In order for you to accomplish AD on OCI, several assumptions are made:

  • 1
    A secure (nonpublic) connection exists between your on-premises environment and Oracle Cloud Infrastructure (this can either be a Fast Connnect or IPSec VPN connection, as shown in the diagram below).
  • 2
    You have a domain admin account in the on-premises Active Directory environment (or an account that has permission to both join the domain and install a domain controller).

Oracle Cloud Infrastructure can help you build and extend your current Active Directory Forest.

Configuring the Domain Controllers

Your Vision, Our Expertise

Elevating Your Software Product Engineering Journey with Vast Edge

Install the Active Directory Domain Services Role:

  • 1
    1. Log in to the first instance that is to be promoted to a domain controller, using the ADMIN user credentials
    (administrator user).
  • 2
    2. Run Server Manager.
  • 3
    3. Click Add Roles and Features.
  • 4
    4. Click Next until you get to the Server Role dialog.
  • 5
    5. Select the Active Directory Domain Services checkbox.
  • 6
    6. In the dialog box that appears, click the Add Features button.
  • 1
    7. Select the DNS Server checkbox. (Optional)
  • 2
    8. the dialog box that appears, click the Add Features button.

Note: If you selected to install the DNS Server role, you will get a warning dialog box informing you that no static IP addresses were found on the computer. Because the IP address associated with this instance will be associated with it for the life of the instance, you can click the Continue button.

  • 1
    9. Once these 2 options have been selected, click Next to continue:
  • 1
    10. Click Next until you get to the Confirmation dialog. Check Restart the destination server automatically if required (accept the pop-up dialog box) and click Install:
  • 1
    11. The installation of the new roles will begin. Once the installation is complete, you can click Close to complete the Add roles and features wizard.

Repeat the steps above for the second domain controller.

Configure DNS

Reconfigure the DNS server to point to the on-premises Active Directory DNS server to promote the domain controller.

Prerequisites:

  • 1
    Credentials for Windows ADMIN account.
  • 2
    IP address(es) of the on-premises DNS server(s).

Configure the on-premises DNS server:

  • 1
    1. Log in to the first system as the ADMIN user.
  • 2
    2. Right-click the Network icon in the right corner of the screen and choose Open Network and Sharing Center.
  • 1
    3. Click Change adapter settings in the left pane.
    Note: The options appearing in the Network Connections window discussed here are for instance launched as Virtual Machine instances. If you launched the Windows servers as Bare Metal instances, the name of the adapter will be different, however, the steps are the same regardless of instance type.
  • 2
    4. Right-click the Ethernet network adapter (it should be labeled "Intel(R) 82599 Virtual function") and choose Properties. (For Bare Metal instances, it should be labeled "Intel(R) Ethernet Server Adapter X520-2" or similar.)
  • 3
    5. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties.
  • 1
    6. Choose Use the following DNS server addresses.
  • 2
    7. Enter the IP address(s) of the on-premises DNS server(s) and click OK.
  • 1
    8. Click Close.
  • 2
    9. You can test that the DNS server is working by either navigating to a public website (assuming that your instance(s) have Internet access) or by running the nslookup command from a command prompt.
    Repeat the steps above for the second domain controller.

Join the domain

Now that the DNS server is configured on your instance, you can join the domain.

Prerequisites:

  • 1
    Credentials for Windows ADMIN account.
  • 2
    Domain credentials for an account that has permission to join the domain.
  • 3
    The Fully Qualified Domain Name (FQDN) of the domain to be joined.

Steps:

  • 1
    1. Log in to the first system as the ADMIN user.
  • 2
    2. Run Windows Explorer.
  • 3
    3. Right-click This PC and choose Properties.
  • 4
    4. In the Computer name, domain, and workgroup settings section, click Change settings.
  • 5
    5. Click Change.
  • 1
    6. Select the Domain radio button.
  • 2
    7. Enter the FQDN name of the domain that you are joining and click OK.
  • 3
    8. If the DNS server is configured correctly, you should be prompted with a dialog box to enter the domain administrator credentials. Enter the credentials and click OK.
  • 4
    9. If the credentials are correct and have the appropriate permissions, you should receive a Welcome to the… domain message.
  • 5
    10. Click OK to close the dialog.
  • 6
    11. Another dialog box notifying you that you need to reboot the server will be displayed, click OK.
  • 1
    12. Click Close to close the System Properties control panel.
  • 2
    13. Click Restart Now to restart the server

    Repeat the steps above for the second domain controller.

Promote the Domain Controller

Prerequisites:

  • 1
    Domain credentials for an account that has domain administrator permission to promote a server as a domain controller.

Promote the server to a read-only domain controller:

  • 1
    1. Log in to the first system as a domain administrator (or account that has equivalent permissions). You will need to change the username from ".\Admin" to "your_domain\your_domain_admin"
  • 2
    2. Run Server Manager.
  • 3
    3. You should notice a yellow warning notification icon. Click it and you should see a message stating that configuration is required for Active Directory Services. Click Promote this server to a domain controller.
  • 1
    4. In the Active Directory Domain Services Configuration Wizard, make sure to Add a domain controller to an existing domain is selected, the correct domain is listed in the Domain field, and the credentials displayed are correct, and click Next.
  • 1
    5. If this domain controller is to become a read-only domain controller, make sure you check the Read only domain controller (RODC) checkbox, otherwise, leave the checkbox unchecked.
  • 2
    6. Enter and confirm a password for Directory Services Restore Mode (DSRM) and click Next.
  • 1
    7. If you chose to install a read-only domain controller, select Delegated administrator account and list the account(s) that are allowed or denied from replicating passwords to this domain controller and click Next.
  • 1
    8. Click Next until you get to the Prerequisites Check step. You may be presented with some warnings on this screen, review the warnings and click Install.
  • 2
    9. The server will reboot at the end of the installation process.

Testing Active Directory

Your Oracle Cloud Infrastructure tenancy should now have two read-only domain controllers and you can now test if these domain controllers can be used to both join the domain from the tenancy, and log in to your servers using the domain credentials.

Configure the test instance to use the newly created domain controllers as the DNS server:

  • 1
    Log in to the test system as the ADMIN user.
  • 2
    Right-click the Network icon in the right corner of the screen and choose Open Network and Sharing Center.
  • 3
    Click Change adapter settings in the left pane
    Note: The options appearing in the Network Connections window discussed here are for instance launched as Virtual Machine instances. If you launched the Windows servers as Bare Metal instances, the name of the adapter will be different, however, the steps are the same regardless of instance type.


  • 4
    Right-click the Ethernet network adapter (it should be labeled "Intel(R) 82599 Virtual function") and choose Properties. (For Bare Metal instances, it should be labeled "Intel(R) Ethernet Server Adapter X520-2", or similar.)
  • 5
    Select Internet Protocol Version 4 (TCP/IPv4) and click Properties.
  • 6
    Choose Use the following DNS server addresses.
  • 7
    Enter the IP address(s) of the newly created domain controllers (these are the RFC1918 IP addresses you recorded earlier and click OK.
  • 8
    Click Close.

Next, you can join the test server to the domain:

  • 1
    Run Windows Explorer.
  • 2
    Right-click This PC and choose Properties.
  • 3
    In the Computer name, domain, and workgroup settings section, click Change settings.
  • 4
    Click Change.
  • 5
    Select the Domain radio button.
  • 6
    Enter the FQDN name of the domain that you are joining and click OK.
  • 7
    If the DNS server is configured correctly, you should be prompted with a dialog box to enter the domain administrator credentials. Enter the credentials and click OK.
  • 8
    If the credentials are correct and have the appropriate permissions, you should receive a Welcome to the… domain message.
  • 9
    Click OK to close the dialog.
  • 10
    Another dialog box notifying you that you need to reboot the server will be displayed. Click OK.
  • 1
    11. Click Close to close the System Properties control panel.

  • 2
    12. Click Restart Now to restart the server.

    Once the server has restarted, you can test that it is now part of the domain by using remote desktop to connect to the server and log in using your domain account rather than the local ADMIN account.

Copyrights © 26 December 2024 All Rights Reserved by Vast Edge Inc.