This guide will provide you with step-by-step instructions on how to create a child domain in Active Directory on Windows Server 2019. The child domain will be created under an existing root domain, and the process will require domain administrator credentials.
Prerequisites:
- A functioning root domain on Windows Server 2019.
- An additional server running Windows Server 2019 to be promoted as the domain controller for the child domain.
- Domain administrator credentials for the root domain.
Procedure:
- Configure the new server's hostname and IP settings:
- Open Server Manager.
- Click 'Local Server' on the left pane.
- Click on the computer name to change the hostname, and click 'OK' to apply changes.
- Click 'IPv4 address assigned by DHCP' to assign a static IP address, and configure the DNS server to point to the root domain's domain controller.
- Install the Active Directory Domain Services (AD DS) role on the new server:
- In Server Manager, click 'Manage' and then 'Add Roles and Features'.
- Click 'Next' until you reach the 'Select server roles' page.
- Check the box for 'Active Directory Domain Services', and click 'Next'.
- Click 'Next' until you reach the 'Confirm installation selections' page, and then click 'Install'.
- Wait for the installation to complete and click 'Close'.
- Promote the new server as a domain controller for the child domain:
- In Server Manager, click the notification flag in the upper right corner and select 'Promote this server to a domain controller'.
- In the Deployment Configuration page, choose 'Add a new domain to an existing forest', and select 'Child Domain'. Click 'Next'.
- Enter the fully qualified domain name (FQDN) of the root domain, and the desired FQDN for the child domain. Click 'Next'.
- Provide the domain administrator credentials for the root domain and click 'Next'.
- Choose the functional levels for the new child domain, and enter a Directory Services Restore Mode (DSRM) password. Click 'Next'.
- Review the DNS options and ensure a delegation is created for the child domain. Click 'Next'.
- Confirm the NetBIOS domain name for the child domain, and click 'Next'.
- Verify the default paths for AD DS database, log files, and SYSVOL folder. Click 'Next'.
- Review your selections, and click 'Next'.
- Allow the prerequisite check to complete, and if there are no issues, click 'Install'.
- The server will automatically reboot after the installation process is complete.
- Verify the child domain creation:
- Log in to the new child domain controller using the root domain administrator credentials.
- Open the Active Directory Users and Computers (ADUC) console by pressing 'Win + R', typing 'dsa.msc', and pressing 'Enter'.
- Confirm that the new child domain is visible under the root domain.
You have now successfully created a child domain under your root domain using Active Directory on Windows Server 2019.
After you establish the root domain, you can create additional domains within the tree if your network plan requires multiple domains. Each new domain within the tree will be a
child domain[1] of the root domain or a child domain of another child domain.
As with other phases of the installation process, you begin creating a
child domain by starting the Active Directory Installation Wizard.
When the wizard asks you which installation option you'd like to follow:
- Click Domain controller for a new domain.
- Select Create a new child domain in an existing domain tree, as shown here:
After you finish specifying the installation information, the wizard installs Active Directory, converts the computer to a domain controller, and adds the consoles described earlier to the Administrative Tools menu on that computer.
[1]
Child domains: A domain located in the namespace tree directly under another domain name (the parent domain), which contains the name of the parent in its own name. Example: sales.tacteam.net is a child domain of the tacteam.net parent domain.
For instance, a domain named
europe.contoso.com
is a child of the root domain,
contoso.com
.
The next domain that you create within that tree can be a child of
constoso.com
or a child of
europe.contoso.com
.