What Active Directory Does and When You Need It

Active Directory is Windows Server's built-in system for managing user accounts, computers, and permissions across a network. It centralizes login credentials, device policies, and access rules so you do not have to configure each machine separately. If you run more than a handful of Windows computers in an office or data center, Active Directory lets you control who can log in where, what software they can use, and what files they can reach — all from one place.

You install Active Directory on a Windows Server machine that becomes your domain controller. That server then handles authentication for every other Windows computer that joins the domain. Small networks with five or fewer machines rarely need it; larger ones almost always do. If you are running a web hosting environment, internal IT infrastructure, or a multi-user office, Active Directory is the standard way to manage it.

Key Takeaways

  • Active Directory runs on Windows Server 2016 or later and requires a machine dedicated to the role — do not install it on a general-purpose server.
  • You add the Active Directory Domain Services role through Server Manager, then promote the server to a domain controller using the configuration wizard.
  • The installation itself takes 10 to 20 minutes, but planning your domain name and forest structure beforehand prevents costly mistakes later.
  • After installation, every Windows computer that joins the domain will authenticate against this server, so it must be reliable and backed up regularly.
  • A second domain controller in a different location protects against total network failure if the first one goes down.

System Requirements and Planning Before You Start

Active Directory runs on Windows Server 2016, 2019, 2022, or later. Your server needs at least 2 GB of RAM (4 GB or more is safer for production), 32 GB of disk space for the system drive, and a static IP address that does not change. The machine should have a reliable network connection and be physically or logically isolated from general-purpose workloads — do not install Active Directory on a file server or web server that handles other traffic.

Before you begin, decide on a domain name. This is the name your network will use — something like company.local or office.internal. Use a name you own or a reserved internal suffix like .local or .internal; do not use a public domain name you do not control, because it can cause DNS conflicts later. Write down this name and keep it consistent across your planning documents.

You also need to decide whether this will be your first domain controller or an additional one. If it is your first, you are creating a new forest and domain. If you are adding a second controller to an existing domain, the process differs slightly. This guide covers installing the first domain controller; adding additional ones follows the same initial steps but with different promotion options.

Installing the Active Directory Domain Services Role

Log into your Windows Server machine as a local administrator. Open Server Manager — it usually appears on the Start menu or taskbar. In the top-right corner, click Manage, then select Add Roles and Features.

The wizard opens. Click Next until you reach the Server Roles page. Check the box for Active Directory Domain Services. A popup will ask whether you want to add required features; click Add Features to include them. Continue clicking Next through the remaining pages — the defaults are fine for a standard installation — then click Install. The role installation takes a few minutes.

When the installation finishes, you will see a notification flag in Server Manager with a message about promoting the server to a domain controller. Do not close Server Manager yet; you need it for the next step.

Promoting the Server to a Domain Controller

In Server Manager, click the notification flag in the top-right corner and select Promote this server to a domain controller. The Active Directory Domain Services Configuration Wizard opens.

On the first page, select Add a new forest (if this is your first domain controller). Enter your domain name in the Root domain name field — for example, company.local. Click Next.

On the Domain Controller Options page, set the Forest Functional Level and Domain Functional Level to match your oldest Windows Server version in use. If you are running Server 2019 or later exclusively, select that version. The wizard will suggest a default; accept it unless you have older servers that must join the domain. Leave DNS server checked. Click Next.

The wizard asks for a Directory Services Restore Mode password. This is a recovery password you use if the domain controller fails and you need to boot into repair mode. Make it long and strong, write it down, and store it securely — you will rarely need it, but you cannot recover without it. Click Next.

Review the summary page and click Next. The wizard checks prerequisites and then begins the promotion. This takes 5 to 15 minutes. When it finishes, the server restarts automatically. Log back in with your domain administrator account — it will now show your domain name instead of the local machine name.

Verifying the Installation and Initial Configuration

After the restart, open Active Directory Users and Computers from the Start menu or by typing dsa.msc in the Run dialog. You should see your domain name in the tree on the left. Expand it to see the default organizational units and built-in user accounts. If you see these, the installation succeeded.

Next, verify DNS is working correctly. Open a command prompt and type nslookup company.local (replace with your domain name). The server should resolve to your domain controller's IP address. If it does not, DNS configuration failed and computers will not be able to find the domain controller. Check that the domain controller is set as its own DNS server in its network settings.

Create a test user account to verify authentication works. In Active Directory Users and Computers, right-click your domain, select New, then User. Fill in a name and password, then click Finish. On another Windows machine, try logging in with this test account using the format company\username. If the login succeeds, your domain controller is working.

Joining Computers to the Domain

On each Windows computer you want to manage through Active Directory, open Settings, go to System, then About. Click Rename this PC (advanced). In the System Properties dialog, click Change, then select Domain and enter your domain name. Windows will prompt for domain administrator credentials. Enter them and click OK. The computer restarts and joins the domain.

After restart, users on that computer can log in with their domain account instead of a local account. The domain controller now controls what they can do, what software is available, and what files they can reach. You manage all these settings from Active Directory Users and Computers or Group Policy Editor on the domain controller.

Backing Up and Protecting Your Domain Controller

Your domain controller is now the most critical machine on your network. If it fails, no one can log in to domain-joined computers until it is restored. Set up automated backups immediately using Windows Server Backup or a third-party backup tool. Back up the entire system drive, not just user data. Test a restore at least once to confirm backups work.

Consider adding a second domain controller in a different location or on different hardware. A second controller provides redundancy — if the first one fails, the second continues handling authentication. Setting up a second controller uses the same promotion process but selects Add a domain controller to an existing domain instead of creating a new forest. Most production networks have at least two.

Keep the domain controller patched and updated. Set Windows Update to install security patches automatically. Monitor disk space — Active Directory's database grows as you add users and computers, and a full disk can cause serious problems. Plan to review and archive old user accounts periodically.

Frequently Asked Questions

Can I install Active Directory on Windows Server Essentials?

Yes, Windows Server Essentials includes Active Directory and is designed for small networks. The installation process is similar but simplified — the wizard guides you through domain setup more directly. Essentials limits you to 25 users and 50 devices, so it works for small offices but not larger deployments.

What happens if I use a public domain name for my domain?

If you use a domain name you do not own — like example.com — DNS conflicts can occur. External mail servers, web services, and other systems may try to reach the real example.com instead of your internal domain controller. Use .local, .internal, or a domain you actually own and control to avoid these problems.

How do I reset the Directory Services Restore Mode password?

You cannot change this password through normal Active Directory tools. If you lose it, you must boot the server into Directory Services Restore Mode (press F8 during startup on older servers, or use recovery options on newer ones) and use the ntdsutil command-line tool to reset it. Store the password securely from the start to avoid this situation.

Can I move Active Directory to a different server later?

Moving the entire Active Directory database is complex and risky. Instead, add a second domain controller on the new server, let it replicate the database, then remove the old one. This is safer and keeps your network running during the transition. Plan this migration carefully with documentation of your current setup.

What should I do if a computer cannot find the domain controller?

Check that the computer's DNS settings point to the domain controller's IP address. Verify the domain controller is running and has network connectivity. On the computer, open a command prompt and type nslookup company.local — if it does not resolve, DNS is not configured correctly. Update the computer's network settings to use the domain controller as its DNS server and restart.