PikoSystem IT engineering services
Servers & Hosting

Windows Server and Active Directory setup and support

When every employee uses a local account on their own PC, one departure turns into a hunt for passwords and files. An Active Directory setup lets you manage accounts, permissions and security policy from one place. We design and build new domains, or clean up and support the one you already have.

Tools & technology windows-server-active-directory
  • Windows Server 2022
  • Active Directory
  • Group Policy
  • DNS
  • DHCP
  • FSRM
  • PowerShell
  • Windows Admin Center
6work areas
5deliverables
4steps

What is Windows Server & AD?

Active Directory setup is the design, build and support of a Windows Server domain so that user accounts, permissions and security policy are managed from one place. It suits companies where every employee uses a local account, the domain controller still runs Windows Server 2012, or accounts of former staff remain active. PikoSystem installs two domain controllers with DNS, DHCP and an OU structure, applies password policy, screen lock and USB restrictions through Group Policy, builds a file server with group-based folder permissions and FSRM quotas, moves FSMO roles to a new Windows Server 2022 host when upgrading, and sets up System State backups with test restores. Health checks use dcdiag and repadmin. You receive documented OUs and GPOs, a shared folder permission matrix, admin credentials, a domain recovery document and a procedure for creating and disabling staff accounts.

When you need Windows Server & AD

  • Every employee has a separate password on their own PC and nothing is managed centrally.
  • We have a shared folder where everyone can open everything.
  • Our domain controller still runs Windows Server 2012, which is out of support.
  • Accounts of people who left are still active.

What Windows Server & AD includes

01

Domain design and build

Domain naming, two domain controllers so logins do not depend on a single server, DNS and DHCP configuration, and an OU structure.

02

Group Policy

Password policy, screen lock, mapped network drives, printer deployment and USB restrictions applied through GPOs.

03

File server and permissions

A file server with folder permissions based on work groups, Shadow Copies and storage quotas with FSRM.

04

Migration and upgrade

Moving FSMO roles to a new Windows Server, raising the domain functional level and safely retiring old domain controllers.

05

Domain backups

System State backups and test restores, so losing one server does not mean losing every account.

06

Health checks

dcdiag and repadmin runs, replication errors reviewed in Event Viewer, and cleanup of stale user and computer accounts.

What you get from Windows Server & AD

  • OU structure, groups and a list of applied GPOs
  • A permission matrix for shared folders
  • Admin credentials and a break-glass account handed to company management
  • A domain recovery document and the result of the latest backup test
  • A procedure for creating and disabling staff accounts

Windows Server & AD: a practical guide

Windows Server 2022 or 2025 for a new domain controller?

Windows Server 2022 is supported until October 2031 and Windows Server 2025 until 2034. The 2025 release adds a new domain functional level, but to add a 2025 domain controller to an existing domain, the forest and domain functional levels must be at least Windows Server 2016. If a 2012 domain controller is still on the network, the upgrade path takes more than one step.

One detail that often gets missed is how SYSVOL replicates. Domains dating back to the Windows Server 2003 era sometimes still use FRS, and newer domain controllers cannot be promoted until SYSVOL is migrated to DFSR with dfsrmig.

Common domain controller setup mistakes

Naming the domain company.local is still common. Public certificate authorities will not issue certificates for .local names, and the suffix clashes with mDNS on Macs and some other devices. A subdomain of your real domain, such as ad.company.com, avoids both problems. Pointing client DNS at 8.8.8.8 is another frequent error, and it leads to slow logons and Group Policy that never applies.

On virtual domain controllers, rolling back to an old snapshot can break replication with a USN rollback. Using a Domain Admin account for everyday work is risky as well, since its credentials stay in memory on every machine it signs in to.

What to prepare before joining computers to the domain

A staff list with departments, the folders each group needs and your network printers form the basis of the OU and group design. Check client Windows editions too. Windows 10 and 11 Home cannot join a domain and need an upgrade to Pro.

After joining, users sign in with a fresh profile, and desktop files and app settings stay behind in the old local profile. We plan profile migration in advance so nobody spends their first morning looking for files.

Securing Active Directory after handover

Many ransomware attacks on Windows networks spread through Active Directory. Windows LAPS gives every computer a unique, automatically rotated local Administrator password, so one shared password no longer opens every machine. Disabling SMBv1 and NTLMv1 and auditing events 4625 and 4740 makes failed logons and account lockouts traceable.

Review the members of Domain Admins every few months, and replace service accounts that use short, static passwords with gMSAs.

How Windows Server & AD works

  1. 01

    Current state review

    We check existing servers, user accounts, shares and permissions, and find out what depends on the domain.

  2. 02

    Design

    We propose the domain structure, groups, policies and access matrix, and finalize them with you.

  3. 03

    Build

    Servers are installed and configured, and computers join the domain in batches outside working hours.

  4. 04

    Handover and training

    Documentation and admin credentials are handed over, and your contact person learns how to create and disable accounts.

Windows Server & AD: frequently asked questions

Will an Active Directory migration to a new Windows Server cause downtime?

Done properly, users usually do not notice. The new domain controller is added alongside the old one, replication is verified and roles are moved. The old server is retired only once the domain is confirmed healthy.

Does a 15-person company need Active Directory?

Once you have more than a handful of users, managing accounts and permissions by hand gets slow and error-prone. If you use shared files, network printers or need access control, a domain makes the job simpler. For teams that work entirely in the cloud, we look at other options too.

Can you supply Windows Server licenses and CALs?

Yes, genuine licenses are available through our licensing service. Before you buy, we work out how many CALs you need based on users or devices.

Are two domain controllers really necessary?

With one domain controller, if that server fails, users cannot sign in and internal DNS stops working. The second domain controller can be a small virtual machine running on a different host.

Related searches

  • Active Directory services
  • domain controller setup
  • Windows Server support
  • Windows Server 2022 installation
  • Group Policy
  • file server setup
  • Active Directory migration

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.