Force password changes for 200 PCsWalk to every computerOne Group Policy pushes to all of them

2. Why use Active Directory? (The Benefits)

πŸ”‘ Centralised identity
One user, one password, one badge β€” everywhere on the network.
πŸ›‚ Authentication & authorization
AD verifies who you are and what you may access, via Kerberos and LDAP.
πŸ“¦ Group Policy
Push software, settings, and security rules to the whole domain at once.
πŸ—‚οΈ Organization
Organise users and computers into a tree of organisational units (OUs).
🧩 Single sign-on (SSO)
Log in once and access email, file shares, and apps without re-entering passwords.
πŸ” Replication
Multiple domain controllers stay in sync, so there's no single point of failure.

3. Core Concepts

ConceptWhat it is
DomainA logical group of users/computers managed together, e.g. corp.example.com
Domain Controller (DC)A server that hosts AD and handles logins β€” the "source of truth"
ForestThe top-level container holding one or more domains under a shared namespace
Organisational Unit (OU)A folder inside a domain for grouping users/computers, e.g. "Sales", "IT". OUs are the natural target for Group Policy
User / ComputerObjects in AD β€” every identity and endpoint in the domain
GroupA collection of users used to grant permissions (e.g. "HR-ReadOnly")
LDAPThe protocol/interface AD exposes for reading and writing the directory
KerberosThe authentication protocol β€” issues "tickets" proving you logged in, so services trust you
Group Policy (GPO)Central rules applied to computers and users (policies, software, security)

4. Workgroup vs Domain

WorkgroupActive Directory (Domain)
Small networks, no central serverCentral server(s) manage everything
Each PC logs in locally (SAM database)Each PC trusts the domain for logins
Account exists only on that one machineOne account works on every joined machine
No central policy or reuseGPOs, centralised AD, single sign-on
🏠 Analogy β€” Each House With Its Own Guest Book vs One Front-Desk
A workgroup is like 20 separate houses, each with its own paper guest book: visitors sign in at each house. A domain is a guarded apartment complex: everyone is registered once at the front desk, and that one badge opens every door you're allowed to use.

5. Step-by-Step: Spin Up a Domain Controller

Prepare the server

Install a Windows Server VM (e.g. Windows Server 2022), give it a static IP address and a fixed hostname. A domain controller's identity must never change (DHCP leases are unreliable for it).

hostname			# e.g. DC-01
Install the AD DS role

Open Server Manager β†’ Add roles and features, tick Active Directory Domain Services, or use PowerShell in an admin console:

> Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
Promote to a domain controller

Click the flag β†’ Promote this server to a domain controller. Choose Add a new forest and type the root domain name (e.g. corp.example.com). Set the Directory Services Restore Mode (DSRM) password.

Create organisational units and groups

Open Active Directory Users and Computers (dsa.msc). Right-click the domain β†’ New β†’ Organisational Unit. Build for example:

corp.example.com
β”œβ”€β”€ Users            ← user accounts live here
β”œβ”€β”€ Groups           ← e.g. "Sales-ReadOnly", "IT-Admins"
└── Computers        ← domain-joined machines
Create users

Right-click the Users OU β†’ New β†’ User. Fill in name and logon name, set (and enforce) a password. Done β€” that user can now log into any joined PC.

Put users in groups
GroupPurpose
Sales-ReadOnlyAccess to shared sales folder (read only)
IT-AdminsAdmin rights on department computers

Select a user β†’ Properties β†’ Member Of β†’ Add the group. Group membership is how you grant permissions once and change them everywhere later.

Join a client computer to the domain

On the Windows PC: Settings β†’ System β†’ About β†’ Rename this PC (advanced) β†’ Change β†’ Member of: Domain. Enter corp.example.com and an admin account name. Reboot β€” now the PC trusts AD for logins.

6. Group Policy (The Superpower)

Group Policy lets you control hundreds of computers at once. Policies apply to OUs, so structure your OUs to match the rules you want to enforce β€” e.g. a "Kiosk-PCs" OU for the lobby machines.

πŸ“‹ Common things to push with a GPO

Using the Group Policy Management console (gpmc.msc): right-click your OU β†’ Create a GPO in this domain... and Link it here.

7. Quick Reference β€” Everyday Tools & Commands

Tool / CommandWhat it does
dsa.mscActive Directory Users and Computers (main console)
gpmc.mscGroup Policy Management
dns.mscDNS snap-in β€” DCs also host DNS
dsadd user / dsrmCreate / delete users from CLI
Get-ADUser, Set-ADUserPowerShell read / modify users
Get-ADGroupMember <group>List members of a group
New-ADUser -Name ... Create a user in PowerShell

8. Best Practices & Next Steps

πŸ—Ώ Don't run DCs from DHCP
Domain controllers must have static IPs and stable hostnames.
πŸ”„ Run at least two DCs
Redundancy means one DC can fail without logging everyone else out.
πŸ“¦ Organise by OU, not group-spaghetti
OUs map to your departments and security rules; keep groups for permission grants.
πŸ” Set real password policy
Enforce complexity, expiry, and lockout via a GPO from day one.
πŸ—žοΈ Back up AD
DCs are critical β€” use your favorite backup method and test a restore.
🧭 Go deeper
Next: federation (ADFS), Azure AD/Entra, or add the Linux Samba side β€” see the Linux guide!

Active Directory turns a thousand passwords and per-PC setups into one directory that runs the network.
Build it once, and identity, policy, and security become a single connected system.

Created by jcmatira