# Install Active Directory on Windows Server 2025: New Forest Step by Step

Source: https://srvscripts.com/guides/install-active-directory-windows-server-2025/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

This guide shows how to install Active Directory on Windows Server 2025 and create a brand-new forest and domain. It covers the first domain controller only. To add a second domain controller to a domain that already exists, follow the domain controller promotion guide linked below once this one is done.

**Short answer:** Give the server a static IP, a final computer name and current updates. Run `Install-WindowsFeature AD-Domain-Services -IncludeManagementTools`, then `Install-ADDSForest -DomainName corp.example.com -DomainNetbiosName CORP -InstallDns` and set the DSRM password. The server reboots as the first domain controller. Afterwards point its DNS to itself, add forwarders and a reverse zone, create sites and OUs, and check health with `dcdiag`.

In short: Give the server a static IP, a final computer name and current updates.

## Plan before you install

| Decision | Recommendation |
| --- | --- |
| Domain name | A subdomain of a domain you own, such as corp.example.com or ad.example.com. Avoid .local and names you do not control. |
| NetBIOS name | Short, 15 characters or fewer, for example CORP. |
| Functional level | Windows Server 2025 only if every DC will run 2025; otherwise Windows Server 2016, which you can raise later. |
| Number of DCs | At least two per domain, on separate hosts, so one can fail or be patched. |
| Server | Windows Server 2025 Standard or Datacenter, 2 vCPU, 4 GB RAM or more, 60 GB system disk, Desktop Experience or Server Core. |

## Step 1: prepare the server

```
# rename and set a static IP (adjust interface alias, addresses and name)
Rename-Computer -NewName DC01 -Restart
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 10.0.10.11 -PrefixLength 24 -DefaultGateway 10.0.10.1
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 127.0.0.1
Set-TimeZone -Id "GMT Standard Time"
```

Install all current Windows updates and reboot. If the server is a VM, disable host time synchronisation for the guest so the domain uses NTP instead, and never use VM snapshots as the backup method for domain controllers.

## Step 2: add the AD DS role

```
Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
```

In Server Manager this is Manage » Add Roles and Features » Active Directory Domain Services. Installing the role does not make the server a domain controller yet.

## Step 3: promote to a new forest

With PowerShell:

```
Install-ADDSForest `
  -DomainName "corp.example.com" `
  -DomainNetbiosName "CORP" `
  -ForestMode "WinThreshold" `
  -DomainMode "WinThreshold" `
  -InstallDns `
  -SafeModeAdministratorPassword (Read-Host -AsSecureString "DSRM password")
```

`WinThreshold` is the Windows Server 2016 functional level; use `Win2025` when every DC will be Windows Server 2025. In Server Manager, click the flag notification, choose Promote this server to a domain controller » Add a new forest, enter the root domain name, pick the functional levels, keep DNS server and Global Catalog ticked, set the DSRM password, accept the NetBIOS name and default paths, and run the prerequisite check. The DNS delegation warning is expected for a new forest. The server reboots when promotion finishes.

Store the DSRM password in your password manager. It is the local recovery password for this DC, separate from the domain administrator account.

## Step 4: DNS after promotion

- Keep the DC’s preferred DNS on its own IP (or 127.0.0.1) and, once a second DC exists, set the other DC as alternate.

- In DNS Manager, add forwarders to your resolvers or ISP under the server’s properties.

- Create a reverse lookup zone for each subnet so PTR records resolve.

- Point clients and DHCP scopes at the domain controllers for DNS, never at a public resolver.

## Step 5: sites, OUs and first changes

- Active Directory Sites and Services: rename `Default-First-Site-Name` to your location and add each subnet.

- Create an OU structure for users, computers, servers and groups so you can link Group Policy to them instead of the default containers.

- Create named admin accounts and stop using the built-in Administrator for daily work.

- Enable the AD Recycle Bin and configure the PDC emulator as the authoritative time source.

- Set up Windows LAPS for local administrator passwords on member computers.

## Step 6: verify

```
Get-ADDomain | Select-Object DNSRoot, NetBIOSName, DomainMode
Get-ADForest | Select-Object ForestMode, SchemaMaster, DomainNamingMaster
dcdiag /v /c /e /q
nslookup -type=srv _ldap._tcp.dc._msdcs.corp.example.com
```

`dcdiag` with `/q` prints only errors, so an empty result is good. The SRV lookup should return the new DC. Join one test computer to the domain, log in with a domain account and confirm Group Policy applies with `gpresult /r`. Then add a second domain controller.

## Install Active Directory at a glance

**Official documentation:** [Install Active Directory Domain Services](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/install-active-directory-domain-services--level-100-), [Install-ADDSForest cmdlet](https://learn.microsoft.com/en-us/powershell/module/addsdeployment/install-addsforest).

**Related guides:** [Add a Windows Server 2025 domain controller](/guides/windows-server-2025-domain-controller/) · [Enable the AD Recycle Bin](/guides/enable-active-directory-recycle-bin/) · [PDC emulator NTP time sync](/guides/pdc-emulator-ntp-time-sync/).

## Frequently asked questions

### Can I use a .local domain name?

It works technically, but it clashes with multicast DNS (mDNS) on Apple and Linux devices and cannot get public certificates. Use a subdomain of a domain you own, such as ad.example.com.

### What is the DSRM password used for?

Directory Services Restore Mode is used to boot a domain controller for offline repair or authoritative restore. The DSRM password is local to each DC and is set during promotion.

### Should I use Server Core for a domain controller?

Server Core has a smaller attack surface and fewer updates, and all AD tasks can be done remotely with RSAT or PowerShell. Desktop Experience is easier if your team is not used to remote management.
