Active Directory Phase 1: Windows Server Foundation¶
Purpose¶
Prepare the Windows Server 2022 VM for Active Directory Domain Services (AD DS). This phase establishes a reliable VM, a final server name, a stable address on VLAN 20, and working network connectivity before the server is promoted to a domain controller.
AD DS is not installed during this phase. Keeping the foundation separate from domain promotion makes network and DNS problems easier to identify.
Starting state¶
The following state is confirmed in the lab overview:
- the Windows Server 2022 VM exists
- Windows Server is installed
- the local Administrator account is available
- AD DS and DNS have not been installed
- VLAN 20 is the infrastructure network behind OPNsense
vmbr1is the VLAN-aware internal Proxmox bridge
The server's exact VM resources, Windows installation type, final host name, and private address must be verified and recorded during implementation.
Intended result¶
At the end of this phase:
- the VM is connected only to
vmbr1with VLAN tag20 - VirtIO drivers and QEMU Guest Agent are installed
- Windows is fully updated and has no pending restart
- the server has its final pre-promotion computer name
- the server has a stable, conflict-free VLAN 20 address
- OPNsense is the default gateway
- temporary pre-promotion DNS resolution works
- the server can reach its gateway and the required update services
- Windows Defender Firewall remains enabled
Public-safe example values¶
The repository is public, so this runbook uses sanitized addresses. Replace them with values from the private IPAM when performing the build.
| Setting | Public-safe example | Implementation rule |
|---|---|---|
| Server name | DC-05 |
Proposed name; confirm before promotion |
| Proxmox bridge | vmbr1 |
Internal bridge |
| VLAN tag | 20 |
Infrastructure segment |
| Server address | 10.42.20.10 |
Use an unused address outside the dynamic pool |
| Prefix length | /24 |
Confirm against the real VLAN configuration |
| Default gateway | 10.42.20.1 |
OPNsense VLAN 20 interface |
| DNS before promotion | 10.42.20.1 |
Temporary use of OPNsense/Unbound |
| DNS after promotion | Server's own address | Changed and verified in Phase 2 |
Do not record the live address, MAC address, passwords, or configuration exports in this public repository.
1. Verify the VM configuration in Proxmox¶
Before changing Windows, record the VM's current CPU, memory, disk size, and Windows installation type in the private inventory.
If the network device needs to be changed, shut down the VM cleanly. In Proxmox:
- Select the Windows Server VM.
- Open Hardware.
- Select Network Device, then Edit.
-
Configure:
- Bridge:
vmbr1 - VLAN Tag:
20 - Model:
VirtIO (paravirtualized) - Firewall: keep the existing lab policy; do not disable security just to make initial testing pass
- Bridge:
-
Confirm that the server has no network device connected to
vmbr0. - Start the VM.
The domain controller belongs behind OPNsense on the internal infrastructure network. It must not be placed directly on the upstream/WAN bridge.
2. Install VirtIO tools and QEMU Guest Agent¶
- Sign in with the local
Administratoraccount. - In Proxmox, attach the VirtIO driver ISO if it is not already attached.
- In Windows, open File Explorer and then This PC.
- Open the VirtIO CD drive.
- Run
virtio-win-guest-tools.exeas Administrator. - Accept the required driver and guest-agent installation prompts.
- Restart Windows.
- In Proxmox, open the VM's Options and enable QEMU Guest Agent.
- Restart again if Proxmox or Windows requests it.
- Confirm that Proxmox can obtain guest information from the VM.
The ISO can be detached after all required drivers are working.
3. Update Windows Server¶
- Open Settings > Update & Security > Windows Update.
- Select Check for updates.
- Install current cumulative, security, and Defender updates.
- Restart when requested.
- Repeat the check until no required updates remain.
Do not install AD DS while Windows is waiting for a restart. A quick reboot immediately before Phase 2 is preferable to beginning promotion with pending servicing work.
4. Set the final server name¶
Confirm the name before running this step. DC-05 is a proposed public-safe
example that follows the existing role-and-sequence inventory style.
Open PowerShell as Administrator and run:
After the restart, sign in with the local Administrator account and verify:
The returned name must match the intended server name. Renaming before domain promotion is simpler than renaming a domain controller later.
5. Select a stable VLAN 20 address¶
First inspect the current DHCP-provided configuration:
The connected adapter should already receive an address from VLAN 20 and show the OPNsense VLAN 20 interface as its gateway. If it receives an address from a different network, correct the Proxmox bridge or VLAN tag before continuing.
In OPNsense:
- Review the VLAN 20 subnet and DHCP pool.
- Review active DHCP leases and the ARP table.
- Select an address outside the dynamic pool, or create an explicit DHCP reservation if that is the chosen assignment policy.
- Ensure the address is not already assigned.
- Record the assignment and owner in the private IPAM.
A failed ping does not prove an address is unused; a host may be offline or may block ICMP. The DHCP configuration, leases, ARP information, and private IPAM must be checked together.
For a domain controller, a manually configured static address outside the DHCP pool is the straightforward learning-lab choice.
6. Configure IPv4 in Windows¶
- Press Windows key + R.
- Enter
ncpa.cpland select OK. - Right-click the connected Ethernet adapter and select Properties.
- Select Internet Protocol Version 4 (TCP/IPv4), then Properties.
- Select Use the following IP address.
-
Enter the private IPAM values for:
- IP address
- subnet mask
- default gateway
-
Select Use the following DNS server addresses.
- For this pre-promotion phase, set Preferred DNS server to the OPNsense VLAN 20 gateway.
- Leave Alternate DNS server blank.
- Select OK, then Close.
Do not enter a public resolver such as Google DNS or Cloudflare DNS on the server's network adapter. After promotion, Active Directory clients and domain controllers must query the AD-aware DNS server. External lookups will be handled through DNS forwarding rather than by bypassing the AD DNS server.
During Phase 2, the first domain controller's DNS client setting will be changed and verified so that it points to itself.
7. Validate the server foundation¶
Inspect the applied configuration:
Using the appropriate private values, test the OPNsense gateway:
Test DNS resolution:
Test outbound HTTPS:
The final command should report:
Check the time service and current clock:
The clock should be accurate before domain promotion because Kerberos authentication is time-sensitive. Domain time hierarchy will be configured and tested after AD DS is installed.
8. Troubleshooting order¶
If a validation test fails, check in this order:
- Adapter state: the Windows Ethernet adapter is enabled and connected.
- Proxmox network: the adapter uses
vmbr1and VLAN tag20. - Addressing: the address, subnet mask, and gateway belong to the same VLAN 20 subnet.
- Address conflict: the chosen static address is not present in DHCP, ARP, or the private IPAM.
- Gateway reachability: the server can reach the OPNsense VLAN 20 interface.
- OPNsense policy: VLAN 20 rules permit the required DNS, update, and HTTPS traffic.
- DNS: the temporary DNS server is reachable and answers queries.
- Host firewall: keep Windows Firewall enabled and inspect its logs or rules instead of disabling it globally.
This order separates a link or VLAN problem from routing, firewall, and DNS problems.
Snapshot and backup decision¶
A snapshot is not required to complete Phase 1. On this host, storage is the primary constraint, so the default choice is to skip the pre-promotion snapshot when LVM-thin free space is limited.
The terms are important:
- a snapshot is a short-lived rollback convenience stored in the same Proxmox storage; it consumes additional space as blocks change
- a backup is a separate recoverable copy, ideally stored outside the Proxmox system disk
A snapshot does not protect against failure of the single SSD and should not be
retained as though it were a backup. If adequate LVM-thin space exists, a
single temporary pre-ad-promotion snapshot can make it faster to repeat the
promotion exercise. Delete it after the next stable milestone. Otherwise,
rebuild from this runbook until external backup storage is available.
Before any snapshot, check the LVM-thin data and metadata utilization, not only the Proxmox root-filesystem usage.
Completion checklist¶
- VM resource allocation and Windows installation type verified privately
- only the intended
vmbr1/VLAN 20 network connection is present - VirtIO drivers installed
- QEMU Guest Agent installed and enabled
- Windows Update completed
- no pending restart
- final computer name confirmed
- conflict-free stable address recorded in the private IPAM
- OPNsense VLAN 20 gateway reachable
- external DNS resolution successful
- outbound HTTPS successful
- clock and time service checked
- Windows Defender Firewall enabled
- snapshot deliberately skipped or created only after checking LVM-thin capacity
When every required item passes, proceed to Phase 2: choose the AD DNS namespace, install AD DS and DNS, and promote the server as the first domain controller in a new forest.