How To Create Additional Domain Controller (ADC) In Windows Server 2012 R2 and 2016

An additional domain controller in Windows Server 2012 R2
In this publication, we’ll learn about the steps to create an additional domain controller in Windows Server 2012 R2. Having a single domain controller is not secure for the enterprise network because it will be a single point of failure in the event of a technical failure. The entire network will be turned off and this will cause a major outage. To eliminate the risk of network failure, we need an additional domain controller (ADC) in our environment. It also depends on the total locations.
 
Organizations have multiple DCs that mean more than one DC is the benefit of having multiple domain controllers to load balance the environment. Moreover, it reduces the risk of total outage in case of low DC current.
 
 

Once the AD-DS role is installed, click on the exclamation sign on the top of Server manager and click on “Promote this server to a domain controller”.

 

To promote this computer as an ADC select the option “Add a domain controller to an existing domain”. Please ensure your domain name is selected and you are logged in as enterprise admin. Click Next. There can be two conditions as below.



1: If your Additional domain controller computer already member of Domain blog2india.com (No need to provide Enterprise Admin and password)
2: If your Additional domain controller computer not member of Domain blog2india.com, so you need to click  select and provide enterprise administartor name and password as below screen and then click next.


Select the options “DNS Server” and “Global Catalog (GC). If you want to install DNS on this server and promote this server as a Global Catalog. Type Directory Services Restore Mode password. Please ensure that you remember this password, we’ll use this password while logging to Active Directory Restore Mode.

In the “DNS Options” window, click on next.

In the “Additional Options” window, select the domain controller from which you want all the data to be replicated. In this example, we only have one DC in our environment. If you have multiple DCs then select the one which is either at our site or near to our site.

In the paths window, define the patch of database folder, log file folder and sysvol folder. We’ll go with the default in this example, but you can change it as per your preference.

Review all your selections. Click previous and change if any changes are required else click next.

In “prerequisite check”, it would show all the prerequisites that are missing and need to be fixed. We can ignore the warnings but we can’t ignore the error message. In case of error message, install option will not be visible. Click on Install to begin the installation of ADC.
Installation will take couple of minutes depending on the connection between DC and newly promoted computer, as it would replicate data. After installation is done, it would restart the computer for changes to get implemented.


After restart is completed, login with Administrator, open active directory users and computer. Select Domain controllers OU. It would show the newly provisioned Computer.
 
 
What is active directory replication
Active Directory replication is a critical service that keeps changes synchronized with other domain controllers in the forest. Problems with replication can cause authentication failures and issues accessing network resources (files, printers, applications).
 
What Exactly Is Replicated in Active Directory
The domain controllers in Active Directory contain the following directory partition replicas:
 
Schema – The schema partition contains objects that can be created in Active Directory and which attributes these objects can contain. Domain controllers in a forest have a read-only copy of the schema partition. Objects stored in the schema partition are replicated to each domain controller in domains/forests.
 
Configuration – The configuration partition contains the objects relevant to the logical structure of the forest, structure of the domain, and replication topology (remember our first article in this series?) Each domain controller in the forest contains a read/write copy of the configuration partition. Any objects stored in the configuration partition are replicated to each domain controller in each domain, and in a forest.
 
Domain – The domain partition or naming context (NC) contains all objects that are stored in a domain. Each domain controller in a domain has a read/write copy of the domain partition. Objects in the domain partition are replicated to only the domain controllers within a domain.
 
Application – The application partition contains objects or data that applications and services store.  For example; DNS, RAS, and DHCP.
Interesting to know is that replication is triggered when certain actions occur in the database. Triggers are when an object is created, deleted, moved, or modified.
 
Replication Types
There are two types of Active Directory replication that can be defined:  intrasite replication and intersite replication.
Intra-site Replication – Intra-site replication takes place between domain controllers within the same site, making it a fairly uncomplicated process. When changes are made to the replica of Active Directory on one particular domain controller, the domain controller contacts the other domain controllers within the same site and it then checks the information it contains against information hosted by the other domain controllers. Intra-site replication uses the Remote Procedure Call (RPC) protocol to perform replication data over fast and reliable network connections.
 
Inter-site Replication – Inter-site replication takes place between sites and uses either RPC over IP or SMTP to replicate the data. Inter-site replication has to be manually configured and occurs between two domain controllers that are so-called bridgeheads. This role is assigned to at least one domain controller within a site. It is only these bridgeheads that replicate data with domain controllers in different domains by performing inter-site replication with its partners and packets are compressed to save bandwidth. Inter-site replication takes place over site links by a polling method which is every 180 minutes by default.
 
Now to Verify Active Directory Replication perform following steps:
 
Click search and type Sites and Services and click Active Directory Sites and Services
Open Active Directory Sites and Services, here you will see both the servers are added.

Navigate to any of the servers and Right Click on Automatically Generated Script. Select Replicate Now Option.

You will see an informative dialog box as displayed in following picture which is a sign of a successful replication

1 thought on “How To Create Additional Domain Controller (ADC) In Windows Server 2012 R2 and 2016”

Leave a comment