Skip to content

Active Directory Phase 1: Windows Server Foundation

Purpose

Prepare the Windows Server 2022 VM for Active Directory Domain Services (AD DS). This phase establishes a reliable VM, a final server name, a stable address on VLAN 20, and working network connectivity before the server is promoted to a domain controller.

AD DS is not installed during this phase. Keeping the foundation separate from domain promotion makes network and DNS problems easier to identify.

Starting state

The following state is confirmed in the lab overview:

  • the Windows Server 2022 VM exists
  • Windows Server is installed
  • the local Administrator account is available
  • AD DS and DNS have not been installed
  • VLAN 20 is the infrastructure network behind OPNsense
  • vmbr1 is the VLAN-aware internal Proxmox bridge

The server's exact VM resources, Windows installation type, final host name, and private address must be verified and recorded during implementation.

Intended result

At the end of this phase:

  • the VM is connected only to vmbr1 with VLAN tag 20
  • VirtIO drivers and QEMU Guest Agent are installed
  • Windows is fully updated and has no pending restart
  • the server has its final pre-promotion computer name
  • the server has a stable, conflict-free VLAN 20 address
  • OPNsense is the default gateway
  • temporary pre-promotion DNS resolution works
  • the server can reach its gateway and the required update services
  • Windows Defender Firewall remains enabled

Public-safe example values

The repository is public, so this runbook uses sanitized addresses. Replace them with values from the private IPAM when performing the build.

Setting Public-safe example Implementation rule
Server name DC-05 Proposed name; confirm before promotion
Proxmox bridge vmbr1 Internal bridge
VLAN tag 20 Infrastructure segment
Server address 10.42.20.10 Use an unused address outside the dynamic pool
Prefix length /24 Confirm against the real VLAN configuration
Default gateway 10.42.20.1 OPNsense VLAN 20 interface
DNS before promotion 10.42.20.1 Temporary use of OPNsense/Unbound
DNS after promotion Server's own address Changed and verified in Phase 2

Do not record the live address, MAC address, passwords, or configuration exports in this public repository.

1. Verify the VM configuration in Proxmox

Before changing Windows, record the VM's current CPU, memory, disk size, and Windows installation type in the private inventory.

If the network device needs to be changed, shut down the VM cleanly. In Proxmox:

  1. Select the Windows Server VM.
  2. Open Hardware.
  3. Select Network Device, then Edit.
  4. Configure:

    • Bridge: vmbr1
    • VLAN Tag: 20
    • Model: VirtIO (paravirtualized)
    • Firewall: keep the existing lab policy; do not disable security just to make initial testing pass
  5. Confirm that the server has no network device connected to vmbr0.

  6. Start the VM.

The domain controller belongs behind OPNsense on the internal infrastructure network. It must not be placed directly on the upstream/WAN bridge.

2. Install VirtIO tools and QEMU Guest Agent

  1. Sign in with the local Administrator account.
  2. In Proxmox, attach the VirtIO driver ISO if it is not already attached.
  3. In Windows, open File Explorer and then This PC.
  4. Open the VirtIO CD drive.
  5. Run virtio-win-guest-tools.exe as Administrator.
  6. Accept the required driver and guest-agent installation prompts.
  7. Restart Windows.
  8. In Proxmox, open the VM's Options and enable QEMU Guest Agent.
  9. Restart again if Proxmox or Windows requests it.
  10. Confirm that Proxmox can obtain guest information from the VM.

The ISO can be detached after all required drivers are working.

3. Update Windows Server

  1. Open Settings > Update & Security > Windows Update.
  2. Select Check for updates.
  3. Install current cumulative, security, and Defender updates.
  4. Restart when requested.
  5. Repeat the check until no required updates remain.

Do not install AD DS while Windows is waiting for a restart. A quick reboot immediately before Phase 2 is preferable to beginning promotion with pending servicing work.

4. Set the final server name

Confirm the name before running this step. DC-05 is a proposed public-safe example that follows the existing role-and-sequence inventory style.

Open PowerShell as Administrator and run:

Rename-Computer -NewName "DC-05" -Restart

After the restart, sign in with the local Administrator account and verify:

hostname

The returned name must match the intended server name. Renaming before domain promotion is simpler than renaming a domain controller later.

5. Select a stable VLAN 20 address

First inspect the current DHCP-provided configuration:

Get-NetIPConfiguration

The connected adapter should already receive an address from VLAN 20 and show the OPNsense VLAN 20 interface as its gateway. If it receives an address from a different network, correct the Proxmox bridge or VLAN tag before continuing.

In OPNsense:

  1. Review the VLAN 20 subnet and DHCP pool.
  2. Review active DHCP leases and the ARP table.
  3. Select an address outside the dynamic pool, or create an explicit DHCP reservation if that is the chosen assignment policy.
  4. Ensure the address is not already assigned.
  5. Record the assignment and owner in the private IPAM.

A failed ping does not prove an address is unused; a host may be offline or may block ICMP. The DHCP configuration, leases, ARP information, and private IPAM must be checked together.

For a domain controller, a manually configured static address outside the DHCP pool is the straightforward learning-lab choice.

6. Configure IPv4 in Windows

  1. Press Windows key + R.
  2. Enter ncpa.cpl and select OK.
  3. Right-click the connected Ethernet adapter and select Properties.
  4. Select Internet Protocol Version 4 (TCP/IPv4), then Properties.
  5. Select Use the following IP address.
  6. Enter the private IPAM values for:

    • IP address
    • subnet mask
    • default gateway
  7. Select Use the following DNS server addresses.

  8. For this pre-promotion phase, set Preferred DNS server to the OPNsense VLAN 20 gateway.
  9. Leave Alternate DNS server blank.
  10. Select OK, then Close.

Do not enter a public resolver such as Google DNS or Cloudflare DNS on the server's network adapter. After promotion, Active Directory clients and domain controllers must query the AD-aware DNS server. External lookups will be handled through DNS forwarding rather than by bypassing the AD DNS server.

During Phase 2, the first domain controller's DNS client setting will be changed and verified so that it points to itself.

7. Validate the server foundation

Inspect the applied configuration:

Get-NetIPConfiguration
ipconfig /all

Using the appropriate private values, test the OPNsense gateway:

Test-Connection 10.42.20.1 -Count 4

Test DNS resolution:

Resolve-DnsName microsoft.com

Test outbound HTTPS:

Test-NetConnection microsoft.com -Port 443

The final command should report:

TcpTestSucceeded : True

Check the time service and current clock:

w32tm /query /status
Get-Date

The clock should be accurate before domain promotion because Kerberos authentication is time-sensitive. Domain time hierarchy will be configured and tested after AD DS is installed.

8. Troubleshooting order

If a validation test fails, check in this order:

  1. Adapter state: the Windows Ethernet adapter is enabled and connected.
  2. Proxmox network: the adapter uses vmbr1 and VLAN tag 20.
  3. Addressing: the address, subnet mask, and gateway belong to the same VLAN 20 subnet.
  4. Address conflict: the chosen static address is not present in DHCP, ARP, or the private IPAM.
  5. Gateway reachability: the server can reach the OPNsense VLAN 20 interface.
  6. OPNsense policy: VLAN 20 rules permit the required DNS, update, and HTTPS traffic.
  7. DNS: the temporary DNS server is reachable and answers queries.
  8. Host firewall: keep Windows Firewall enabled and inspect its logs or rules instead of disabling it globally.

This order separates a link or VLAN problem from routing, firewall, and DNS problems.

Snapshot and backup decision

A snapshot is not required to complete Phase 1. On this host, storage is the primary constraint, so the default choice is to skip the pre-promotion snapshot when LVM-thin free space is limited.

The terms are important:

  • a snapshot is a short-lived rollback convenience stored in the same Proxmox storage; it consumes additional space as blocks change
  • a backup is a separate recoverable copy, ideally stored outside the Proxmox system disk

A snapshot does not protect against failure of the single SSD and should not be retained as though it were a backup. If adequate LVM-thin space exists, a single temporary pre-ad-promotion snapshot can make it faster to repeat the promotion exercise. Delete it after the next stable milestone. Otherwise, rebuild from this runbook until external backup storage is available.

Before any snapshot, check the LVM-thin data and metadata utilization, not only the Proxmox root-filesystem usage.

Completion checklist

  • VM resource allocation and Windows installation type verified privately
  • only the intended vmbr1/VLAN 20 network connection is present
  • VirtIO drivers installed
  • QEMU Guest Agent installed and enabled
  • Windows Update completed
  • no pending restart
  • final computer name confirmed
  • conflict-free stable address recorded in the private IPAM
  • OPNsense VLAN 20 gateway reachable
  • external DNS resolution successful
  • outbound HTTPS successful
  • clock and time service checked
  • Windows Defender Firewall enabled
  • snapshot deliberately skipped or created only after checking LVM-thin capacity

When every required item passes, proceed to Phase 2: choose the AD DNS namespace, install AD DS and DNS, and promote the server as the first domain controller in a new forest.

Official references