Академический Документы
Профессиональный Документы
Культура Документы
Chapter 4
Using the Active Directory Installation Wizard, you can quickly and easily create new domains by promoting a Windows Server 2008 stand-alone server or a member server to a domain controller. When you install a new domain controller, you can choose to make it part of an existing domain, or you can choose to make it the first domain controller in a new domain. In the following sections and exercises, youll become familiar with the exact steps you need to take to create a domain tree and a domain forest when you promote a server to a domain controller.
157
2.
The Choose A Deployment Configuration screen appears. Click Existing Forest and then click Create A New Domain In An Existing Forest. Click Next.
3.
A warning box may appear stating that the local administrator account becomes the domain administrator account for the new domain. If it appears, Click Yes to continue.
4.
On the Network Credentials page, specify the full name of the domain that you installed in the previous chapter. Then click the Set button. In the new Windows Security dialog box that appears, enter the username and password for the domain administrator of the domain you wish to join.
158
Chapter 4
5.
Click the OK button on the Alternate Credentials screen. The domain administrator account that you used in the previous chapter should now be listed. A warning may appear stating that the current user credentials cannot be selected because they are local to this computer. The warning appears because our local account is the same as our domain administrators account. This warning will not affect the exercise. Click Next.
6.
If the information you entered was correct, you will see the Name The New Domain page. Here, you will be able to confirm the name of the parent domain and then enter the domain name for the child domain. Enter the new child domain name (in the following example, we used NH for the state of New Hampshire). Click Next to continue.
159
7.
If the Select A Site screen appears, choose any site and click Next. (You may not have any sites created on your other domain. This server will then be added to the DefaultFirstSite.)
8.
On the Additional Domain Controller Options page, uncheck any options and click Next.
9.
A warning box appears stating that you have chosen not to install DNS; just click Yes.
160
Chapter 4
10. On the Location for Database, Log Files, and SYSVOL page, youll need to specify the
database and log locations. These settings specify where the Active Directory database resides on the local machine. As mentioned previously, it is good practice to place the log files on a separate physical hard disk because this increases performance. Enter the path for a local directory (you can also leave the defaults for these exercises), and click Next.
11. In order to be able to recover this server in the event of a loss of Active Directory information, you will need to provide a password on the Directory Services Restore Mode Administrator Password page. This password will allow you to use the built-in recovery features of Windows Server 2008 in the event that the Active Directory database is lost or corrupted. Enter P@ssw0rd, confirm it, and then click Next.
161
12. On the Summary page, you will be given a brief listing of all the choices you made in the
previous steps. Its a good idea to copy this information and paste it into a text document for future reference. Click Next to continue.
13. On the Completing the Active Directory Domain Services Installation Wizard, click Finish.
162
Chapter 4
The command-line tool adprep.exe is used to prepare a Microsoft Windows 2003 forest or a Windows 2003 domain for the installation of Windows Server 2008 domain controllers. Before you promote a Windows Server 2008 domain controller into a Windows 2003 forest, an administrator should successfully run adprep /forestprep on the schema operations master and run adprep /domainprep on the infrastructure master in the Windows 2003 forest. The forestprep and domainprep processes prepare the Windows 2000 or 2003 network to accept the installation of the Windows Server 2008 servers.
In Exercise 4.2, you will use the Active Directory Installation Wizard to create a new domain tree to add to a forest. In order to add a new domain to an existing forest, you must already have at least one other domain, which is the root domain. Keep in mind that the entire forest structure is destroyed if the original root domain is ever entirely removed. Therefore, you should have at least two domain controllers in the Active Directory root domain; the second serves as a backup in case you have a problem with the first, and it can also serve as a backup solution for disaster recovery and fault tolerance purposes. Such a setup provides additional protection for the entire forest in case one of the domain controllers fails. In order to complete this exercise, you must have already installed another domain controller that serves as the root domain for a forest, and you must use a server in the domain that is not a domain controller.