How to Add Tree Domain in an Existing Forest | Windows Server 2019

  Рет қаралды 38,633

MSFT WebCast

MSFT WebCast

5 жыл бұрын

Managing Active Directory Forest Infrastructure:
In this video guide we will see the steps to add tree domain in an existing windows server 2019 AD forest.

Пікірлер: 60
@bendunaway8296
@bendunaway8296 2 жыл бұрын
dude, you are everywhere. Your tutorials make my job so much easier.
@lstanford23
@lstanford23 8 ай бұрын
Once again, so informative. You make the best videos on IT. Keep up the great work!
@farith6411
@farith6411 4 жыл бұрын
I learned a lot from MSFT webcast..its more than my schoolings.
@jurajvantuch9636
@jurajvantuch9636 5 жыл бұрын
You are great man, your skills are perfect. Please continue in streaming videos. Big thanks for you.
@MSFTWebCast
@MSFTWebCast 5 жыл бұрын
Thank you very much for kind words.
@hamzapuris
@hamzapuris 2 жыл бұрын
Great tutorial as always, keep up the good work! :)
@annetterodriguez5375
@annetterodriguez5375 4 жыл бұрын
Very good tutorial!
@muhireherve4930
@muhireherve4930 Жыл бұрын
Thank you very much Sir. The video has helped me a lot.
@radhikagupta7595
@radhikagupta7595 Жыл бұрын
Thank you for this informative video😊
@hemendrgupta1681
@hemendrgupta1681 Жыл бұрын
All your video are amazing!. You forgot to include this video in Managing Active Directory Infrastructure playlist.
@MSFTWebCast
@MSFTWebCast Жыл бұрын
Again thank you.
@htconex19062012
@htconex19062012 Жыл бұрын
Well done
@arnabdey9731
@arnabdey9731 2 жыл бұрын
Bro, nice tutorial. But one question. Can we use forest level DNS replication instead of conditional forwarder..
@pg4694
@pg4694 2 жыл бұрын
one more thing i have seen ur all videos adding ADC,CDC AND TREE DOMAIN while installation and promoting this to dc on TREE DOMAIN AND ADC delegation DNS is not included its not checkd please explain and why it is checked in case of a CDC
@yuvaraj-mz7bf
@yuvaraj-mz7bf Ай бұрын
Hi, I installed an tree domain in my forest. But I cant install LDAPS.. Is that possible to install it in tree domain
@asbestinuS
@asbestinuS 11 ай бұрын
Hi! I have a question. I noticed that you didn't configure the Reverse Lookup Zone on bangalore-dc. Why? I tried it and I get a permission error. Can I only create it in my root domain or is it not needed? Replication seems to run fine. Also on my network adapter on my Tree domain controller I see my root-Domain as DNS-Name not my tree-Domain. Is that correct? Thank you for the tutorials!
@MSFTWebCast
@MSFTWebCast 11 ай бұрын
Yes, I had forgotten to create a reverse lookup zone on Tree domain. It shouldn't be the permission error, it might be due to replication is not completed. You can change the preferred DNS server address as required. The Local DNS servers address should be preferred address for DNS.
@pg4694
@pg4694 2 жыл бұрын
and hy replication server we need to select in case of adc and rodc not in case of cdc and tree domain
@amirnazari7928
@amirnazari7928 3 ай бұрын
hello why when i want add a tree the dc must disjoined a forest root domain ?
@RajeshKumar-cp8sr
@RajeshKumar-cp8sr Жыл бұрын
Getting message, while trying to add conditional forwarder. "This DNS server is not enlisted in the specified directory partition". Could you please suggest, what could be missing here. I am able to ping the root domain from tree domain controller.
@MSFTWebCast
@MSFTWebCast Жыл бұрын
You can create default Application partitions using DNS manager. For name resolution purpose, temporary use the hostfile (in case required). Create default application partitions, make sure Forest DNS zone is replicating and then you can remote the changes from the hostfile.
@danielpronin30
@danielpronin30 4 жыл бұрын
i have followed your instructions but got an error fsmo role ownership could not be verified
@imamkasali7435
@imamkasali7435 2 жыл бұрын
I got same error
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
yes beucause on you root domain you have 2 DC you must open both of them to do the procedure
@RajeshKumar-qz3hx
@RajeshKumar-qz3hx Жыл бұрын
I am trying to create a tree domain. as per first step explained trying to assign a different IP range but unable to ping the root domain. I see for root domain you have used 172.18.72.X and for tree you are using 10.10.72.x but DNS for tree is 172,18,72.5. I did the same but unable to ping because IP range changes and they cannot communicate. any suggestion would be greatly appreciated. Seems here my limited knowledge with networking.
@MSFTWebCast
@MSFTWebCast Жыл бұрын
I have one more VM with two network interfaces. I have configured LAN routing on it so it can act a router.
@RajeshKumar-cp8sr
@RajeshKumar-cp8sr Жыл бұрын
@@MSFTWebCast Thank you. Any good reference to learn more on networking?
@YuvarajPfx
@YuvarajPfx 2 ай бұрын
Hi, How to remove a tree domain controller(Which is inactive) from a forest?
@MSFTWebCast
@MSFTWebCast 2 ай бұрын
If tree domain is not coming back then and then only follow this process. 1. Check who holds the FSMO roles. If any fsmo role is assigned to tree DC, then transfer the role and assign to an active domain controller. 2. You can use Active Directory Domains and Trusts GUI option or Metadata cleanup CUI option to remove the tree domains domain controller.
@pg4694
@pg4694 2 жыл бұрын
what is this tree domain exactly and why it is used for we have created adc,cdc and rodc but not getting point for tree domain plz explain
@MSFTWebCast
@MSFTWebCast 2 жыл бұрын
Generally we use tree domain in forest if we want to have separate domain with different domain dns name. And also Root Domain administrator have access on it.
@pg4694
@pg4694 2 жыл бұрын
@@MSFTWebCast thanks for your reply
@chetansharma6595
@chetansharma6595 3 жыл бұрын
I tried to check the replication status and I got error message "Access is denied"
@MSFTWebCast
@MSFTWebCast 3 жыл бұрын
On which domain controller?
@chetansharma6595
@chetansharma6595 3 жыл бұрын
@@MSFTWebCast I guess I made a mistake. Now it fixed. Thank you for your quick reply.
@xinyuechen2494
@xinyuechen2494 4 ай бұрын
Great video, I followed the instruction. I cannot ping root AD domain name, but ping AD IP address is ok. I am in installation step for more than 2 hours and unable to stop. I was wondering if it is normal?
@MSFTWebCast
@MSFTWebCast 4 ай бұрын
I think its related to DNS. Have you configured root domains DNS servers address as a preferred DNS server address on the server which you want to setup as a child domain?
@xinyuechen2494
@xinyuechen2494 4 ай бұрын
Thank you for your reply. Yes, I set up the root domain DNS as a preferred DNS server address. I can nslookup the domain name. It points to my root domain private ip address (this is what I want). But if I ping, it redirect to public ip address of my root domain (no response, timeout). And I still stuck in installation steps (configuring the local computer to host Active Directory Domain Services). Is there anywhere I can see the log for the installation process. @@MSFTWebCast
@MSFTWebCast
@MSFTWebCast 4 ай бұрын
@@xinyuechen2494 This is strange! Why public IP address of root domain? For time being add static entry of your domain names DNS name and private IP address in hostfile. for exmaple: x.x.x.x yourdomainname.com And check ping again.
@xinyuechen2494
@xinyuechen2494 4 ай бұрын
It works! Thank you so much!@@MSFTWebCast
@pichratanak1757
@pichratanak1757 10 ай бұрын
Great Video, but I have got a problem with Tree domain " replication was denied", how to fix it? thk in adv.
@MSFTWebCast
@MSFTWebCast 10 ай бұрын
Might be permissions issue. On tree domain, if you have sign in with tree domain administrator account. you can not force root domain for replication. You can only ask for replication data from root domain. On root domain, you can perform both side replication (to tree domain and from tree domain).
@pichratanak1757
@pichratanak1757 10 ай бұрын
Yes, I understood, and big thk for your advise.
@pg4694
@pg4694 2 жыл бұрын
what is the difference between cdc and tree domain
@MSFTWebCast
@MSFTWebCast 2 жыл бұрын
CDC use the parent domain dns name and in case of tree domain you get new domain dns name.
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
How we enable enterprise admin group in tree forest?
@MSFTWebCast
@MSFTWebCast 2 жыл бұрын
You will find the group in your root domain. You can add one of your admin (of other domain) into enterprise admin group if needed.
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
@@MSFTWebCast thanks for your help
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
I do the procedure but I don't have trust between root domain and tree domain
@MSFTWebCast
@MSFTWebCast 2 жыл бұрын
Tree root trust will create automatically, there is no manually steps required. Can you be more specific about your setup?
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
@@MSFTWebCast I have two DC on root domain. 1 on child domain. 1 on tree domain . On child and tree domain I have two networks cards and I enable rooting . On tree domain I can't resolve the name. . On replication topology as here I don't have the Delhi DC on Bangalore DC
@MSFTWebCast
@MSFTWebCast 2 жыл бұрын
@@theodorosroufis870 I am confused. You mean you have three domains. One Parent Root Domain, one child domain and one tree domain. There will be no direct trust relationship between one child domain and another tree domain within same AD forest. If you are unable to resolve domain dns name then add or create dns conditional forwarding for that domain in DNS. That will fix dns name related issue. Make sure all domains can communicate with other domain using DNS name. If they are not able to do so then use DNS conditional forwarded or dns stub zone to fix it.
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
@@MSFTWebCast thank you I fixed up
@theodorosroufis870
@theodorosroufis870 2 жыл бұрын
When I am trying to create a reverse look up zone. When I try to finish it. Dns failure
@akashmali9137
@akashmali9137 Жыл бұрын
You can video in Hindi
@akashmali9137
@akashmali9137 Жыл бұрын
Making
@pradeeppowduri166
@pradeeppowduri166 2 жыл бұрын
followed similar steps. but unable to ping mylab.local. Any one else seeing same issue or am I missing any thing?
@MSFTWebCast
@MSFTWebCast 2 жыл бұрын
Check DNS servers IP address settings. Try to ping the IP address of DNS Server.
Stay on your way 🛤️✨
00:34
A4
Рет қаралды 23 МЛН
Женская драка в Кызылорде
00:53
AIRAN
Рет қаралды 498 М.
What is Forest , Tree and Domain in Active Directory
13:10
Learn Microsoft Active Directory Advanced skills!
40:37
Andy Malone MVP
Рет қаралды 54 М.
Stay on your way 🛤️✨
00:34
A4
Рет қаралды 23 МЛН