Emergency server help: get in touch

Install Active Directory on Windows Server 2025: New Forest Step by Step

Build a new Active Directory forest on Windows Server 2025: prepare the server, add the AD DS role, promote with PowerShell or Server Manager, then configure DNS, sites, OUs and health checks.

Published Updated 4 min read

This guide shows how to install Active Directory on Windows Server 2025 and create a brand-new forest and domain. It covers the first domain controller only. To add a second domain controller to a domain that already exists, follow the domain controller promotion guide linked below once this one is done.

Short answer: Give the server a static IP, a final computer name and current updates. Run Install-WindowsFeature AD-Domain-Services -IncludeManagementTools, then Install-ADDSForest -DomainName corp.example.com -DomainNetbiosName CORP -InstallDns and set the DSRM password. The server reboots as the first domain controller. Afterwards point its DNS to itself, add forwarders and a reverse zone, create sites and OUs, and check health with dcdiag.

Plan before you install

DecisionRecommendation
Domain nameA subdomain of a domain you own, such as corp.example.com or ad.example.com. Avoid .local and names you do not control.
NetBIOS nameShort, 15 characters or fewer, for example CORP.
Functional levelWindows Server 2025 only if every DC will run 2025; otherwise Windows Server 2016, which you can raise later.
Number of DCsAt least two per domain, on separate hosts, so one can fail or be patched.
ServerWindows Server 2025 Standard or Datacenter, 2 vCPU, 4 GB RAM or more, 60 GB system disk, Desktop Experience or Server Core.

Step 1: prepare the server

# rename and set a static IP (adjust interface alias, addresses and name)
Rename-Computer -NewName DC01 -Restart
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 10.0.10.11 -PrefixLength 24 -DefaultGateway 10.0.10.1
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 127.0.0.1
Set-TimeZone -Id "GMT Standard Time"

Install all current Windows updates and reboot. If the server is a VM, disable host time synchronisation for the guest so the domain uses NTP instead, and never use VM snapshots as the backup method for domain controllers.

Step 2: add the AD DS role

Install-WindowsFeature AD-Domain-Services -IncludeManagementTools

In Server Manager this is Manage » Add Roles and Features » Active Directory Domain Services. Installing the role does not make the server a domain controller yet.

Step 3: promote to a new forest

With PowerShell:

Install-ADDSForest `
  -DomainName "corp.example.com" `
  -DomainNetbiosName "CORP" `
  -ForestMode "WinThreshold" `
  -DomainMode "WinThreshold" `
  -InstallDns `
  -SafeModeAdministratorPassword (Read-Host -AsSecureString "DSRM password")

WinThreshold is the Windows Server 2016 functional level; use Win2025 when every DC will be Windows Server 2025. In Server Manager, click the flag notification, choose Promote this server to a domain controller » Add a new forest, enter the root domain name, pick the functional levels, keep DNS server and Global Catalog ticked, set the DSRM password, accept the NetBIOS name and default paths, and run the prerequisite check. The DNS delegation warning is expected for a new forest. The server reboots when promotion finishes.

Store the DSRM password in your password manager. It is the local recovery password for this DC, separate from the domain administrator account.

Step 4: DNS after promotion

  • Keep the DC’s preferred DNS on its own IP (or 127.0.0.1) and, once a second DC exists, set the other DC as alternate.
  • In DNS Manager, add forwarders to your resolvers or ISP under the server’s properties.
  • Create a reverse lookup zone for each subnet so PTR records resolve.
  • Point clients and DHCP scopes at the domain controllers for DNS, never at a public resolver.

Step 5: sites, OUs and first changes

  1. Active Directory Sites and Services: rename Default-First-Site-Name to your location and add each subnet.
  2. Create an OU structure for users, computers, servers and groups so you can link Group Policy to them instead of the default containers.
  3. Create named admin accounts and stop using the built-in Administrator for daily work.
  4. Enable the AD Recycle Bin and configure the PDC emulator as the authoritative time source.
  5. Set up Windows LAPS for local administrator passwords on member computers.

Step 6: verify

Get-ADDomain | Select-Object DNSRoot, NetBIOSName, DomainMode
Get-ADForest | Select-Object ForestMode, SchemaMaster, DomainNamingMaster
dcdiag /v /c /e /q
nslookup -type=srv _ldap._tcp.dc._msdcs.corp.example.com

dcdiag with /q prints only errors, so an empty result is good. The SRV lookup should return the new DC. Join one test computer to the domain, log in with a domain account and confirm Group Policy applies with gpresult /r. Then add a second domain controller.

Install Active Directory at a glance

Install Active Directory on Windows Server 2025 summary card: Give the server a static IP, a final computer name and current updates.
In short: Give the server a static IP, a final computer name and current updates.

Official documentation: Install Active Directory Domain Services, Install-ADDSForest cmdlet.

Related guides: Add a Windows Server 2025 domain controller · Enable the AD Recycle Bin · PDC emulator NTP time sync.

Frequently asked questions

Can I use a .local domain name?

It works technically, but it clashes with multicast DNS (mDNS) on Apple and Linux devices and cannot get public certificates. Use a subdomain of a domain you own, such as ad.example.com.

What is the DSRM password used for?

Directory Services Restore Mode is used to boot a domain controller for offline repair or authoritative restore. The DSRM password is local to each DC and is set during promotion.

Should I use Server Core for a domain controller?

Server Core has a smaller attack surface and fewer updates, and all AD tasks can be done remotely with RSAT or PowerShell. Desktop Experience is easier if your team is not used to remote management.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.