# Install and promote a Windows Server 2025 domain controller step by step

Source: https://srvscripts.com/guides/windows-server-2025-domain-controller/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

Windows Server 2025 (build 10.0.26100) is the current long-term servicing release, with mainstream support to November 2029, and it is the natural target for replacing 2016 and 2019 domain controllers. Promotion has not changed much on the surface, but there are two hard requirements that catch people out: SYSVOL must already be on DFS Replication rather than FRS, and the forest schema must be extended before the new DC will join. The steps below cover both a new forest and an additional DC in an existing domain.

In short: Give the server a static IP pointing at an existing DC for DNS, install the role with Install-WindowsFeature AD-Domain-Services -IncludeManagementTools, run adprep /forestprep and /domainprep from the 2025 media if the forest has never had…

**Short answer:** Give the server a static IP pointing at an existing DC for DNS, install the role with `Install-WindowsFeature AD-Domain-Services -IncludeManagementTools`, run `adprep /forestprep` and `/domainprep` from the 2025 media if the forest has never had a 2025 DC, then promote with `Install-ADDSDomainController -DomainName corp.example.com -InstallDns -SiteName Default-First-Site-Name` and reboot. For a brand-new forest use `Install-ADDSForest` instead. Confirm with `dcdiag /test:advertising` and `repadmin /replsummary`.

## Prepare the server

Install Windows Server 2025 Standard or Datacenter, apply the latest cumulative update, and set the basics:

```
Rename-Computer -NewName DC03 -Restart
New-NetIPAddress -InterfaceAlias Ethernet -IPAddress 10.10.0.13 -PrefixLength 24 -DefaultGateway 10.10.0.1
Set-DnsClientServerAddress -InterfaceAlias Ethernet -ServerAddresses 10.10.0.11,10.10.0.12
Set-TimeZone -Id "UTC"
```

Point DNS at existing DCs only; do not add a public resolver. Join the domain as a member first with `Add-Computer -DomainName corp.example.com -Restart` if you prefer a two-stage approach, though promotion will also join it. If the server is a VM, disable time sync from the hypervisor for DCs and give it at least 2 vCPU and 4 GB RAM; AD itself is light, but the DFSR staging area and event logs are not.

## Check the existing domain is ready

On an existing DC, confirm SYSVOL is on DFSR and the functional level is at least 2008 R2:

```
dfsrmig /getglobalstate
Get-ADForest | Select-Object ForestMode
Get-ADDomain | Select-Object DomainMode
repadmin /replsummary
```

The migration state must be “Eliminated”; if it is not, complete the FRS to DFSR migration with `dfsrmig /setglobalstate 1`, then 2, then 3, waiting for each to replicate. Fix any replication failures before continuing. Then extend the schema from the 2025 media, logged on as a member of Schema Admins and Enterprise Admins, on the Schema Master:

```
D:\support\adprep\adprep.exe /forestprep
D:\support\adprep\adprep.exe /domainprep
```

The promotion wizard runs these automatically when the account has the rights, but doing it manually lets you schedule the schema change and check `Get-ADObject (Get-ADRootDSE).schemaNamingContext -Properties objectVersion` afterwards; expect the version to match the 2025 level listed in the media’s schema files.

## Install the role and promote

```
Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
Install-ADDSDomainController -DomainName "corp.example.com" `
  -InstallDns -CreateDnsDelegation:$false `
  -SiteName "Default-First-Site-Name" `
  -DatabasePath "C:\Windows\NTDS" -LogPath "C:\Windows\NTDS" -SysvolPath "C:\Windows\SYSVOL" `
  -NoGlobalCatalog:$false -Credential (Get-Credential CORP\adminuser)
```

You will be prompted for the Directory Services Restore Mode password; store it in your password vault, because it is the only way to log on if AD fails to start. Add `-ReplicationSourceDC DC01` to pull from a specific partner, or `-InstallationMediaPath` to promote from IFM media over a slow link. For a new forest:

```
Install-ADDSForest -DomainName "corp.example.com" -DomainNetbiosName "CORP" `
  -ForestMode WinThreshold -DomainMode WinThreshold -InstallDns
```

The server reboots at the end. Windows Server 2025 also offers the 2025 functional level; leave it at Windows Server 2016 (WinThreshold) unless every DC is 2025, then raise it later as described in [raise the AD forest and domain functional level safely](/guides/raise-ad-functional-level/).

## Post-promotion tasks

After the reboot, set the DC’s own DNS to another DC first and itself second, then make sure the DNS server has forwarders and that the new DC is registered in the site you intended. Enable the AD Recycle Bin if the forest has not done so already. Move clients and DHCP scopes to the new DC’s address only after it has been advertising for a while. If the plan is to retire the old DC, transfer any FSMO roles it holds with [transfer and seize FSMO roles](/guides/transfer-fsmo-roles-powershell/), and remember to move the time source configuration if it was the PDC emulator.

## Verify

```
dcdiag /test:advertising /test:sysvolcheck /test:netlogons /test:replications
repadmin /replsummary
Get-DnsServerResourceRecord -ZoneName "_msdcs.corp.example.com" -RRType Srv | Select-Object -First 5
nltest /dsgetdc:corp.example.com /force
```

All tests should pass, `_msdcs` must contain SRV records for the new DC, and a client running nltest from the same site should be handed the new server. A common pitfall is promoting with the server’s DNS pointing at itself before the zones have replicated; the DC then logs Event 4013 and waits for a DNS that does not exist yet, which is fixed by setting a partner DC as primary DNS and restarting Netlogon.

## Windows Server 2025 domain controller at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Change a domain controller’s IP address without breaking replication](https://srvscripts.com/guides/change-domain-controller-ip-address/) · [Fix “The trust relationship between this workstation and the primary domain failed”](https://srvscripts.com/guides/trust-relationship-failed-fix/) · [Raise the AD forest and domain functional level safely](https://srvscripts.com/guides/raise-ad-functional-level/).

## Frequently asked questions

### Does Windows Server 2025 require a specific forest functional level before promotion?

The forest and domain must be at Windows Server 2008 R2 or higher and SYSVOL must be migrated to DFSR; the functional level itself does not need to be raised to 2025 for the new DC to join.

### How long does promoting a Windows Server 2025 domain controller take?

The role install and promotion typically take 10 to 20 minutes including the reboot, plus initial replication, which can run from a few minutes for a small directory to an hour or more across a slow WAN link.

### Can I undo the promotion if something goes wrong?

Yes; run `Uninstall-ADDSDomainController -DemoteOperationMasterRole -RemoveApplicationPartitions` to demote cleanly, or `-ForceRemoval` if the DC cannot contact the domain, then clean up its metadata on a surviving DC.
