安裝複本 Windows Server 2012 網域控制站在現有的網域 (層級 200)Install a Replica Windows Server 2012 Domain Controller in an Existing Domain (Level 200)

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

本主題涵蓋將現有的樹系或網域升級到 Windows Server 2012,使用 Windows PowerShell 或伺服器管理員所需的步驟。This topic covers the steps necessary to upgrade an existing forest or domain to Windows Server 2012, using either Server Manager or Windows PowerShell. 它涵蓋如何加入網域控制站執行 Windows Server 2012 加入現有的網域。It covers how to add domain controllers that run Windows Server 2012 to an existing domain.

升級及複本工作流程Upgrade and Replica Workflow

下圖顯示 Active Directory Domain Services 設定程序,當您之前已經安裝 AD DS 角色,以及您已經開始進行 Active Directory Domain Services 組態精靈使用現有的網域中建立新的網域控制站伺服器管理員。The following diagram illustrates the Active Directory Domain Services configuration process when you previously installed the AD DS role and you have started the Active Directory Domain Services Configuration Wizard using Server Manager to create a new domain controller in an existing domain.

安裝複本

升級及複本 Windows PowerShellUpgrade and Replica Windows PowerShell

ADDSDeployment CmdletADDSDeployment Cmdlet 引數 (粗體所需的引數。Arguments (Bold arguments are required. 斜體引數可以使用 Windows PowerShell 或 AD DS 設定精靈指定。)Italicized arguments can be specified by using Windows PowerShell or the AD DS Configuration Wizard.)
安裝-AddsDomainControllerInstall-AddsDomainController -SkipPreChecks-SkipPreChecks

-網域名稱-DomainName

-SafeModeAdministratorPassword-SafeModeAdministratorPassword

-站台名稱-SiteName

-ADPrepCredential-ADPrepCredential

-ApplicationPartitionsToReplicate-ApplicationPartitionsToReplicate

-AllowDomainControllerReinstall-AllowDomainControllerReinstall

-確認-Confirm

-CreateDNSDelegation-CreateDNSDelegation

認證-Credential

-CriticalReplicationOnly-CriticalReplicationOnly

-DatabasePath-DatabasePath

-DNSDelegationCredential-DNSDelegationCredential

-推動-Force

-InstallationMediaPath-InstallationMediaPath

-InstallDNS-InstallDNS

-LogPath-LogPath

-MoveInfrastructureOperationMasterRoleIfNecessary-MoveInfrastructureOperationMasterRoleIfNecessary

-NoDnsOnNetwork-NoDnsOnNetwork

-NoGlobalCatalog-NoGlobalCatalog

-Norebootoncompletion-Norebootoncompletion

-ReplicationSourceDC-ReplicationSourceDC

-SkipAutoConfigureDNS-SkipAutoConfigureDNS

-站台名稱-SiteName

-SystemKey-SystemKey

-SYSVOLPath-SYSVOLPath

-UseExistingAccount-UseExistingAccount

-Whatif-Whatif

注意

-認證引數只有需要如果您不已登入為企業系統管理員和架構管理員群組 (如果您在升級樹系) 或群組網域系統管理員 」 的成員 (如果您現有的網域新增新的 DC)。The -credential argument is only required if you are not already logged on as a member of the Enterprise Admins and Schema Admins groups (if you are upgrading the forest) or the Domain Admins group (if you are adding a new DC to an existing domain).

部署Deployment

部署設定Deployment Configuration

安裝複本

伺服器管理員會開始使用每個網域控制站升級部署組態頁面。Server Manager begins every domain controller promotion with the Deployment Configuration page. 剩餘的選項與所需的欄位變更此頁面上,後續的部署操作根據您選擇的頁面。The remaining options and required fields change on this page and subsequent pages, depending on which deployment operation you select.

升級現有的樹系或加入現有的網域新增寫入網域控制站,請按一下現有的網域中加入的網域控制站,按一下 [選取 [指定這個網域的網域資訊To upgrade an existing forest or add a writable domain controller to an existing domain, click Add a domain controller to an existing domain and click Select to Specify the domain information for this domain. 伺服器管理員會提示您輸入正確的認證視。Server Manager prompts you for valid credentials if needed.

升級樹系需要認證群組成員資格包含 Windows Server 2012 中的企業系統管理員 」 和 「 架構管理員群組。Upgrading the forest requires credentials that include group memberships in both the Enterprise Admins and Schema Admins groups in Windows Server 2012. Active Directory Domain Services 組態精靈會提示您稍後如果您目前的認證,不需要的適當權限或群組成員資格。The Active Directory Domain Services Configuration Wizard prompts you later if your current credentials do not have adequate permissions or group memberships.

自動 Adprep 處理程序有只操作不同加入網域控制站現有的 Windows Server 2012 網域和執行網域控制站較舊版本的 Windows Server 網域。The automatic Adprep process is the only operational difference between adding a domain controller to an existing Windows Server 2012 domain and a domain where domain controllers run an earlier version of Windows Server.

部署設定 ADDSDeployment cmdlet 和引數︰The Deployment Configuration ADDSDeployment cmdlet and arguments are:

Install-AddsDomainController  
-domainname <string>  
-credential <pscredential>  

安裝複本

安裝複本

在每個頁面上,其中一些重複稍後為不同的必要條件檢查執行特定測試。Certain tests perform at each page, some of which repeat later as discrete prerequisite checks. 例如,如果選取的網域不符合最低功能的等級,您不必一直促銷前往必要條件檢查以了解:For instance, if the selected domain does not meet the minimal functional levels, you do not have to go all the way through promotion to the prerequisite check to find out:

安裝複本

網域控制站選項Domain Controller Options

安裝複本

網域控制站選項頁面上指定的新的網域控制站的網域控制站功能。The Domain Controller Options page specifies the domain controller capabilities for the new domain controller. 可設定的網域控制站功能的的 DNS 伺服器通用,並唯讀網域控制站The configurable domain controller capabilities are DNS server, Global Catalog, and Read-only domain controller. Microsoft 建議所有網域控制站都提供 DNS 和 GC 服務的可用性分散式環境中。Microsoft recommends that all domain controllers provide DNS and GC services for high availability in distributed environments. GC 隨時選取預設,如果現有的網域主機已經在其 Dc DNS 根據授權起始查詢預設選取 DNS 伺服器。GC is always selected by default and DNS server is selected by default if the current domain hosts DNS already on its DCs based on Start of Authority query. 網域控制站選項頁面上也可讓您選擇適當的 Active Directory 邏輯網站名稱的樹系設定。The Domain Controller Options page also enables you to choose the appropriate Active Directory logical site name from the forest configuration. 根據預設,它會選取最正確的子網路的網站。By default, it selects the site with the most correct subnet. 只有一個網站時,會自動選取。If there is only one site, it selects automatically.

注意

如果伺服器不屬於 Active Directory 子網路,而且有一個以上的 Active Directory 網站,就選取任何項目和下一步按鈕,即表示,直到您選擇的網站清單。If the server does not belong to an Active Directory subnet and there is more than one Active Directory site, nothing is selected and the Next button is unavailable until you choose a site from the list.

指定Directory 服務還原模式密碼必須遵守密碼原則套用到伺服器。The specified Directory Services Restore Mode Password must adhere to the password policy applied to the server. 隨時複雜的密碼或最好複雜密碼。Always choose a strong, complex password or preferably, a passphrase.

網域控制站選項ADDSDeployment 引數:The Domain Controller Options ADDSDeployment arguments are:

-InstallDNS <{$false | $true}>  
-NoGlobalCatalog <{$false | $true}>  
-sitename <string>  
-SafeModeAdministratorPassword <secure string>  

重要

網站名稱必須存在時引數提供-站台名稱The site name must already exist when provided as an argument to -sitename. 安裝-AddsDomainController cmdlet 不會建立的網站。The install-AddsDomainController cmdlet does not create sites. 您可以使用 cmdlet新 adreplicationsite來建立新的網站。You can use cmdlet new-adreplicationsite to create new sites.

SafeModeAdministratorPassword引數的作業會特殊:The SafeModeAdministratorPassword argument's operation is special:

  • 如果未指定引數,cmdlet 會提示您輸入並確認遮罩的密碼。If not specified as an argument, the cmdlet prompts you to enter and confirm a masked password. 執行 cmdlet 互動時,這是慣用的使用方式。This is the preferred usage when running the cmdlet interactively.

    例如,treyresearch.net 網域中建立網域控制站,並提示您輸入並確認密碼遮罩:For example, to create an additional domain controller in treyresearch.net domain and be prompted to enter and confirm a masked password:

    Install-ADDSDomainController "DomainName treyresearch.net "credential (get-credential)  
    
  • 如果指定的值,,值必須安全字串。If specified with a value, the value must be a secure string. 執行 cmdlet 互動時,這是不慣用的使用方式。This is not the preferred usage when running the cmdlet interactively.

例如,您可以手動提示密碼使用朗讀主機cmdlet 提示安全字串的使用者:For example, you can manually prompt for a password by using the Read-Host cmdlet to prompt the user for a secure string:

-safemodeadministratorpassword (read-host -prompt "Password:" -assecurestring)  

警告

在前一個選項不會確認密碼、 小心謹慎: 看不到密碼。As the previous option does not confirm the password, use extreme caution: the password is not visible.

您也可以提供安全字串為轉換明文變數,雖然這是非常不建議使用。You can also provide a secure string as a converted clear-text variable, although this is highly discouraged.

-safemodeadministratorpassword (convertto-securestring "Password1" -asplaintext -force)  

最後,您可能會將模糊的密碼儲存在檔案,並再重複使用之後,清除文字並不會顯示密碼。Finally, you could store the obfuscated password in a file, and then reuse it later, without the clear text password ever appearing. 例如:For example:

$file = "c:\pw.txt"  
$pw = read-host -prompt "Password:" -assecurestring  
$pw | ConvertFrom-SecureString | Set-Content $file  

-safemodeadministratorpassword (Get-Content $File | ConvertTo-SecureString)  

警告

不建議提供或儲存清除或模糊文字密碼。Providing or storing a clear or obfuscated text password is not recommended. 任何人指令碼執行這個命令或在您身邊尋找知道網域控制站 DSRM 的密碼。Anyone running this command in a script or looking over your shoulder knows the DSRM password of that domain controller. 任何人的存取權檔案無法反向模糊的密碼。Anyone with access to the file could reverse that obfuscated password. 有了這個認知,他們可以登入以 DSRM 開始 DC 及最後模擬網域控制站本身他們的權限提高 Active Directory 森林中的最高層級。With that knowledge, they can logon to a DC started in DSRM and eventually impersonate the domain controller itself, elevating their privileges to the highest level in an Active Directory forest. 步驟使用另一組System.Security.Cryptography來將檔案加密資料建議但是超出範圍。An additional set of steps using System.Security.Cryptography to encrypt the text file data is advisable but out of scope. 最好的做法是完全避免儲存的密碼。The best practice is to totally avoid password storage.

ADDSDeployment cmdlet 提供略過 DNS client 設定、 轉送程式,以及根提示自動設定的其他選項。The ADDSDeployment cmdlet offers an additional option to skip automatic configuration of DNS client settings, forwarders, and root hints. 您不能略過此組態選項時使用伺服器管理員。You cannot skip this configuration option when using Server Manager. 此引數重要只有當您在安裝前設定的網域控制站伺服器的 DNS 伺服器角色:This argument matters only if you installed the DNS Server role prior to configuring the domain controller:

-SkipAutoConfigureDNS  

網域控制站選項頁面會警告您無法建立朗讀只網域控制站如果現有的網域控制站執行 Windows Server 2003。The Domain Controller Options page warns that you cannot create read only domain controllers if your existing domain controllers run Windows Server 2003. 這會如預期般,以及您可以關閉警告。This is expected, and you can dismiss the warning.

安裝複本

DNS 選項],然後 DNS 的認證委派DNS Options and DNS Delegation Credentials

安裝複本

DNS 選項頁面上,可讓您設定 DNS 委派,如果您選取DNS 伺服器上選項網域控制站選項頁面上,如果您指向可以 DNS 委派區域。The DNS Options page enables you to configure DNS delegation if you selected the DNS server option on the Domain Controller Options page and if pointing to a zone where DNS delegations are allowed. 您可能需要提供其他成員的使用者認證DNS 管理員群組。You may need to provide alternate credentials of a user that is a member of the DNS Admins group.

DNS 選項ADDSDeployment cmdlet 引數:The DNS Options ADDSDeployment cmdlet arguments are:

-creatednsdelegation   
-dnsdelegationcredential <pscredential>  

安裝複本

如需有關您是否需要建立 DNS 委派的詳細資訊,請查看了解區域委派For more information about whether you need to create a DNS delegation, see Understanding Zone Delegation.

其他選項Additional Options

安裝複本

的其他選項頁面上提供設定選項,來命名網域控制站為複寫來源,或您可以使用任何網域控制站為複寫來源。The Additional Options page provides the configuration option to name a domain controller as the replication source, or you can use any domain controller as the replication source.

您也可以選擇備份使用安裝媒體 (IFM) 選項從媒體安裝網域控制站使用。You can also choose to install the domain controller using backed up media using the Install from media (IFM) option. 安裝媒體的核取方塊提供選取一次瀏覽] 選項,您必須按驗證以確保所提供有效的媒體。The Install from media checkbox provides a browse option once selected and you must click Verify to ensure the provided path is valid media. 從其他現有 Windows Server 2012 電腦; IFM 選項使用媒體建立與 Windows Server 備份或 Ntdsutil.exe您無法建立 Windows Server 2012 網域控制站媒體使用 Windows Server 2008 R2 或先前的作業系統。Media used by the IFM option is created with Windows Server Backup or Ntdsutil.exe from another existing Windows Server 2012 computer only; you cannot use a Windows Server 2008 R2 or previous operating system to create media for a Windows Server 2012 domain controller. 如需變更 IFM 的詳細資訊,請查看簡化管理附錄For more information about changes in IFM, see Simplified Administration Appendix. 如果使用的 media 受 SYSKEY,伺服器管理員會在驗證期間影像的密碼提示。If using media protected with a SYSKEY, Server Manager prompts for the image's password during verification.

安裝複本

的其他選項ADDSDeployment cmdlet 引數:The Additional Options ADDSDeployment cmdlet arguments are:

-replicationsourcedc <string>  
-installationmediapath <string>  
-syskey <secure string>  

路徑Paths

安裝複本

路徑頁面上,可讓您覆寫預設資料夾位置的 AD DS 資料庫中資料庫交易登,並 SYSVOL 分享。The Paths page enables you to override the default folder locations of the AD DS database, the database transaction logs, and the SYSVOL share. 預設位置都之隱藏資料夾中。The default locations are always in subdirectories of %systemroot%.

Active Directory 路徑 ADDSDeployment cmdlet 引數︰The Active Directory Paths ADDSDeployment cmdlet arguments are:

-databasepath <string>  
-logpath <string>  
-sysvolpath <string>  

準備選項Preparation Options

安裝複本

準備選項頁面上,系統會通知您 AD DS 設定,包括擴充架構 (forestprep) 及更新的網域 (準備網域)。The Preparation Options page alerts you that the AD DS configuration includes extending the Schema (forestprep) and updating the domain (domainprep). 樹系和網域不已經準備手動執行 Adprep.exe 或上一個 Windows Server 2012 網域控制站安裝時,只會看到此頁面。You only see this page when the forest and domain have not been prepared by previous Windows Server 2012 domain controller installation or from manually running Adprep.exe. 例如,Active Directory Domain Services 組態精靈會如果現有的 Windows Server 2012 樹系根網域中新增新的網域控制站隱藏此頁面。For example, the Active Directory Domain Services Configuration Wizard suppresses this page if you add a new domain controller to an existing Windows Server 2012 forest root domain.

延伸架構和更新網域不會發生當您按一下下一步Extending the Schema and updating the domain do not occur when you click Next. 只有在安裝期間發生這些事件。These events occur only during the installation phase. 此頁面只要帶來在安裝之後會發生的事件有關感知。This page simply brings awareness about the events that will occur later in the installation.

這個頁面也驗證的目前使用者的認證管理員架構與企業系統管理員群組成員您需要成員資格擴充架構或準備網域這些群組中。This page also validates that the current user credentials are members of the Schema Admin and Enterprise Admins groups, as you need membership in these groups to extend the schema or prepare a domain. 按一下變更頁面會通知您目前的憑證,並不提供不足權限時,提供的適當的使用者的認證。Click Change to provide the adequate user credentials if the page informs you that the current credentials do not provide sufficient permissions.

安裝複本

其他選項 ADDSDeployment cmdlet 引數是:The Additional Options ADDSDeployment cmdlet argument is:

-adprepcredential <pscredential>  

重要

為使用舊版的 Windows Server 執行 Windows Server 2012 」 的網域控制站自動化的網域此處不會執行 GPPREP。As with previous versions of Windows Server, automated domain preparation for domain controllers that run Windows Server 2012 does not run GPPREP. 執行adprep.exe /gpprep以手動方式的所有先前已未準備適用於 Windows Server 2003、Windows Server 2008 或 Windows Server 2008 R2 的網域。Run adprep.exe /gpprep manually for all domains that were not previously prepared for Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2. 您應該先執行一次 GPPrep 歷史不是每份升級與加入網域中。You should run GPPrep only once in the history of a domain, not with every upgrade. Adprep.exe 不會執行 /gpprep 自動因為其作業都可能造成所有檔案和資料夾重新複寫所有網域控制站 SYSVOL 資料夾中。Adprep.exe does not run /gpprep automatically because its operation can cause all files and folders in the SYSVOL folder to re-replicate on all domain controllers.

當您升級第一階段未 RODC 網域中的,將會執行自動 RODCPrep。Automatic RODCPrep runs when you promote the first un-staged RODC in a domain. 不是當您第一次的寫入 Windows Server 2012 網域控制站升級。It does not occur when you promote the first writeable Windows Server 2012 domain controller. 您也仍然以手動方式可以adprep.exe /rodcprep如果您要部署唯讀網域控制站計劃。You can also still manually adprep.exe /rodcprep if you plan to deploy read-only domain controllers.

檢視選項],然後檢視指令碼Review Options and View Script

安裝複本

評論選項頁面上可讓您驗證您的設定,並確保您開始安裝之前,先其符合您的需求。The Review Options page enables you to validate your settings and ensure that they meet your requirements before you start the installation. 這不是一個機會停止使用伺服器管理員安裝。This is not the last opportunity to stop the installation using Server Manager. 此頁面上可讓您檢查並確認您的設定,才能繼續設定。This page simply enables you to review and confirm your settings before continuing the configuration.

評論選項在伺服器管理員頁面也提供選擇性檢視指令碼按鈕,以建立包含目前 ADDSDeployment 設定成單一的 Windows PowerShell 指令碼 Unicode 文字檔案。The Review Options page in Server Manager also offers an optional View Script button to create a Unicode text file that contains the current ADDSDeployment configuration as a single Windows PowerShell script. 這可讓您在伺服器管理員圖形介面作為 Windows PowerShell 部署 studio。This enables you to use the Server Manager graphical interface as a Windows PowerShell deployment studio. 若要設定選項,匯出設定,然後取消精靈使用 Active Directory Domain Services 組態精靈。Use the Active Directory Domain Services Configuration Wizard to configure options, export the configuration, and then cancel the wizard. 此程序會建立進一步修改或直接使用有效且語法正確範例。This process creates a valid and syntactically correct sample for further modification or direct use.

例如:For example:

#  
# Windows PowerShell Script for AD DS Deployment  
#  
Import-Module ADDSDeployment  
Install-ADDSDomainController `  
-CreateDNSDelegation `  
-Credential (Get-Credential) `  
-CriticalReplicationOnly:$false `  
-DatabasePath "C:\Windows\NTDS" `  
-DomainName "root.fabrikam.com" `  
-InstallDNS:$true `  
-LogPath "C:\Windows\NTDS" `  
-SiteName "Default-First-Site-Name" `  
-SYSVOLPath "C:\Windows\SYSVOL"  
-Force:$true  

注意

伺服器管理員通常會填入所有引升級後不會依賴預設值 (因為它們可能會改變之間未來版本 Windows 的 service pack) 的值。Server Manager generally fills in all arguments with values when promoting and does not rely on defaults (as they may change between future versions of Windows or service packs). 有一個例外此-safemodeadministratorpassword引數。The one exception to this is the -safemodeadministratorpassword argument. 若要強制確認提示忽略值執行 cmdlet 互動時To force a confirmation prompt omit the value when running cmdlet interactively

使用選擇性Whatif以引數安裝-ADDSDomainController cmdlet 檢視設定的資訊。Use the optional Whatif argument with the Install-ADDSDomainController cmdlet to review configuration information. 這可讓您查看 cmdlet 引數明確和隱含的值。This enables you to see the explicit and implicit values of the arguments for a cmdlet.

安裝複本

必要條件核取Prerequisites Check

安裝複本

請必要條件是 AD DS 網域設定中的新功能。The Prerequisites Check is a new feature in AD DS domain configuration. 這個新階段驗證的網域和樹系的新的 Windows Server 2012 網域控制站的支援。This new phase validates that the domain and forest are capable of supporting a new Windows Server 2012 domain controller.

當您安裝新的網域控制站伺服器管理員 Active Directory Domain Services 組態精靈叫用一系列序列化模組測試。When installing a new domain controller, the Server Manager Active Directory Domain Services Configuration Wizard invokes a series of serialized modular tests. 這些測試提醒建議的修復選項。These tests alert you with suggested repair options. 您可以視需要執行測試。You can run the tests as many times as required. 無法繼續網域控制站程序,直到所有必要條件測試傳遞。The domain controller process cannot continue until all prerequisite tests pass.

請必要條件也會呈現相關資訊,例如安全性變更會影響較舊的作業系統。The Prerequisites Check also surfaces relevant information such as security changes that affect older operating systems.

如需有關的特定的必要條件檢查,請查看必要條件檢查For more information about the specific prerequisite checks, see Prerequisite Checking.

您無法略過必要條件檢查時使用伺服器管理員中,但您可以跳過此程序使用 [使用下列引數 AD DS 部署 cmdlet 時:You cannot bypass the Prerequisite Check when using Server Manager, but you can skip the process when using the AD DS Deployment cmdlet using the following argument:

-skipprechecks  

警告

Microsoft 會阻礙重覆它會導致部分網域控制站升級或損壞 AD DS 森林略過必要條件檢查。Microsoft discourages skipping the prerequisite check as it can lead to a partial domain controller promotion or damaged AD DS forest.

按一下安裝若要開始網域控制站升級程序。Click Install to begin the domain controller promotion process. 這是最後取消安裝的機會。This is last opportunity to cancel the installation. 開始後,您就無法取消升級程序。You cannot cancel the promotion process once it begins. 電腦將會在升級,無論促銷結果結尾自動重新開機。請必要條件頁面會顯示在程序和指導方針解析問題時遇到任何問題。The computer will reboot automatically at the end of promotion, regardless of the promotion results.The Prerequisites Check page displays any issues it encountered during the process and guidance for resolving the issue.

安裝Installation

安裝複本

安裝頁面會顯示,網域控制站設定開始和無法終止或取消。When the Installation page displays, the domain controller configuration begins and cannot be halted or canceled. 詳細的作業會顯示在此頁面上,而且寫入登:Detailed operations display on this page and are written to logs:

  • %systemroot%\debug\dcpromo.log%systemroot%\debug\dcpromo.log

  • %systemroot%\debug\dcpromoui.log%systemroot%\debug\dcpromoui.log

  • %systemroot%\debug\adprep\logs%systemroot%\debug\adprep\logs

  • %systemroot%\debug\netsetup.log (如果伺服器工作群組中)%systemroot%\debug\netsetup.log (if server is in a workgroup)

若要安裝新的 Active Directory 森林使用 ADDSDeployment 模組,使用下列 cmdlet:To install a new Active Directory forest using the ADDSDeployment module, use the following cmdlet:

Install-addsdomaincontroller  

查看升級及複本 Windows PowerShell選用和引數。See Upgrade and Replica Windows PowerShell for required and optional arguments.

安裝-AddsDomainController cmdlet 僅有兩個階段 (必要條件檢查並安裝)。The Install-AddsDomainController cmdlet only has two phases (prerequisite checking and installation). 有兩個下方的數字顯示安裝階段檔最低的的網域名稱-認證The two figures below show the installation phase with the minimum required arguments of -domainname and -credential. 請注意 Adprep 作業會自動的第一個 Windows Server 2012 網域控制站加入現有的 Windows Server 2003 樹系的一部分:Note how the Adprep operation happens automatically as part of adding the first Windows Server 2012 domain controller to an existing Windows Server 2003 forest:

安裝複本

請注意,就像伺服器管理員中,安裝-ADDSDomainController ,升級將會自動重新開機伺服器提醒您。Note how, just like Server Manager, Install-ADDSDomainController reminds you that promotion will reboot the server automatically. 若要自動接受重新開機命令提示字元中,使用-強制-確認: $false的任何 ADDSDeployment Windows PowerShell cmdlet 引數。To accept the reboot prompt automatically, use the -force or -confirm:$false arguments with any ADDSDeployment Windows PowerShell cmdlet. 若要防止伺服器促銷結尾自動重新開機,使用-norebootoncompletion引數。To prevent the server from automatically rebooting at the end of promotion, use the -norebootoncompletion argument.

警告

覆寫在重新開機,建議。Overriding the reboot is discouraged. 網域控制站必須重新開機才能正確運作。The domain controller must reboot to function correctly.

安裝複本

安裝複本

若要設定的網域控制站從遠端使用 Windows PowerShell,包含安裝-adddomaincontroller cmdlet叫用命令cmdlet。To configure a domain controller remotely using Windows PowerShell, wrap the install-adddomaincontroller cmdlet inside of the invoke-command cmdlet. 這需要使用大括弧。This requires using the curly braces.

invoke-command {install-addsdomaincontroller "domainname <domain> -credential (get-credential)} -computername <dc name>  

例如:For example:

安裝複本

注意

如需有關如何安裝及 Adprep 程序運作方式的詳細資訊,請查看進行疑難排解的網域控制站部署For more information on how the installation and Adprep process works, see the Troubleshooting Domain Controller Deployment.

結果Results

安裝複本

結果頁面會顯示成功或失敗的升級與管理的任何重要資訊。The Results page shows the success or failure of the promotion and any important administrative information. 如果成功,網域控制站將會自動重新開機之後 10 秒。If successful, the domain controller will automatically reboot after 10 seconds.

與之前版本的 Windows Server、 執行 Windows server 2012 的網域控制站自動化的網域此處無法執行 GPPREP。As with previous versions of Windows Server, automated domain preparation for domain controllers that run Windows server 2012 does not run GPPREP. 執行adprep.exe /gpprep以手動方式的所有先前已未準備適用於 Windows Server 2003、Windows Server 2008 或 Windows Server 2008 R2 的網域。Run adprep.exe /gpprep manually for all domains that were not previously prepared for Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2. 您應該先執行一次 GPPrep 歷史不是每份升級與加入網域中。You should run GPPrep only once in the history of a domain, not with every upgrade. Adprep.exe 不會執行 /gpprep 自動因為其作業都可能造成所有檔案和資料夾重新複寫所有網域控制站 SYSVOL 資料夾中。Adprep.exe does not run /gpprep automatically because its operation can cause all files and folders in the SYSVOL folder to re-replicate on all domain controllers.