Domain design and build
Domain naming, two domain controllers so logins do not depend on a single server, DNS and DHCP configuration, and an OU structure.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
When every employee uses a local account on their own PC, one departure turns into a hunt for passwords and files. An Active Directory setup lets you manage accounts, permissions and security policy from one place. We design and build new domains, or clean up and support the one you already have.
Active Directory setup is the design, build and support of a Windows Server domain so that user accounts, permissions and security policy are managed from one place. It suits companies where every employee uses a local account, the domain controller still runs Windows Server 2012, or accounts of former staff remain active. PikoSystem installs two domain controllers with DNS, DHCP and an OU structure, applies password policy, screen lock and USB restrictions through Group Policy, builds a file server with group-based folder permissions and FSRM quotas, moves FSMO roles to a new Windows Server 2022 host when upgrading, and sets up System State backups with test restores. Health checks use dcdiag and repadmin. You receive documented OUs and GPOs, a shared folder permission matrix, admin credentials, a domain recovery document and a procedure for creating and disabling staff accounts.
Domain naming, two domain controllers so logins do not depend on a single server, DNS and DHCP configuration, and an OU structure.
Password policy, screen lock, mapped network drives, printer deployment and USB restrictions applied through GPOs.
A file server with folder permissions based on work groups, Shadow Copies and storage quotas with FSRM.
Moving FSMO roles to a new Windows Server, raising the domain functional level and safely retiring old domain controllers.
System State backups and test restores, so losing one server does not mean losing every account.
dcdiag and repadmin runs, replication errors reviewed in Event Viewer, and cleanup of stale user and computer accounts.
Windows Server 2022 is supported until October 2031 and Windows Server 2025 until 2034. The 2025 release adds a new domain functional level, but to add a 2025 domain controller to an existing domain, the forest and domain functional levels must be at least Windows Server 2016. If a 2012 domain controller is still on the network, the upgrade path takes more than one step.
One detail that often gets missed is how SYSVOL replicates. Domains dating back to the Windows Server 2003 era sometimes still use FRS, and newer domain controllers cannot be promoted until SYSVOL is migrated to DFSR with dfsrmig.
Naming the domain company.local is still common. Public certificate authorities will not issue certificates for .local names, and the suffix clashes with mDNS on Macs and some other devices. A subdomain of your real domain, such as ad.company.com, avoids both problems. Pointing client DNS at 8.8.8.8 is another frequent error, and it leads to slow logons and Group Policy that never applies.
On virtual domain controllers, rolling back to an old snapshot can break replication with a USN rollback. Using a Domain Admin account for everyday work is risky as well, since its credentials stay in memory on every machine it signs in to.
A staff list with departments, the folders each group needs and your network printers form the basis of the OU and group design. Check client Windows editions too. Windows 10 and 11 Home cannot join a domain and need an upgrade to Pro.
After joining, users sign in with a fresh profile, and desktop files and app settings stay behind in the old local profile. We plan profile migration in advance so nobody spends their first morning looking for files.
Many ransomware attacks on Windows networks spread through Active Directory. Windows LAPS gives every computer a unique, automatically rotated local Administrator password, so one shared password no longer opens every machine. Disabling SMBv1 and NTLMv1 and auditing events 4625 and 4740 makes failed logons and account lockouts traceable.
Review the members of Domain Admins every few months, and replace service accounts that use short, static passwords with gMSAs.
We check existing servers, user accounts, shares and permissions, and find out what depends on the domain.
We propose the domain structure, groups, policies and access matrix, and finalize them with you.
Servers are installed and configured, and computers join the domain in batches outside working hours.
Documentation and admin credentials are handed over, and your contact person learns how to create and disable accounts.
Done properly, users usually do not notice. The new domain controller is added alongside the old one, replication is verified and roles are moved. The old server is retired only once the domain is confirmed healthy.
Once you have more than a handful of users, managing accounts and permissions by hand gets slow and error-prone. If you use shared files, network printers or need access control, a domain makes the job simpler. For teams that work entirely in the cloud, we look at other options too.
Yes, genuine licenses are available through our licensing service. Before you buy, we work out how many CALs you need based on users or devices.
With one domain controller, if that server fails, users cannot sign in and internal DNS stops working. The second domain controller can be a small virtual machine running on a different host.
Related searches
Quote
A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.