Skip to content

Active Directory

Outcome

Built and validated a small Active Directory environment with one Windows Server 2022 domain controller and one Windows 11 Enterprise client. The lab demonstrates the core administration workflow without adding unnecessary servers or permanent identities.

Microsoft Entra ID synchronization and hybrid identity remain a separate, future extension.

Environment

Component Role Validation evidence
DC-05 AD DS, AD-integrated DNS, Global Catalog Domain health, DNS, SYSVOL, NETLOGON, and time checks passed
CL-01 Managed Windows 11 workstation Domain join, standard-user authentication, Group Policy, and AppLocker validated
OPNsense VLAN 20 gateway and DNS forwarder Internal clients reached the internet and resolved external names through the DC forwarding path

The forest-root domain is ad.arphaxad.dev, with NetBIOS name ARPHAXAD. The namespace is internal: no public DNS delegation or AD records were added to the public arphaxad.dev website zone.

Live addresses, credentials, MAC addresses, and private inventory details are not stored in this public repository.

DC-05 and CL-01 are temporary workloads and are planned for deletion to reclaim storage. The phase pages below retain the design, implementation, validation, troubleshooting, and recovery details needed to recreate them.

Build phases

Phase Result
1. Windows Server foundation Prepared DC-05, VLAN 20 networking, stable addressing, updates, and VirtIO integration
2. AD DS and first domain controller Created the forest, AD-integrated DNS, Global Catalog, and forwarding path
3. Directory structure and identities Built OUs, separated account roles, created groups, delegated workstation joins, and practised identity lifecycle operations
4. Windows client domain join Prepared and joined CL-01, then validated standard domain authentication
5. Group Policy and application control Deployed and audited AppLocker, then enforced a group-targeted application restriction

Skills demonstrated

  • Install and promote the first domain controller in a new forest.
  • Explain how AD DS depends on DNS, time synchronization, LDAP, Kerberos, and computer secure channels.
  • Create and manage OUs, users, global security groups, and computer objects.
  • Separate everyday, privileged, and delegated enrollment responsibilities.
  • Delegate workstation-join permissions without granting Domain Admin.
  • Prestage and join a Windows client into the intended OU.
  • Authenticate a standard domain user and retain a local recovery account.
  • Create, link, audit, enforce, and troubleshoot a computer-side GPO.
  • Use AppLocker with OU scope and security-group targeting.
  • Read Event Viewer evidence to distinguish an audited action from an enforced denial.
  • Record implementation decisions, failures, validation, and rollback paths.

Important operational lessons

DNS is part of Active Directory

The client queries DC-05 for AD service records. DC-05 answers for the internal domain and forwards external queries to OPNsense. Pointing the client at a public resolver would break reliable domain-controller discovery.

Permissions belong to roles

Permissions were assigned to groups such as GG-Workstation-Joiners, not directly to individual users. Membership changes who holds the role without redesigning the OU access-control list.

Audit before enforcement

The AppLocker rule was first deployed in audit mode and validated with Event ID 8003. Enforcement was enabled only after the expected match was proven; the blocked application then provided visible validation and enforcement evidence.

Recovery access remains necessary

The local workstation administrator and built-in domain recovery paths were retained. Restrictive policy changes should always have a tested way to reverse them.

Deliberately deferred

  • a second domain controller and replication exercises
  • a dedicated client VLAN and inter-VLAN AD firewall policy
  • certificate services
  • Microsoft Entra Connect or Cloud Sync
  • hybrid join, Conditional Access, and cloud identity licensing exercises
  • enterprise monitoring, backup, and disaster-recovery infrastructure

These are useful extensions, but they are not required to understand the core AD DS management workflow demonstrated by this two-VM lab.

Official references