03 - 1002 - I - 2 Install Domain Controller
03 - 1002 - I - 2 Install Domain Controller
Contents
Install Windows 2008 R2 Server (Skip If Already Installed) ..................................................................3
Promote the Server to a Root Domain Controller (Skip if already done) ............................................11
Given a server grade platform (in in-centre class T310 and remote class virtual platform), install
Windows Server 2008 R2 Standard Edition. The tasks following this task (of installing 2008 R2)
will create and configure a Domain Controller which is appropriate to be used as part of an
Experion system.
The steps detailed out in the subsequent tasks are also available in the Experion Windows
Domain/Workgroup Implementation Guide.
Main Idea
For the purpose of this class skip the steps to install Windows Server 2008 R2 Standard Operating
system software and updates. The image you restored did this for you.
ATTENTION
Step Action
1 Insert the Windows Server 2008 R2 Standard Edition CD-ROM and boot the machine
to begin the installation.
TIP
Install the Latest W2K8 R2 Service Pack (Per Honeywell) (Skip if already
installed)
Main Idea
If the node which will become the DC is already installed with Windows2008 R2 Standard Edition
with Service Pack1 then skip this procedure.
In class, skip this procedure. It has been done by the image you restored.
Step Action
ATTENTION
4 If necessary, check the “Do not display the page at logon” checkbox.
5 Insert the Experion Initialization Update media or browse to the D_EXP_UPD folder
present on the ESIS ( in class: \\OPC1\ESISR430 ).
Step Action
12 After the restart, logon to the machine as administrator. If a dialog box appears
"Windows Server Service pack 1 is now installed" click close to exit.
This procedure may have been done as part of the Windows 2008 R2 installation. The time on your
system may already be correct, and you may not need to do this procedure.
ATTENTION
Step Action
TIP
2 Click Start > Control Panel > Clock, Language and Region > Date and Time.
3 Click the Change Time Zone button in ‘Date and Time’ tab.
4 Use the drop-down menu to select the local time zone. Click OK
5 Click the Change date and time button in Date and Time tab.
Step Action
2 At the server which will later become the DC, logon as a user with administrative
privileges.
3 From the Start menu, right-click the Network and select Properties.
7 Select Internet Protocol Version 4(TCP/IPv4) and click the Properties button.
9 Enter the Yellow IP address, Subnet mask, Default gateway, and Preferred DNS
server from your partition sheet.
ATTENTION
10 Click the OK button to close the Internet Protocol Version 4(TCP/IPv4) Properties dialog
box.
11 Click the Close button to close the Supervisory Network (NIC1) Properties dialog box.
Step Action
13
ATTENTION
Physically connect the network (Ethernet) cable to the NIC1 using either the yellow or
green cable.
ATTENTION
Set the password for the Administrator account (in class, use ac NL01 1).
5 Right-click on the Administrator account and set the password for Administrator account
(in class: ac NL01 1).
ATTENTION
Procedure
1 Select Start > All Programs > Accessories > Run.
2 Type dcpromo and press Enter.
3 If User Account Control prompts, click Continue.
Patience, loading the Active Directory Domain Services binaries takes a little over a
minute.
8 In the Welcome dialog box select Use advanced mode Installation and click Next.
Step Action
11 Enter the full DNS name for this root domain from the partition sheet Windows Domain
Name and click Next.
• The DNS name should adhere to DNS conventions (for example, underscores
are permitted by Microsoft DNS Servers, but may not be supported by other
DNS server products).
TIP
12 Accept the NetBIOS Domain name and click the Next button.
Typically, you will accept the default name, which matches the first portion of the DNS
name.
13 Select Windows Server 2003 for the Forest functional level and click Next.
14 Select Windows Server 2003 for the Domain functional level and click Next.
16 If you see this message click ‘Yes, the computer will use…’
Step Action
ATTENTION
The Active Directory installation wizard does not create a reverse lookup zone. If you
want a reverse lookup zone, you will need to create one after you complete the Active
Directory installation.
Step Action
18 Accept the default Database folder, Log files folder and SYSVOL locations and click the
Next button.
At your plant, if disk space is an issue, an alternate location can be selected
19 Enter a Directory Services Restore Mode Administration Password (in class, use
ac NL01 1), and click the Next button.
ATTENTION
ATTENTION
22 Click the Restart Now button to make the Active Directory installation effective.
ATTENTION
Step Action
TIP
ATTENTION
Step Action
2 In the Console tree (left-hand side of the MMC), expand your DNS server by clicking
PLUS SIGN (+).
4 Right-click the Reverse Lookup Zones folder and select New Zone.
TIP
6 In the Zone Type dialog box, select Primary zone, check the Store the zone in Active
Directory…… checkbox and click the Next button.
Step Action
7 In the Active Directory Zone Replication Scope screen, select To all domain controllers
in this domain (for Windows 2000 compatibility): NameofDomain and click Next.
Step Action
8 In the Reverse Lookup Zone Name dialog box, select IPv4 Reverse Lookup Zone and
click Next.
9 In the Reverse Lookup Zone Name dialog box, select the Network ID option; enter your
Network ID (in class, the first three octets of your IP address.
Ex: 164.145.214), and click Next.
Step Action
10 In the Dynamic Update screen, select Allow only secure dynamic updates…… and
click Next.
Step Action
4 From your partition sheet, enter the IP address of the DNS Forwarder (the DNS server
to which this DNS server should forward name resolution requests) and press Enter.
ATTENTION
8 Click Add, type Local Service, click Check Names, and click OK.
9 Ensure that Local Access Allow is selected for the user ‘Local Service’, and click OK.
Step Action
10 In the ‘Launch and Activation Permissions’ group, click the Edit Default button.
11 Click Add, type Local Service, click Check Names, and click OK.
12 Ensure that Local Launch Allow and Local Activation Allow are selected for the user
‘Local Service’, and click OK.
Step Action
Domain Controller Security and Optional Component Installation
15
TIP
17 When the AutoPlay dialog appears, click on Run Experion Media Browser.
TIP
18 In the ‘Honeywell – Experion PKS Installer – R430’ dialog, click Install/Migrate Experion
PKS.
21 When the ‘Welcome to the Installshield wizard Honeywell Security Model – Domain
Controller’ window appears, click Next.
Step Action
TIP
24 Click Install.
Step Action
TIP
3 Right-click the domain name at the top of the hierarchy and select New >
Organizational Unit.
4 In the dialog box for the organizational unit, enter the TPSTeam# (where # is your
student group number) and click OK.
ATTENTION
5 The newly created OU appears in the directory tree. Select the newly created OU, then
right-click the OU and select Properties from the menu.
ATTENTION
The accounts built in this lab are specific to this Automation College class. At your site, you would
build accounts based on your requirements rather than building accounts with these names.
Step Action
1 If necessary, open the Active Directory Users and Computers MMC by selecting:
Start >Administrative Tools > Active Directory Users and Computers.
2 Navigate to the Users container. It may be necessary to expand the domain to be able to
access the Users container.
3 In the Console Tree (left-hand side of the MMC), click on the Users container to display
the contents.
4 In the Details pane (right-hand side of the MMC), right-click Student and select
Properties.
5 Add the Student user to the DCS Administrators and Domain Admins groups.
Procedure
1. Select the Member Of tab.
2. Click the Add button.
3. Click Advanced.
4. Click Find Now.
5. Select the DCS Administrators group.
6. Hold the Ctrl button down while selecting the Domain Admins
group.
(Note: both groups should be selected.)
7. Click the OK button.
8. Click OK to close the ‘Select Groups’ dialog box.
9. Click OK to close the ‘Student Properties’ dialog box.
Step Action
ATTENTION
8 For the engr# account, enter ac NL01 1 in both of the password fields.
Verify that only the following selections are selected:
User cannot change password
Password never expires.
Click the Next button
10 In the Console Tree (left-hand side of the MMC), click on the Users container to display
the contents.
11 In the Details pane (right-hand side of the MMC), select engr# (this deselects the student
account), then right-click engr# and select Properties.
Procedure
1. Click the Add button.
2. Click Advanced.
3. Click Find Now.
4. Select the Engineers group.
5. Click the OK button.
6. Click OK to close the ‘Select Groups’ dialog box.
Step Action
Procedure
1. Display the properties of engr#
2. Select the group which should be the primary group (for engr#, Engineers).
3. Click the Set Primary Group button.
4. Select the Domain Users group.
5. Click the Remove button.
6. Click the Yes button.
16 Repeat steps 7 to 15 with the following table to create the remaining domain accounts in
the Users container:
1
Deselect (uncheck) the User must change password at next logon option, and select the User
cannot change password and the Password never expires options.
2
This is the password we will use in class. At your site, you may choose any password. Choose your
passwords carefully; they can be difficult to change – especially the password for the mngr account.
Step Action
This is a lab for reference only. It shows how you can install and use the Windows Server Backup
feature. In class, we do not want students creating images of the DC.
Step Action
ATTENTION
2 Select Start > All Programs > Administrative Tools > Server Manager
TIP
3 In the left pane click Features and then In the right pane click Add Features. This opens
the Add Features Wizard.
Step Action
Add Windows Server Backup Feature
4 On the Select Features page, expand Windows Server Backup Features by clicking
(+) symbol, and then select the check box Windows Server Backup
Click Next
Step Action
Add Windows Server Backup Feature
Step Action
1 Select Start > All Programs > Administrative Tools > Windows Server Backup.
2 In the right pane click Backup once. This opens the Backup Once Wizard.
TIP
Step Action
Perform Backup Procedure
TIP
Step Action
Perform Backup Procedure
TIP
6 Enter a UNC path to store the backup. Select the option Inherit. Click Next.
Step Action
Perform Backup Procedure