Skip to content

Child Domain

SettingValue
Domain Namecorp.microsoftlab.ch
NetBIOS NameCORP
Parent Domainmicrosoftlab.ch
Domain ModeWindows Server 2025
Domain Controllersrv-dcc-zrh-01
IP Address10.30.30.15
Terminal window
# Set static IP
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 10.30.30.15 -PrefixLength 24 -DefaultGateway 10.30.30.1
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 10.30.30.10
# Set hostname
Rename-Computer -NewName "srv-dcc-zrh-01" -Restart
# Install AD DS role
Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
Terminal window
Install-ADDSDomain `
-CreateDnsDelegation:$true `
-Credential (Get-Credential "MSLAB\Administrator") `
-DatabasePath "C:\Windows\NTDS" `
-DomainMode "Win2025" `
-DomainType "ChildDomain" `
-NewDomainName "corp" `
-ParentDomainName "microsoftlab.ch" `
-NewDomainNetbiosName "CORP" `
-InstallDns:$true `
-LogPath "C:\Windows\NTDS" `
-SysvolPath "C:\Windows\SYSVOL" `
-NoRebootOnCompletion:$false `
-Force:$true

Child DC DNS Settings:

Terminal window
# Child DC points to itself
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 127.0.0.1

Update Forest Root DC:

Terminal window
# On srv-dc-zrh-01 - Add child DC as secondary
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 10.30.30.15, 127.0.0.1

Automatic two-way transitive trust:

Terminal window
# Verify trust
Get-ADTrust -Filter *
# Expected:
# Source: corp.microsoftlab.ch
# Target: microsoftlab.ch
# Direction: BiDirectional
# TrustType: ParentChild
RoleLocation
PDC Emulatorsrv-dcc-zrh-01.corp.microsoftlab.ch
RID Mastersrv-dcc-zrh-01.corp.microsoftlab.ch
Infrastructure Mastersrv-dcc-zrh-01.corp.microsoftlab.ch

Forest-level roles remain on srv-dc-zrh-01.

Terminal window
Add-Computer -DomainName "corp.microsoftlab.ch" -NewName "srv-xxx-zrh-01" -Credential (Get-Credential "CORP\Administrator") -Restart