安裝新 Windows Server 2012 Active Directory 森林 (層級 200)Install a New Windows Server 2012 Active Directory Forest (Level 200)

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

本主題解釋的新 Windows Server 2012 Active Directory Domain Services 網域控制站促銷功能簡介層級。This topic explains the new Windows Server 2012 Active Directory Domain Services domain controller promotion feature at an introductory level. 在 Windows Server 2012,AD DS 會取代帶領工具與伺服器管理員及 Windows PowerShell 為基礎的部署系統。In Windows Server 2012, AD DS replaces the Dcpromo tool with a Server Manager and Windows PowerShell-based deployment system.

Active Directory Domain 服務簡化的管理Active Directory Domain Services Simplified Administration

Windows Server 2012 導入下一代 Active Directory Domain 服務簡化管理的而且最根本網域重新構想自 Windows 2000 Server。Windows Server 2012 introduces the next generation of Active Directory Domain Services Simplified Administration, and is the most radical domain re-envisioning since Windows 2000 Server. AD DS 簡化管理拍下全家 Active directory 12 年來,並讓更多可支援、更具彈性、更直覺管理體驗 architects 和系統管理員。AD DS Simplified Administration takes lessons learned from twelve years of Active Directory and makes a more supportable, more flexible, more intuitive administrative experience for architects and administrators. 這是建立現有的技術,以及擴充功能的元件在 Windows Server 2008 R2 推出的最新版本。This meant creating new versions of existing technologies as well as extending the capabilities of components released in Windows Server 2008 R2.

何謂 AD DS 簡化管理嗎?What Is AD DS Simplified Administration?

AD DS 簡化管理是 reimagining 網域部署。AD DS Simplified Administration is a reimagining of domain deployment. 這些功能包括:Some of those features include:

  • AD DS 角色部署現在伺服器管理員架構新的一部分,並且可讓遠端安裝。AD DS role deployment is now part of the new Server Manager architecture and allows remote installation.

  • AD DS 部署和設定引擎時,現在 Windows PowerShell,甚至使用的圖形安裝。The AD DS deployment and configuration engine is now Windows PowerShell, even when using a graphical setup.

  • 立即升級包括必要條件檢查驗證樹系和網域整備新的網域控制站,降低失敗促銷活動的機會。Promotion now includes prerequisite checking that validates forest and domain readiness for the new domain controller, lowering the chance of failed promotions.

  • Windows Server 2012 樹系層級尚未實作新功能和網域功能等級為僅針對新 Kerberos 功能,減輕常用的系統管理員子集需要的功能需要質網域控制站環境。The Windows Server 2012 forest functional level does not implement new features and domain functional level is required only for a subset of new Kerberos features, relieving administrators of the frequent need for a homogenous domain controller environment.

用途與優點Purpose and Benefits

這些變更可能會更加複雜,不簡單。These changes may appear more complex, not simpler. 但重新設計 AD DS 部署程序,有是機會到較少、 變得更容易動作聯合許多步驟與最佳做法的規範。In redesigning the AD DS deployment process though, there was opportunity to coalesce many steps and best practices into fewer, easier actions. 這表示,例如,新的複本網域控制站的圖形設定現在是 8 對話方塊,而非之前的 12。This means, for example, that the graphical configuration of a new replica domain controller is now eight dialogs rather than the previous twelve. 建立新的 Active Directory 樹系需要單一僅限使用 Windows PowerShell 命令引數: 的網域名稱。Creating a new Active Directory forest requires a single Windows PowerShell command with only one argument: the name of the domain.

有為何這類重點放在 Windows Server 2012 中的 Windows PowerShell?Why is there such an emphasis on Windows PowerShell in Windows Server 2012? 隨著分散式運算發展,Windows PowerShell 可設定和維護圖形從命令列介面的單一引擎。As distributed computing evolves, Windows PowerShell allows a single engine for configuration and maintenance from both graphical and command-line interfaces. 它可以讓完整功能指令碼的任何具有相同一流表現元件適用於 IT 專業人員的 API 會授與開發人員。It permits fully featured scripting of any component with the same first class citizenship for an IT Professional that an API grants to developers. 隨著普遍運算以雲端為基礎,Windows PowerShell 也最後帶來的能力的遠端管理的伺服器,其中不圖形介面的電腦具有相同的管理功能當成一個使用的監視器和滑鼠。As cloud-based computing becomes ubiquitous, Windows PowerShell also finally brings the ability to remotely administer a server, where a computer with no graphical interface has the same management capabilities as one with a monitor and mouse.

資深 AD DS 系統管理員應該會看到他們的上一個知識高度相關。A veteran AD DS administrator should find their previous knowledge highly relevant. 開始系統管理員可以找到遠淺學習。A beginning administrator will find a far shallower learning curve.

技術概觀Technical Overview

有哪些您應該要知道您開始之前What You Should Know Before You Begin

本主題假設熟悉的 Active Directory Domain Services,舊版並不提供其用途與功能的基礎詳細資料。This topic assumes familiarity with previous releases of Active Directory Domain Services, and does not provide foundational detail around their purpose and functionality. 如需 AD DS,查看 TechNet 入口網站連結下方頁面:For more information about AD DS, see the TechNet Portal pages linked below:

描述的功能Functional Descriptions

安裝 AD DS 角色AD DS Role Installation


Active Directory Domain Services 安裝會使用伺服器管理員及 Windows PowerShell,例如所有其他伺服器角色與 Windows Server 2012 中的功能。Active Directory Domain Services installation uses Server Manager and Windows PowerShell, like all other server roles and features in Windows Server 2012. Dcpromo.exe 程式不會再提供 GUI 設定選項。The Dcpromo.exe program no longer provides GUI configuration options.

在本機和遠端安裝在伺服器管理員或 ServerManager 模組圖形精靈用於 Windows PowerShell 中。You use a graphical wizard in Server Manager or the ServerManager module for Windows PowerShell in both local and remote installations. 來執行多個那些精靈或 cmdlet 執行個體目標不同的伺服器,您可以將部署 AD DS 多網域控制站同時,全都透過單一的單一主機。By running multiple instances of those wizards or cmdlets and targeting different servers, you can deploy AD DS to multiple domain controllers simultaneously, all from one single console. 雖然這些新功能不是回溯相容性與 Windows Server 2008 R2 或更早版本作業系統,您也仍然可以使用 Dism.exe 應用程式的命令列傳統本機角色安裝在 Windows Server 2008 R2 推出。Although these new features are not backwards compatible with Windows Server 2008 R2 or earlier operating systems, you can also still use the Dism.exe application introduced in Windows Server 2008 R2 for local role installation from the classic command-line.


AD DS 角色設定AD DS Role Configuration


Active Directory Domain Services 設定 「 先前稱為帶領 」 是目前的角色安裝所謂作業。Active Directory Domain Services configuration " previously known as DCPROMO " is a now a discrete operation from role installation. 安裝之後 AD DS 角色,系統管理員可以設定伺服器為網域控制站使用不同的精靈在伺服器管理員中,或使用 ADDSDeployment Windows PowerShell 模組。After installing the AD DS role, an administrator configures the server as a domain controller using a separate wizard within Server Manager or using the ADDSDeployment Windows PowerShell module.

AD DS 角色設定欄位體驗中的 12 個年的組建,並現在設定網域控制站根據最新 Microsoft 最佳做法的規範。AD DS role configuration builds on twelve years of field experience and now configures domain controllers based on the most recent Microsoft best practices. 例如,網域名稱系統 」 和 「 通用目錄安裝每個網域控制站預設。For example, Domain Name System and Global Catalogs install by default on every domain controller.

伺服器管理員 AD DS 設定精靈將許多個人對話方塊合併到較少的提示,並不會再隱藏在 [進階] 模式中的設定。The Server Manager AD DS configuration wizard merges many individual dialogs into fewer prompts and no longer hides settings in an "advanced" mode. 在安裝期間,其中一個展開對話方塊中是整個升級程序。The entire promotion process is in one expanding dialog box during installation. 精靈,並 ADDSDeployment Windows PowerShell 模組顯示值得注意的變更並安全性考量,連結的詳細資訊。The wizard and the ADDSDeployment Windows PowerShell module show you notable changes and security concerns, with links to further information.

Dcpromo.exe 僅命令列自動安裝會留在 Windows Server 2012,並不會再執行圖形安裝精靈中。The Dcpromo.exe remains in Windows Server 2012 for command-line unattended installations only, and no longer runs the graphical installation wizard. 我們建議您停止使用的自動安裝 Dcpromo.exe 並 ADDSDeployment 模組,以取代為現在取代可執行檔將不會包含在下一個版本的 Windows。It is highly recommended that you discontinue use of Dcpromo.exe for unattended installs and replace it with the ADDSDeployment module, as the now-deprecated executable will not be included in the next version of Windows.

這些新功能不是以 Windows Server 2008 R2 或較舊的作業系統回溯相容性。These new features are not backwards compatible to Windows Server 2008 R2 or older operating systems.



Dcpromo.exe 不再包含圖形精靈,並不會再安裝二進位角色或功能。Dcpromo.exe no longer contains a graphical wizard and no longer installs role or feature binaries. 請嘗試執行 Explorer 殼層傳回 Dcpromo.exe:Attempting to run Dcpromo.exe from the Explorer shell returns:

「 Active Directory Domain Services 安裝精靈搬在伺服器管理員中。"The Active Directory Domain Services Installation Wizard is relocated in Server Manager. 如需詳細資訊,請 https://go.microsoft.com/fwlink/?LinkId=220921。」For more information, see https://go.microsoft.com/fwlink/?LinkId=220921."

嘗試執行 Dcpromo.exe / 自動仍然安裝二進位檔,如下所示先前的作業系統,但會警告:Attempting to run Dcpromo.exe /unattend still installs the binaries, as in previous operating systems, but warns:

「 帶領自動的操作取代的 Windows PowerShell 模組 ADDSDeployment。"The dcpromo unattended operation is replaced by the ADDSDeployment module for Windows PowerShell. 如需詳細資訊,請 https://go.microsoft.com/fwlink/?LinkId=220924。」For more information, see https://go.microsoft.com/fwlink/?LinkId=220924."

Windows Server 2012 deprecates dcpromo.exe 並不會包含在未來的 Windows 版本也將它收到關於調節此作業系統。Windows Server 2012 deprecates dcpromo.exe and it will not be included with future versions of Windows, nor will it receive further enhancements in this operating system. 系統管理員應該停止使用,若要建立網域控制站從命令列切換到支援的 Windows PowerShell 模組。Administrators should discontinue its use and switch to the supported Windows PowerShell modules if they wish to create domain controllers from the command-line.

必要條件檢查Prerequisite Checking

網域控制站設定也會實作評估的樹系和網域繼續網域控制站升級之前的必要條件檢查階段。Domain controller configuration also implements a prerequisite checking phase that evaluates the forest and domain prior to continuing with domain controller promotion. 這包括 FSMO 角色可用性、 使用者權限、 延伸的架構相容性及其他需求。This includes FSMO role availability, user privileges, extended schema compatibility and other requirements. 這個新的設計可以減輕位置網域控制站升級開始,然後中止中途島組態嚴重錯誤的問題。This new design alleviates issues where domain controller promotion starts and then halts midway with a fatal configuration error. 這會失去關聯的網域控制站中繼資料森林中的機會減少或不正確認為這伺服器網域控制站。This lessens the chance of orphaned domain controller metadata in the forest or a server that incorrectly believes it is a domain controller.

部署樹系的伺服器管理員Deploying a Forest with Server Manager

本章節如何安裝的第一個網域控制站森林根網域圖形 Windows Server 2012 電腦上使用伺服器管理員中。This section explains how to install the first domain controller in a forest root domain using Server Manager on a graphical Windows Server 2012 computer.

伺服器管理員 AD DS 角色安裝程序Server Manager AD DS Role Installation Process

下圖顯示 Active Directory Domain Services 角色安裝程序,開頭為您執行 ServerManager.exe 和結束網域控制站在升級之前的權限。The diagram below illustrates the Active Directory Domain Services role installation process, beginning with you running ServerManager.exe and ending right before the promotion of the domain controller.


伺服器集區與新增角色Server Pool and Add Roles

從執行伺服器管理員可存取的任何 Windows Server 2012 電腦的符合資格的共用。Any Windows Server 2012 computers accessible from the computer running Server Manager are eligible for pooling. 一旦共用,您選取這些伺服器遠端安裝 AD DS,或在伺服器管理員中可能任何其他設定選項。Once pooled, you select those servers for remote installation of AD DS or any other configuration options possible within Server Manager.

若要新增的伺服器,請選擇下列其中一個動作:To add servers, choose one of the following:

  • 按一下以管理新增其他伺服器在儀表板歡迎畫面的磚Click Add Other Servers to Manage on the dashboard welcome tile

  • 按一下管理功能表,然後選取新增伺服器Click the Manage menu and select Add Servers

  • 以滑鼠右鍵按一下所有伺服器] ,然後選擇 [新增伺服器Right-click All Servers and choose Add Servers

這時新增伺服器對話方塊:This brings up the Add Servers dialog:


這可讓您使用或群組集區中新增伺服器三種方式:This gives you three ways to add servers to the pool for use or grouping:

  • Active Directory 搜尋使用 LDAP (需要電腦所屬的網域、 作業系統篩選可讓和支援萬用字元)Active Directory search (uses LDAP, requires that the computers belong to a domain, allows operating system filtering and supports wildcards)

  • DNS 搜尋 (使用 DNS 別名或 ARP 或 NetBIOS 廣播或 WINS 對應,透過 IP 位址不允許作業系統篩選或支援萬用字元)DNS search (uses DNS alias or IP address via ARP or NetBIOS broadcast or WINS lookup, does not allow operating system filtering or support wildcards)

  • 匯入 (使用伺服器分隔 CR 日 LF 文字檔案清單)Import (uses a text file list of servers separated by CR/LF)

按一下現在尋找返回從該相同的 Active Directory 網域的電腦已經加入的伺服器清單,按一下 [一或多個伺服器名稱,從清單中的伺服器。Click Find Now to return a list of servers from that same Active Directory domain that the computer is joined to, Click one or more server names from the list of servers. 按一下 [新增至伺服器向選取清單中。Click the right arrow to add the servers to the Selected list. 使用新增伺服器]對話方塊中選取的伺服器新增至儀表板角色群組。Use the Add Servers dialog to add selected servers to dashboard role groups. 或按一下 [管理,,然後按一下 [建立伺服器群組,或按一下 [建立伺服器群組儀表板上歡迎伺服器管理員來建立群組自訂伺服器] 磚。Or Click Manage, and then click Create Server Group, or click Create Server Group on the dashboard Welcome to Server Manager tile to create custom server groups.


新增伺服器程序未驗證伺服器是 online 或無障礙。The Add Servers procedure does not validate that a server is online or accessible. 不過,無法存取的任何伺服器旗標管理檢視在伺服器管理員中下, 一步重新整理中However, any unreachable servers flag in the Manageability view in Server Manager at the next refresh

您可以安裝角色遠端任何的 Windows Server 2012 上的電腦新增集區,所示:You can install roles remotely on any Windows Server 2012 computers added the pool, as shown:


您無法完全管理執行 Windows Server 2012 較舊的作業系統的伺服器。You cannot fully manage servers running operating systems older than Windows Server 2012. 新增角色與功能選取項目執行的 ServerManager Windows PowerShell 模組安裝-WindowsFeatureThe Add Roles and Features selection is running ServerManager Windows PowerShell Module Install-WindowsFeature.


您也可以使用現有的網域控制站伺服器管理員儀表板,以選取遠端伺服器 AD DS 安裝角色已經預先選取 AD DS 儀表板磚上按一下滑鼠右鍵,然後選取AD DS 新增另一部伺服器以You can also use the Server Manager Dashboard on an existing domain controller to select remote server AD DS installation with the role already preselected by right clicking the AD DS dashboard tile and selecting Add AD DS to Another Server. 這會叫用安裝-WindowsFeature AD 網域服務This is invoking Install-WindowsFeature AD-Domain-Services.

在電腦執行伺服器管理員集區,本身自動。The computer you are running Server Manager on pools itself automatically. 若要安裝的 AD DS 角色時,只要按一下管理功能表和新增角色與功能To install the AD DS role here, simply click the Manage menu and click Add Roles and Features.


安裝類型Installation Type


安裝類型對話方塊中提供的選項,不支援 Active Directory Domain Services:遠端桌面服務案例-安裝The Installation Type dialog provides an option that does not support Active Directory Domain Services: the Remote Desktop Services scenario based-installation. 這個選項只會在多部伺服器分散式工作負載允許遠端桌面服務。That option only allows Remote Desktop Service in a multi-server distributed workload. 如果您選取它,無法安裝 AD DS。If you select it, AD DS cannot install.

隨時安裝 AD DS 保留就地預設選項:安裝以角色為基礎,或為基礎的功能的Always leave the default selection in place when installing AD DS: Role-based or Feature-based Installation.

伺服器選取項目Server Selection


選擇伺服器對話方塊,可讓您選擇其中一集區之前加入伺服器,只要無障礙。The Server Selection dialog enables you to choose from one of the servers previously added to the pool, as long as it is accessible. 本機伺服器執行伺服器管理員是可供使用。The local server running Server Manager is automatically available.

此外,您可以選擇與 Windows Server 2012 作業系統 HYPER-V VHD 生效和伺服器管理員加入角色它們直接透過服務的元件。In addition, you can select offline Hyper-V VHD files with the Windows Server 2012 operating system and Server Manager adds the role to them directly through component servicing. 這可讓您提供的必要元件 virtual 伺服器才能進一步進行設定。This allows you to provision virtual servers with the necessary components before further configuring them.

伺服器角色與功能Server Roles and Features


選取 [ Active Directory Domain Services如果您想要升級網域控制站的角色。Select the Active Directory Domain Services role if you intend to promote a domain controller. 所有 Active Directory 的管理功能和服務需要自動安裝更新,即使它們是很明顯是另一個角色或不會顯示已選取在伺服器管理員介面。All Active Directory administration features and required services install automatically, even if they are ostensibly part of another role or do not appear selected in the Server Manager interface.

伺服器管理員也會顯示此角色隱含安裝; 的管理功能的資訊] 對話方塊這是相當於-IncludeManagementTools引數。Server Manager also presents an informational dialog that shows which management features this role implicitly installs; this is equivalent to the -IncludeManagementTools argument.



其他功能可以在此處加入像您想要。Additional Features can be added here as desired.

Active Directory Domain ServicesActive Directory Domain Services


Active Directory Domain Services對話方塊需求與最佳做法提供有限的資訊。The Active Directory Domain Services dialog provides limited information on requirements and best practices. 確認您選擇 AD DS 角色為主要做 」 這個畫面未顯示,如果您未選取 AD DS。It mainly acts as a confirmation that you chose the AD DS role " if this screen does not appear, you did not select AD DS.



確認對話方塊是檢查最後一個點之前的角色安裝開始。The Confirmation dialog is the final checkpoint before role installation starts. 它所提供的選項開機視角色安裝之後,但 AD DS 安裝並不需要重新開機。It offers an option to restart the computer as needed after role installation, but AD DS installation does not require a reboot.

按一下安裝,即可開始安裝角色您確認。By clicking Install, you confirm you are ready to begin role installation. 開始後,您就無法取消安裝角色。You cannot cancel a role installation once it begins.



結果對話方塊中顯示目前安裝進度和目前安裝的狀態。The Results dialog shows the current installation progress and current installation status. 安裝角色持續無論是否伺服器管理員已關閉。Role installation continues regardless of whether Server Manager is closed.

安裝結果驗證仍是最好的作法。Verifying the installation results is still a best practice. 如果您關閉結果對話方塊安裝完成之前,您可以檢查伺服器管理員通知旗標結果。If you close the Results dialog before installation completes, you can check the results using the Server Manager notification flag. 伺服器管理員也會顯示一則警告訊息的任何已安裝 AD DS 角色但進一步並未設定為網域控制站伺服器。Server Manager also shows a warning message for any servers that have installed the AD DS role but not been further configured as domain controllers.

工作的通知Task Notifications


AD DS 詳細資料AD DS Details


工作的詳細資料Task Details


升級為網域控制站Promote to Domain Controller


結尾的角色安裝 AD DS,您可以繼續進行設定使用這個網域控制站伺服器升級連結。At the end of the AD DS role installation, you can continue with configuration by using the Promote this server to a domain controller link. 這必要伺服器網域控制站,但不一定要立即執行設定精靈。This is required to make the server a domain controller, but is not necessary to run the configuration wizard immediately. 例如您可能只想要提供使用的 AD DS 二進位檔案伺服器之前將它們傳送到另一個分公司較新的設定。For example, you may only want to provision servers with the AD DS binaries before sending them to another branch office for later configuration. 透過新增 AD DS 角色交貨之前,您儲存當到達目的地的時間。By adding the AD DS role before shipping, you save time when it reaches its destination. 您也可以依照不天或星期保持 offline 網域控制站的最佳做法。You also follow the best practice of not keeping a domain controller offline for days or weeks. 最後,這可讓您更新元件之前網域控制站升級,儲存您的後續重新開機至少一次。Finally, this enables you to update components before domain controller promotion, saving you at least one subsequent reboot.

選取此連結稍後會叫用 ADDSDeployment cmdlet:安裝-addsforest安裝-addsdomain,或安裝-addsdomaincontrollerSelecting this link later invokes the ADDSDeployment cmdlets: install-addsforest, install-addsdomain, or install-addsdomaincontroller.


移除 AD DS 角色像任何其他的角色,無論您是否升級為網域控制站伺服器。You remove the AD DS role like any other role, regardless of whether you promoted the server to a domain controller. 不過,移除 AD DS 角色需要重新開機完成。However, removing the AD DS role requires a restart on completion.

Active Directory Domain Services 角色移除點不同安裝,在它需要網域控制站降級,才能完成。Active Directory Domain Services role removal is different from installation, in that it requires domain controller demotion before it can complete. 這是必要以避免網域控制站其解除安裝,而不適當的中繼資料清除森林中的角色二進位檔。This is necessary to prevent a domain controller from having its role binaries uninstalled without proper metadata cleanup in the forest. 如需詳細資訊,請查看降級網域控制站和網域和 #40;層級 200 和 #41;.For more information, see Demoting Domain Controllers and Domains (Level 200).


升級為網域控制站不支援後將會防止伺服器通常會開機,請移除 Dism.exe 或 Windows PowerShell DISM 模組 AD DS 角色。Removing the AD DS roles with Dism.exe or the Windows PowerShell DISM module after promotion to a Domain Controller is not supported and will prevent the server from booting normally.

伺服器管理員與或不同的 Windows PowerShell 模組 AD DS 部署,DISM 是原生維護系統有既有不知道 AD DS 或其設定。Unlike Server Manager or the AD DS Deployment module for Windows PowerShell, DISM is a native servicing system that has no inherent knowledge of AD DS or its configuration. 請勿使用 Dism.exe 或 Windows PowerShell DISM 模組除非伺服器不再網域控制站解除安裝 AD DS 角色。Do not use Dism.exe or the Windows PowerShell DISM module to uninstall the AD DS role unless the server is no longer a domain controller.

建立 AD DS 森林根網域與伺服器管理員Create an AD DS Forest Root Domain with Server Manager

下圖顯示 Active Directory Domain Services 設定程序,如此,您先前安裝 AD DS 角色並開始在Active Directory Domain Services 組態精靈使用伺服器管理員。The following diagram illustrates the Active Directory Domain Services configuration process, in the case where you have previously installed the AD DS role and started the Active Directory Domain Services Configuration Wizard using Server Manager.


部署設定Deployment Configuration


伺服器管理員會開始使用每個網域控制站升級部署組態頁面。Server Manager begins every domain controller promotion with the Deployment Configuration page. 剩餘的選項與所需的欄位變更此頁面上,後續的部署操作根據您選擇的頁面。The remaining options and required fields change on this page and subsequent pages, depending on which deployment operation you select.

若要建立新的 Active Directory 森林,請按一下新增新的樹系To create a new Active Directory forest, click Add a new forest. 您必須提供有效的根網域名稱。名稱無法單一標示 (必須名稱,例如contoso.com或類似和不只是以 contoso) 必須使用允許的 DNS 網域命名需求。You must provide a valid root domain name; the name cannot be single-labeled (for example, the name must be contoso.com or similar and not just contoso) and must use allowed DNS domain naming requirements.

如需有關有效的網域名稱,查看知識庫文章適用於電腦、 網域、 網站及 Ou 命名 Active Directory 規格For more information on valid domain names, see KB article Naming conventions in Active Directory for computers, domains, sites, and OUs.


無法建立新的 Active Directory 樹系的外部 DNS 名稱相同的名稱。Do not create new Active Directory forests with the same name as an external DNS name. 例如 http://contoso.com DNS URL 網際網路時,您必須選擇不同的名稱為內部樹系避免未來的相容性問題。For example, if your Internet DNS URL is http://contoso.com, you must choose a different name for your internal forest to avoid future compatibility issues. 該名稱應該唯一和網路流量的。That name should be unique and unlikely for web traffic. 例如: corp.contoso.com。For example: corp.contoso.com.

新的樹系的網域中的系統管理員 account 就不需要新的認證。A new forest does not need new credentials for the domain's Administrator account. 網域控制站升級程序使用來自第一次用來建立樹系根的網域控制站建的認證。The domain controller promotion process uses the credentials of the built-in Administrator account from the first domain controller used to create the forest root. 就不 (預設) 來停用或鎖定建,可能會樹系的唯一的進入點的系統管理網域帳號會進入不穩定。There is no way (by default) to disable or lock out the built-in Administrator account and it may be the only entry point into a forest if the other administrative domain accounts are unusable. 請務必部署新的樹系之前必須知道的密碼。It is critical to know the password before deploying a new forest.

網域名稱需要有效的完整的網域 DNS 名稱,就需要。DomainName requires a valid fully qualified domain DNS name and is required.

網域控制站選項Domain Controller Options


網域控制站選項可讓您設定樹系功能等級網域功能等級新的樹系根網域。The Domain Controller Options enables you to configure the forest functional level and domain functional level for the new forest root domain. 根據預設,這些設定的新的樹系根網域中的 Windows Server 2012。By default, these settings are Windows Server 2012 in a new forest root domain. Windows Server 2012 的樹系功能等級透過 Windows Server 2008 R2 的樹系功能等級不提供任何新的功能。The Windows Server 2012 forest functional level does not provide any new functionality over the Windows Server 2008 R2 forest functional level. 只為了實作新 Kerberos 設定所需的 Windows Server 2012 網域功能等級 [永遠提供宣告 」 和 「 失敗護身的驗證要求 」。The Windows Server 2012 domain functional level is required only in order to implement the new Kerberos settings "always provide claims" and "Fail unarmored authentication requests." Windows Server 2012 中功能層級的主要使用是限制需求允許的最小作業系統的網域控制站參與。A primary use for functional levels in Windows Server 2012 is to restrict participation in the domain to domain controllers that meet minimum-allowed operating system requirements. 亦即,您可以指定 Windows Server 2012 網域功能層級只網域控制站執行 Windows Server 2012 可以裝載網域。In other words, you can specify Windows Server 2012 domain functional level only domain controllers that run Windows Server 2012 can host the domain. Windows Server 2012 實作新的網域控制站標幟稱為DS_WIN8_REQUIREDDSGetDcName功能的專屬找出 Windows Server 2012 網域控制站的 NetLogon。Windows Server 2012 implements a new domain controller flag called DS_WIN8_REQUIRED in the DSGetDcName function of NetLogon that exclusively locates Windows Server 2012 domain controllers. 這可讓您的網域控制站在執行作業系統的允許,則多同或異質性樹系彈性。This allows you the flexibility of a more homogeneous or heterogeneous forest in terms of which operating systems are permitted to be run on domain controllers.

如需網域控制站的位置,檢視Directory 服務功能For more information about domain controller Location, review Directory Service Functions.

僅限可設定的網域控制站功能是 [DNS 伺服器] 選項。The only configurable domain controller capability is the DNS server option. Microsoft 建議所有網域控制站都提供 DNS 服務的可用性分散式的環境中,這是安裝任何模式或網域中的網域控制站預設選取此選項的原因。Microsoft recommends that all domain controllers provide DNS services for high availability in distributed environments, which is why this option is selected by default when installing a domain controller in any mode or domain. 通用和朗讀只網域控制站選項時,會無法使用建立新的樹系根網域。第一次網域控制站必須 GC、,且無法讀取只有網域控制站 (RODC)。The Global Catalog and read only domain controller options are unavailable when creating a new forest root domain; the first domain controller must be a GC, and cannot be a read only domain controller (RODC).

指定Directory 服務還原模式密碼必須遵守密碼原則套用到伺服器,預設不需要穩固密碼。僅限非空白一個。The specified Directory Services Restore Mode Password must adhere to the password policy applied to the server, which by default does not require a strong password; only a non-blank one. 隨時複雜的密碼或最好複雜密碼。Always choose a strong, complex password or preferably, a passphrase.

DNS 選項],然後 DNS 的認證委派DNS Options and DNS Delegation Credentials


DNS 選項頁面上可讓您設定 DNS 委派,並提供其他 DNS 系統管理員認證。The DNS Options page enables you to configure DNS delegation and provide alternate DNS administrative credentials.

您無法設定 DNS 選項或委派 Active Directory Domain Services 組態精靈中安裝新 Active Directory 森林根網域何處選取的 DNS 伺服器網域控制站選項頁面。You cannot configure DNS options or delegation in the Active Directory Domain Services Configuration Wizard when installing a new Active Directory Forest Root Domain where you selected the DNS server on the Domain Controller Options page. 建立 DNS 委派選項時,使用現有的 DNS 伺服器基礎結構中建立新的樹系根 DNS 區域。The Create DNS delegation option is available when creating a new forest root DNS zone in an existing DNS server infrastructure. 此選項可讓您提供其他 DNS 管理認證已更新 DNS 區域的權限。This option enables you to provide alternate DNS administrative credentials that have the rights to update DNS zone.

如需有關您是否需要建立 DNS 委派的詳細資訊,請查看了解區域委派For more information about whether you need to create a DNS delegation, see Understanding Zone Delegation.

其他選項Additional Options


的其他選項頁面顯示 NetBIOS 的網域名稱,可讓您撤銷它。The Additional Options page shows the NetBIOS name of the domain and enables you to override it. 根據預設,NetBIOS 網域名稱符合上所提供的完整的網域名稱的最左邊標籤部署組態頁面。By default, the NetBIOS domain name matches the left-most label of the fully qualified domain name provided on the Deployment Configuration page. 例如,如果您提供 corp.contoso.com 的完整的網域名稱,預設 NetBIOS 網域名稱是 CORP.For example, if you provided the fully qualified domain name of corp.contoso.com, the default NetBIOS domain name is CORP.

如果 15 字元名稱或較少並不會衝突另一個 NetBIOS 名稱,這是不變。If the name is 15 characters or less and does not conflict with another NetBIOS name, it is unaltered. 如果它能與其他 NetBIOS 名稱衝突,數字會附加的名稱。If it does conflict with another NetBIOS name, a number is appended to the name. 如果超過 15 字元名稱,精靈將會提供唯一、 被截斷的建議。If the name is more than 15 characters, the wizard provides a unique, truncated suggestion. 不論,精靈先驗證名稱未在使用透過 WINS 查詢,NetBIOS 廣播。In either case, the wizard first validates the name is not already in use via a WINS lookup and NetBIOS broadcast.

如需有關有效的網域名稱,查看知識庫文章適用於電腦、 網域、 網站及 Ou 命名 Active Directory 規格For more information on valid domain names, see KB article Naming conventions in Active Directory for computers, domains, sites, and OUs.



路徑頁面上,可讓您覆寫預設資料夾位置的 AD DS 資料庫中資料庫交易登,並 SYSVOL 分享。The Paths page enables you to override the default folder locations of the AD DS database, the database transaction logs, and the SYSVOL share. 預設位置都在之 %systemroot (亦即 C:\Windows)。The default locations are always in subdirectories of %systemroot% (i.e. C:\Windows).

檢視選項],然後檢視指令碼Review Options and View Script


評論選項頁面上可讓您驗證您的設定,並確保您開始安裝之前,先符合您的需求。The Review Options page enables you to validate your settings and ensure they meet your requirements before you start the installation. 這不是一個機會停止使用伺服器管理員安裝。This is not the last opportunity to stop the installation when using Server Manager. 這是只要之前繼續進行設定,請先確認您的設定選項This is simply an option to confirm your settings before continuing the configuration

評論選項在伺服器管理員頁面也提供選擇性檢視指令碼按鈕,以建立包含目前 ADDSDeployment 設定成單一的 Windows PowerShell 指令碼 Unicode 文字檔案。The Review Options page in Server Manager also offers an optional View Script button to create a Unicode text file that contains the current ADDSDeployment configuration as a single Windows PowerShell script. 這可讓您在伺服器管理員圖形介面作為 Windows PowerShell 部署 studio。This enables you to use the Server Manager graphical interface as a Windows PowerShell deployment studio. 若要設定選項,匯出設定,然後取消精靈使用 Active Directory Domain Services 組態精靈。Use the Active Directory Domain Services Configuration Wizard to configure options, export the configuration, and then cancel the wizard. 此程序會建立進一步修改或直接使用有效且語法正確範例。This process creates a valid and syntactically correct sample for further modification or direct use. 例如:For example:

# Windows PowerShell Script for AD DS Deployment  

Import-Module ADDSDeployment  
Install-ADDSForest `  
-CreateDNSDelegation `  
-DatabasePath "C:\Windows\NTDS" `  
-DomainMode "Win2012" `  
-DomainName "corp.contoso.com" `  
-DomainNetBIOSName "CORP" `  
-ForestMode "Win2012" `  
-InstallDNS:$true `  
-LogPath "C:\Windows\NTDS" `  
-NoRebootOnCompletion:$false `  
-SYSVOLPath "C:\Windows\SYSVOL"  


伺服器管理員通常會填入所有引升級後不會依賴預設值 (因為它們可能會改變之間未來版本 Windows 的 service pack) 的值。Server Manager generally fills in all arguments with values when promoting and does not rely on defaults (as they may change between future versions of Windows or service packs). 有一個例外此-safemodeadministratorpassword (在故意的指令碼省略) 引數。The one exception to this is the -safemodeadministratorpassword argument (which is deliberately omitted from the script). 若要強制確認的提示,請執行 cmdlet 互動時省略值。To force a confirmation prompt, omit the value when running cmdlet interactively.

必要條件核取Prerequisites Check


請必要條件是 AD DS 網域設定中的新功能。The Prerequisites Check is a new feature in AD DS domain configuration. 這個新階段驗證伺服器設定可以新 AD DS 樹系的支援。This new phase validates that the server configuration is capable of supporting a new AD DS forest.

當您安裝新的樹系根網域,伺服器管理員 Active Directory Domain Services 組態精靈會叫用一系列模組測試。When installing a new forest root domain, the Server Manager Active Directory Domain Services Configuration Wizard invokes a series of modular tests. 這些測試提醒建議的修復選項。These tests alert you with suggested repair options. 您可以視需要執行測試。You can run the tests as many times as required. 無法繼續網域控制站程序,直到所有必要條件測試傳遞。The domain controller process cannot continue until all prerequisite tests pass.

請必要條件也會呈現相關資訊,例如安全性變更會影響較舊的作業系統。The Prerequisites Check also surfaces relevant information such as security changes that affect older operating systems.

如需有關的特定的必要條件檢查的詳細資訊,請查看必要條件檢查For more information on the specific prerequisite checks, see Prerequisite Checking.



安裝頁面會顯示,網域控制站設定開始和無法終止或取消。When the Installation page displays, the domain controller configuration begins and cannot be halted or canceled. 詳細的作業會顯示在此頁面上,而且寫入登:Detailed operations display on this page and are written to logs:

  • %systemroot%\debug\dcpromo.log%systemroot%\debug\dcpromo.log

  • %systemroot%\debug\dcpromoui.log%systemroot%\debug\dcpromoui.log


您可以從同一部主機伺服器管理員中同時執行多個角色安裝和 AD DS 設定精靈。You can run multiple role installation and AD DS configuration wizards from the same Server Manager console simultaneously.



結果頁面會顯示成功或失敗的升級與管理的任何重要資訊。The Results page shows the success or failure of the promotion and any important administrative information. 網域控制站將會自動重新開機之後 10 秒。The domain controller will automatically reboot after 10 seconds.

部署 Windows PowerShell 中的樹系Deploying a Forest with Windows PowerShell

本章節如何安裝森林根網域核心 Windows Server 2012 的電腦上使用 Windows PowerShell 中的第一個網域控制站。This section explains how to install the first domain controller in a forest root domain using Windows PowerShell on a Core Windows Server 2012 computer.

Windows PowerShell AD DS 角色安裝程序Windows PowerShell AD DS Role Installation Process

執行的幾個簡單 ServerManager 部署 cmdlet 到您的部署程序,您進一步了解的 AD DS 簡化管理。By implementing a few straightforward ServerManager deployment cmdlets into your deployment processes, you further realize the vision of AD DS simplified administration.

下圖顯示 Active Directory Domain Services 角色安裝程序,開頭為您執行的PowerShell.exe和結束網域控制站在升級之前的權限。The next figure illustrates the Active Directory Domain Services role installation process, beginning with you running PowerShell.exe and ending right before the promotion of the domain controller.


ServerManager CmdletServerManager Cmdlet 引數 (粗體所需的引數。Arguments (Bold arguments are required. 斜體引數可以使用 Windows PowerShell 或 AD DS 設定精靈指定。)Italicized arguments can be specified by using Windows PowerShell or the AD DS Configuration Wizard.)
安裝-WindowsFeature 日新增-WindowsFeatureInstall-WindowsFeature/Add-WindowsFeature 名稱-Name











一些不需要,引數-IncludeManagementTools我們建議安裝 AD DS 角色二進位檔While not required, the argument -IncludeManagementTools is highly recommended when installing the AD DS role binaries

ServerManager 模組的 Windows PowerShell 公開角色安裝、 狀態,並移除的部分新 DISM 模組。The ServerManager module exposes role installation, status, and removal portions of the new DISM module for Windows PowerShell. 這個層簡化最工作並減少強大 (但時濫用危險) 直接使用量需要 DISM 模組。This layering simplifies the most tasks and reduces need for direct usage of the powerful (but dangerous when misused) DISM module.

使用Get 命令將別名和中 ServerManager cmdlet 匯出。Use Get-Command to export the aliases and cmdlets in ServerManager.

Get-Command -module ServerManager  

例如:For example:


若要新增的 Active Directory Domain Services 角色,只要執行安裝-WindowsFeature與引數 AD DS 角色名稱。To add the Active Directory Domain Services role, simply run the Install-WindowsFeature with the AD DS role name as an argument. 伺服器管理員,例如所有所需的服務隱含到 AD DS 角色自動安裝更新。Like Server Manager, all required services implicit to the AD DS role install automatically.

Install-WindowsFeature -name AD-Domain-Services  

如果您也可以安裝-AD DS 管理工具,這會建議-然後提供-IncludeManagementTools引數:If you also want the AD DS management tools installed - and this is highly recommended - then provide the -IncludeManagementTools argument:

Install-WindowsFeature -name AD-Domain-Services -IncludeManagementTools  

例如:For example:


請列出所有的功能與他們安裝狀態的角色,使用取得-WindowsFeature不引數。To list all features and roles with their installation status, use Get-WindowsFeature without arguments. 指定電腦名稱的安裝狀態從遠端伺服器引數。Specify -ComputerName argument for the installation status from a remote server.


因為取得-WindowsFeature不需要篩選機制,您必須使用Where-object以管線尋找特定的功能。Because Get-WindowsFeature does not have a filtering mechanism, you must use Where-Object with a pipeline to find specific features. 管線之間傳送資料的多個 cmdlet 所使用的通道,而且 where-object 做為篩選。The pipeline is a channel used between multiple cmdlets to pass data and the Where-Object cmdlet acts as a filter. $_變數做為通過該光碟可能包含任何屬性管線目前物件。The built-in $_ variable acts as the current object passing through the pipeline with any properties it may contain.

Get-WindowsFeature | where-object <options>  

例如,尋找所有功能包含 「 作用中 Dir 」 中的顯示名稱屬性,使用:For example, to find all features containing "Active Dir" in their Display Name property, use:

Get-WindowsFeature | where displayname -like "*active dir*"  

進一步的範例如下所示:Further examples illustrated below:


如需更多的 Windows PowerShell 作業管線與 Where-object 的詳細資訊,請查看傳送及 Windows PowerShell 中的管線For more information about more Windows PowerShell operations with pipelines and Where-Object, see Piping and the Pipeline in Windows PowerShell.

請注意,Windows PowerShell 3.0 大幅簡化的命令列需要這項操作管線引數。Note also that Windows PowerShell 3.0 significantly simplified the command-line arguments needed in this pipeline operation. Windows PowerShell 2.0 您必須:Windows PowerShell 2.0 would have required:

Get-WindowsFeature | where {$_.displayname - like "*active dir*"}  

您可以使用 Windows PowerShell 管線,建立可讀取的結果。By using the Windows PowerShell pipeline, you can create readable results. 例如:For example:

Install-WindowsFeature | Format-List  
Install-WindowsFeature | select-object | Format-List  


請注意如何使用選取物件cmdlet 的-expandproperty引數傳回有趣的資料:Note how using the Select-Object cmdlet with the -expandproperty argument returns interesting data:



選擇物件-expandproperty引數速度變慢整體安裝效能稍微。The Select-Object -expandproperty argument slows down overall installation performance slightly.

使用 Windows PowerShell 建立 AD DS 森林根網域Create an AD DS Forest Root Domain with Windows PowerShell

若要安裝新的 Active Directory 森林使用 ADDSDeployment 模組,使用下列 cmdlet:To install a new Active Directory forest using the ADDSDeployment module, use the following cmdlet:


安裝-AddsForest cmdlet 僅有兩個階段 (必要條件檢查並安裝)。The Install-AddsForest cmdlet only has two phases (prerequisite checking and installation). 有兩個下方的數據會顯示安裝階段的最低的必要引數的網域名稱The two figures below show the installation phase with the minimum required argument of -domainname.

ADDSDeployment CmdletADDSDeployment Cmdlet 引數 (粗體所需的引數。Arguments (Bold arguments are required. 斜體引數可以使用 Windows PowerShell 或 AD DS 設定精靈指定。)Italicized arguments can be specified by using Windows PowerShell or the AD DS Configuration Wizard.)
安裝-AddsforestInstall-Addsforest -確認-Confirm



















-DomainNetBIOSName如果您想要變更自動根據 DNS 網域名稱前置詞的 15 字元名稱或名稱超過 15 字元,則需要引數。The -DomainNetBIOSName argument is required if you want to change the automatically generated 15-character name based on the DNS domain name prefix or if the name exceeds 15 characters.

伺服器管理員相當於部署組態ADDSDeployment cmdlet 和引數:The equivalent Server Manager Deployment Configuration ADDSDeployment cmdlet and arguments are:

-DomainName <string>  

相當於伺服器管理員網域控制站選項 ADDSDeployment cmdlet 引數︰The equivalent Server Manager Domain Controller Options ADDSDeployment cmdlet arguments are:

-ForestMode <{Win2003 | Win2008 | Win2008R2 | Win2012 | Default}>  
-DomainMode <{Win2003 | Win2008 | Win2008R2 | Win2012 | Default}>  
-InstallDNS <{$false | $true}>  
-SafeModeAdministratorPassword <secure string>  

安裝-ADDSForest如果您不指定引數請遵循相同的預設值為伺服器管理員。The Install-ADDSForest arguments follow the same defaults as Server Manager if not specified.

SafeModeAdministratorPassword引數的作業會特殊:The SafeModeAdministratorPassword argument's operation is special:

  • 如果未指定引數,cmdlet 會提示您輸入並確認遮罩的密碼。If not specified as an argument, the cmdlet prompts you to enter and confirm a masked password. 執行 cmdlet 互動時,這是慣用的使用方式。This is the preferred usage when running the cmdlet interactively.

    例如,建立新的樹系名 corp.contoso.com,並提示您輸入並確認密碼遮罩:For example, to create a new forest named corp.contoso.com and be prompted to enter and confirm a masked password:

    Install-ADDSForest "DomainName corp.contoso.com  
  • 如果指定的值,,值必須安全字串。If specified with a value, the value must be a secure string. 執行 cmdlet 互動時,這是不慣用的使用方式。This is not the preferred usage when running the cmdlet interactively.

例如,您可以手動提示密碼使用朗讀主機cmdlet 提示安全字串的使用者:For example, you can manually prompt for a password by using the Read-Host cmdlet to prompt the user for a secure string:

-safemodeadministratorpassword (read-host -prompt "Password:" -assecurestring)  


在前一個選項不會確認密碼、 小心謹慎: 看不到密碼。As the previous option does not confirm the password, use extreme caution: the password is not visible.

您也可以提供安全字串為轉換明文變數,雖然這是非常不建議使用。You can also provide a secure string as a converted clear-text variable, although this is highly discouraged.

-safemodeadministratorpassword (convertto-securestring "Password1" -asplaintext -force)  

最後,您可能會將模糊的密碼儲存在檔案,並再重複使用之後,清除文字並不會顯示密碼。Finally, you could store the obfuscated password in a file, and then reuse it later, without the clear text password ever appearing. 例如:For example:

$file = "c:\pw.txt"  
$pw = read-host -prompt "Password:" -assecurestring  
$pw | ConvertFrom-SecureString | Set-Content $file  

-safemodeadministratorpassword (Get-Content $File | ConvertTo-SecureString)  


不建議提供或儲存清除或模糊文字密碼。Providing or storing a clear or obfuscated text password is not recommended. 任何人指令碼執行這個命令或在您身邊尋找知道網域控制站 DSRM 的密碼。Anyone running this command in a script or looking over your shoulder knows the DSRM password of that domain controller. 任何人的存取權檔案無法反向模糊的密碼。Anyone with access to the file could reverse that obfuscated password. 有了這個認知,他們可以登入以 DSRM 開始 DC 及最後模擬網域控制站本身他們的權限提高 Active Directory 森林中的最高層級。With that knowledge, they can logon to a DC started in DSRM and eventually impersonate the domain controller itself, elevating their privileges to the highest level in an Active Directory forest. 步驟使用另一組System.Security.Cryptography來將檔案加密資料建議但是超出範圍。An additional set of steps using System.Security.Cryptography to encrypt the text file data is advisable but out of scope. 最好的做法是完全避免儲存的密碼。The best practice is to totally avoid password storage.

ADDSDeployment cmdlet 提供略過 DNS client 設定、 轉送程式,以及根提示自動設定的其他選項。The ADDSDeployment cmdlet offers an additional option to skip automatic configuration of DNS client settings, forwarders, and root hints. 您不能略過此組態選項時使用伺服器管理員。You cannot skip this configuration option when using Server Manager. 此引數重要只有當您在安裝前設定的網域控制站伺服器的 DNS 伺服器角色:This argument matters only if you installed the DNS Server role prior to configuring the domain controller:


DomainNetBIOSName也是特殊操作:The DomainNetBIOSName operation is also special:

  • 如果DomainNetBIOSName未使用 NetBIOS 的網域名稱和單一標籤前置詞網域中的名稱指定引數網域名稱、 15 字元或較少,然後升級繼續使用自動的名稱。If the DomainNetBIOSName argument is not specified with a NetBIOS domain name and the single-label prefix domain name in the DomainName argument is 15 characters or fewer, then promotion continues with an automatically generated name.

  • 如果DomainNetBIOSName未使用 NetBIOS 的網域名稱和單一標籤前置詞網域中的名稱指定引數網域名稱、 16 字元或更多,然後升級失敗。If the DomainNetBIOSName argument is not specified with a NetBIOS domain name and the single-label prefix domain name in the DomainName argument is 16 characters or more, then promotion fails.

  • 如果DomainNetBIOSName指定引數 NetBIOS 網域名稱的 15 字元或較少,然後升級繼續指定名稱。If the DomainNetBIOSName argument is specified with a NetBIOS domain name of 15 characters or fewer, then promotion continues with that specified name.

  • 如果DomainNetBIOSName指定引數字元 16 NetBIOS 網域名稱或更多,然後升級失敗。If the DomainNetBIOSName argument is specified with a NetBIOS domain name of 16 characters or more, then promotion fails.

相當於伺服器管理員其他選項 ADDSDeployment cmdlet 引數是:The equivalent Server Manager Additional Options ADDSDeployment cmdlet argument is:

-domainnetbiosname <string>  

伺服器管理員相當於路徑ADDSDeployment cmdlet 引數:The equivalent Server Manager Paths ADDSDeployment cmdlet arguments are:

-databasepath <string>  
-logpath <string>  
-sysvolpath <string>  

使用選擇性Whatif以引數安裝-ADDSForest cmdlet 檢視設定的資訊。Use the optional Whatif argument with the Install-ADDSForest cmdlet to review configuration information. 這可讓您查看明確和隱含 cmdlet 的引數的值。This enables you to see the explicit and implicit values of a cmdlet's arguments.

例如:For example:


您無法略過必要條件檢查時使用伺服器管理員中,但您可以跳過此程序使用 [使用下列引數 AD DS 部署 cmdlet 時:You cannot bypass the Prerequisite Check when using Server Manager, but you can skip the process when using the AD DS Deployment cmdlet using the following argument:



Microsoft 會阻礙重覆它會導致部分網域控制站升級或損壞 AD DS 森林略過必要條件檢查。Microsoft discourages skipping the prerequisite check as it can lead to a partial domain controller promotion or damaged AD DS forest.

請注意,就像伺服器管理員中,安裝-ADDSForest ,升級將會自動重新開機伺服器提醒您。Note how, just like Server Manager, Install-ADDSForest reminds you that promotion will reboot the server automatically.



若要自動接受重新開機命令提示字元中,使用-強制-確認: $false的任何 ADDSDeployment Windows PowerShell cmdlet 引數。To accept the reboot prompt automatically, use the -force or -confirm:$false arguments with any ADDSDeployment Windows PowerShell cmdlet. 若要防止伺服器促銷結尾自動重新開機,使用-norebootoncompletion引數。To prevent the server from automatically rebooting at the end of promotion, use the -norebootoncompletion argument.


覆寫在重新開機,建議。Overriding the reboot is discouraged. 網域控制站必須重新開機才能正確運作。The domain controller must reboot to function correctly.

也了See Also

Active Directory Domain Services (TechNet 入口網站)Active Directory Domain Services (TechNet Portal)
Windows Server 2008 R2 的 active Directory Domain ServicesActive Directory Domain Services for Windows Server 2008 R2
Windows Server 2008 的 active Directory Domain ServicesActive Directory Domain Services for Windows Server 2008
Windows Server Technical 參考資料 (Windows Server 2003)Windows Server Technical Reference (Windows Server 2003)
Active Directory 系統管理員中心: 快速入門 (Windows Server 2008 R2)Active Directory Administrative Center: Getting Started (Windows Server 2008 R2)
Active Directory 管理,使用 Windows PowerShell (Windows Server 2008 R2)Active Directory Administration with Windows PowerShell (Windows Server 2008 R2)
詢問 Directory 服務小組 (官方的 Microsoft 廣告技術支援部落格)Ask the Directory Services Team (Official Microsoft Commercial Technical Support Blog)