Active Directory¶
Outcome¶
Built and validated a small Active Directory environment with one Windows Server 2022 domain controller and one Windows 11 Enterprise client. The lab demonstrates the core administration workflow without adding unnecessary servers or permanent identities.
Microsoft Entra ID synchronization and hybrid identity remain a separate, future extension.
Environment¶
| Component | Role | Validation evidence |
|---|---|---|
DC-05 |
AD DS, AD-integrated DNS, Global Catalog | Domain health, DNS, SYSVOL, NETLOGON, and time checks passed |
CL-01 |
Managed Windows 11 workstation | Domain join, standard-user authentication, Group Policy, and AppLocker validated |
| OPNsense | VLAN 20 gateway and DNS forwarder | Internal clients reached the internet and resolved external names through the DC forwarding path |
The forest-root domain is ad.arphaxad.dev, with NetBIOS name ARPHAXAD.
The namespace is internal: no public DNS delegation or AD records were added to
the public arphaxad.dev website zone.
Live addresses, credentials, MAC addresses, and private inventory details are not stored in this public repository.
DC-05 and CL-01 are temporary workloads and are planned for deletion to
reclaim storage. The phase pages below retain the design, implementation,
validation, troubleshooting, and recovery details needed to recreate them.
Build phases¶
| Phase | Result |
|---|---|
| 1. Windows Server foundation | Prepared DC-05, VLAN 20 networking, stable addressing, updates, and VirtIO integration |
| 2. AD DS and first domain controller | Created the forest, AD-integrated DNS, Global Catalog, and forwarding path |
| 3. Directory structure and identities | Built OUs, separated account roles, created groups, delegated workstation joins, and practised identity lifecycle operations |
| 4. Windows client domain join | Prepared and joined CL-01, then validated standard domain authentication |
| 5. Group Policy and application control | Deployed and audited AppLocker, then enforced a group-targeted application restriction |
Skills demonstrated¶
- Install and promote the first domain controller in a new forest.
- Explain how AD DS depends on DNS, time synchronization, LDAP, Kerberos, and computer secure channels.
- Create and manage OUs, users, global security groups, and computer objects.
- Separate everyday, privileged, and delegated enrollment responsibilities.
- Delegate workstation-join permissions without granting Domain Admin.
- Prestage and join a Windows client into the intended OU.
- Authenticate a standard domain user and retain a local recovery account.
- Create, link, audit, enforce, and troubleshoot a computer-side GPO.
- Use AppLocker with OU scope and security-group targeting.
- Read Event Viewer evidence to distinguish an audited action from an enforced denial.
- Record implementation decisions, failures, validation, and rollback paths.
Important operational lessons¶
DNS is part of Active Directory¶
The client queries DC-05 for AD service records. DC-05 answers for the
internal domain and forwards external queries to OPNsense. Pointing the client
at a public resolver would break reliable domain-controller discovery.
Permissions belong to roles¶
Permissions were assigned to groups such as GG-Workstation-Joiners, not
directly to individual users. Membership changes who holds the role without
redesigning the OU access-control list.
Audit before enforcement¶
The AppLocker rule was first deployed in audit mode and validated with Event ID
8003. Enforcement was enabled only after the expected match was proven; the
blocked application then provided visible validation and enforcement evidence.
Recovery access remains necessary¶
The local workstation administrator and built-in domain recovery paths were retained. Restrictive policy changes should always have a tested way to reverse them.
Deliberately deferred¶
- a second domain controller and replication exercises
- a dedicated client VLAN and inter-VLAN AD firewall policy
- certificate services
- Microsoft Entra Connect or Cloud Sync
- hybrid join, Conditional Access, and cloud identity licensing exercises
- enterprise monitoring, backup, and disaster-recovery infrastructure
These are useful extensions, but they are not required to understand the core AD DS management workflow demonstrated by this two-VM lab.