安裝 Active Directory Domain Services (層級 100)Install Active Directory Domain Services (Level 100)

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

本主題如何安裝 Windows Server 2012 中 AD DS,使用下列方法:This topic explains how to install AD DS in Windows Server 2012 by using any of the following methods:

若要執行 Adprep.exe 並安裝 Active Directory Domain Services 認證需求Credential requirements to run Adprep.exe and install Active Directory Domain Services

下列認證,才能執行 Adprep.exe 並安裝 AD DS。The following credentials are required to run Adprep.exe and install AD DS.

  • 若要安裝新的樹系,您必須本機電腦的系統管理員的身分登入。To install a new forest, you must be logged on as the local Administrator for the computer.

  • 若要安裝新的子女網域或新的網域樹,您必須成員群組企業系統管理員的身分登入。To install a new child domain or new domain tree, you must be logged on as a member of the Enterprise Admins group.

  • 若要安裝的網域控制站現有網域中,您必須網域管理群組成員。To install an additional domain controller in an existing domain, you must be a member of the Domain Admins group.

    注意

    如果您無法執行 adprep.exe 命令另行購買,您要安裝 Windows Server 2012 上執行的現有網域或樹系的第一個網域控制站系統會提示您將會提供認證來執行 Adprep 命令。If you do not run adprep.exe command separately and you are installing the first domain controller that runs Windows Server 2012 in an existing domain or forest, you will be prompted to supply credentials to run Adprep commands. 認證需求如下:The credential requirements are as follows:

    • 若要介紹的第一個 Windows Server 2012 網域控制站森林中,您需要的架構管理群組,企業系統管理員群組成員提供的認證並網域系統管理員組網域中裝載架構主機。To introduce the first Windows Server 2012 domain controller in the forest, you need to supply credentials for a member of Enterprise Admins group, the Schema Admins group, and the Domain Admins group in the domain that hosts the schema master.
    • 若要介紹的第一個 Windows Server 2012 網域控制站網域中,您需要提供的認證網域管理群組成員。To introduce the first Windows Server 2012 domain controller in a domain, you need to supply credentials for a member of the Domain Admins group.
    • 若要介紹的第一個唯讀網域控制站 (RODC) 森林中,您需要提供的認證管理員企業群組成員。To introduce the first read-only domain controller (RODC) in the forest, you need to supply credentials for a member of the Enterprise Admins group.

      注意

      如果您已經執行 Windows Server 2008,或 Windows Server 2008 R2 adprep /rodcprep,您不需要再執行一次適用於 Windows Server 2012。If you have already run adprep /rodcprep in Windows Server 2008 or Windows Server 2008 R2, you do not need to run it again for Windows Server 2012 .

使用 Windows PowerShell 來安裝 AD DSInstalling AD DS by Using Windows PowerShell

開始使用 Windows Server 2012,您可以安裝 AD DS,使用 Windows PowerShell。Beginning with Windows Server 2012 , you can install AD DS using Windows PowerShell. 已被 Dcpromo.exe 取代開始使用 Windows Server 2012,但您仍然可以執行 dcpromo.exe 使用回應檔案 (帶領自動 /:或帶領 /answer:)。Dcpromo.exe is deprecated beginning with Windows Server 2012 , but you can still run dcpromo.exe by using an answer file (dcpromo /unattend: or dcpromo /answer:). 請繼續執行 dcpromo.exe 回應檔案的功能提供資源投資現有自動化時間 dcpromo.exe 自動化轉換到 Windows PowerShell 中的組織。The ability to continue running dcpromo.exe with an answer file provides organizations that have resources invested in existing automation time to convert the automation from dcpromo.exe to Windows PowerShell. 適用於執行 dcpromo.exe 回應檔案的相關詳細資訊,請查看http://support.microsoft.com/kb/947034For more information about running dcpromo.exe with an answer file, see http://support.microsoft.com/kb/947034.

如需有關移除使用 Windows PowerShell AD DS,請查看移除使用 Windows PowerShell AD DSFor more information about removing AD DS using Windows PowerShell, see Remove AD DS using Windows PowerShell.

開始使用新增使用 Windows PowerShell 中的角色。Start with adding the role using Windows PowerShell. 這個命令安裝 AD DS 伺服器角色並安裝 AD DS 與廣告 LDS 伺服器管理工具,包括 GUI 為基礎的工具,例如 Active Directory 使用者及電腦和命令列工具,例如 dcdia.exe。This command installs the AD DS server role and installs the AD DS and AD LDS server administration tools, including GUI-based tools such as Active Directory Users and Computers and command-line tools such as dcdia.exe. 當您使用 Windows PowerShell 預設不會安裝伺服器管理工具。Server administration tools are not installed by default when you use Windows PowerShell. 您需要指定「 IncludeManagementTools來管理本機伺服器或安裝遠端伺服器管理工具來管理遠端伺服器。You need to specify "IncludeManagementTools to manage the local server or install Remote Server Administration Tools to manage a remote server.

Install-windowsfeature -name AD-Domain-Services -IncludeManagementTools  
<<Windows PowerShell cmdlet and arguments>>  

還有不 AD DS 安裝完成後,直到需要重新開機。There is no reboot required until after the AD DS installation is complete.

您可以再執行這個命令,以檢視可用 cmdlet ADDSDeployment 單元。You can then run this command to see the available cmdlets in the ADDSDeployment module.

Get-Command -Module ADDSDeployment

若要查看 cmdlet 和語法可以指定引數清單:To see the list of arguments that can be specified for a cmdlets and syntax:

Get-Help <cmdlet name>  

例如,若要查看的引數建立位置唯讀網域控制站 (RODC) 帳號,輸入For example, to see the arguments for creating an unoccupied read-only domain controller (RODC) account, type

Get-Help Add-ADDSReadOnlyDomainControllerAccount

選擇性引數會出現在方括弧。Optional arguments appear in square brackets.

您也可以下載最新的協助範例及 Windows PowerShell cmdlet 的概念。You can also download the latest Help examples and concepts for Windows PowerShell cmdlets. 如需詳細資訊,請查看about_Updatable_HelpFor more information, see about_Updatable_Help.

您可以執行 Windows PowerShell cmdlet 遠端伺服器功能:You can run Windows PowerShell cmdlets against remote servers:

  • Windows PowerShell 中, 使用 ADDSDeployment cmdlet Invoke-Command。In Windows PowerShell, use Invoke-Command with the ADDSDeployment cmdlet. 例如,名為 ConDC3 contoso.com 網域中的遠端伺服器上安裝 AD DS,請輸入:For example, to install AD DS on a remote server named ConDC3 in the contoso.com domain, type:

    Invoke-Command { Install-ADDSDomainController -DomainName contoso.com -Credential (Get-Credential) } -ComputerName ConDC3  
    

-或者--or-

  • 在伺服器管理員中,建立伺服器群組包含遠端伺服器。In Server Manager, create a server group that includes the remote server. 以滑鼠右鍵按一下 [遠端伺服器的名稱,然後按一下Windows PowerShellRight-click the name of the remote server and click Windows PowerShell.

下一節中如何執行安裝 AD DS ADDSDeployment 模組 cmdlet。The next sections explain how to run ADDSDeployment module cmdlets to install AD DS.

ADDSDeployment cmdlet 引數ADDSDeployment cmdlet arguments

下表列出 Windows PowerShell 中 ADDSDeployment cmdlet 引數。The following table lists arguments for the ADDSDeployment cmdlets in Windows PowerShell. 引數以粗體顯示所需項目。Arguments in bold are required. 如果稱為 Windows PowerShell 中的其他 dcpromo.exe 相等引數所示括號。Equivalent arguments for dcpromo.exe are listed in parentheses if they are named different in Windows PowerShell.

Windows PowerShell 參數接受 $TRUE 或 $FALSE 引數。Windows PowerShell switches accept $TRUE or $FALSE arguments. 不需要指定引數 $TRUE 預設程式。Arguments that are $TRUE by default do not need to be specified.

若要覆寫預設值,您可以指定引數 $False 值。To override default values, you can specify the argument with a $False value. 例如,因為-installdns自動執行安裝新的樹系如果未指定的唯一方式避免DNS 安裝當您安裝新的樹系是使用:For example, because -installdns is automatically run for a new forest installation if it is not specified, the only way to prevent DNS installation when you install a new forest is to use:

-InstallDNS:$false  

同樣地,因為「 installdns有 $False 預設值,如果您安裝的網域控制站在環境不主控 Windows Server DNS 伺服器,您需要安裝 DNS 伺服器,才能指定下列引數:Similarly, because "installdns has a default value of $False if you install a domain controller in an environment that does not host Windows Server DNS server, you need to specify the following argument in order to install DNS server:

-InstallDNS:$true  
引數Argument 描述Description
ADPrepCredential ** **請注意:所需如果您正在安裝網域中的第一個 Windows Server 2012 網域控制站或森林與目前的使用者的認證的不足,無法執行此作業。ADPrepCredential Note: Required if you are installing the first Windows Server 2012 domain controller in a domain or forest and the credentials of the current user are insufficient to perform the operation. 根據的規則企業系統管理員和架構系統管理員可以準備、 樹系的群組成員資格指定 account取得認證和 PSCredential 物件。Specifies the account with Enterprise Admins and Schema Admins group membership that can prepare the forest, according to the rules of Get-Credential and a PSCredential object.

如果未指定值的值「 認證使用引數。If no value is specified, the value of the "credential argument is used.
AllowDomainControllerReinstallAllowDomainControllerReinstall 指定要繼續安裝此寫入網域控制站,雖然的偵測到另一個寫入網域控制站 account 具有相同名稱。Specifies whether to continue installing this writable domain controller, despite the fact that another writable domain controller account with the same name is detected.

使用$True僅您是否確定 account 目前無法使用,另一個寫入網域控制站。Use $True only if you are sure that the account is not currently used by another writable domain controller.

預設值是$FalseThe default is $False.

此引數不正確的 RODC。This argument is not valid for an RODC.
AllowDomainReinstallAllowDomainReinstall 指定現有的網域是否重新建立。Specifies whether an existing domain is recreated.

預設值是$FalseThe default is $False.
AllowPasswordReplicationAccountName < 字串 [>AllowPasswordReplicationAccountName <string []> 指定帳號,群組帳號,並其密碼可以複製到此 RODC 電腦帳號的名稱。Specifies the names of user accounts, group accounts, and computer accounts whose passwords can be replicated to this RODC. 使用空字串 」 」 如果您想要保留空白的值。Use an empty string "" if you want to keep the value empty. 根據預設,允許只允許 RODC 密碼複寫群組,而最初建立空白。By default, only the Allowed RODC Password Replication Group is allowed, and it is originally created empty.

提供的值為字串陣列。Supply values as a string array. 例如:For example:

程式碼-AllowPasswordReplicationAccountName 」 JSmith 」、 「 JSmithPC 「,「 分支使用者]Code -AllowPasswordReplicationAccountName "JSmith","JSmithPC","Branch Users"
ApplicationPartitionsToReplicate < 字串 [>請注意:在 UI 不等選項。ApplicationPartitionsToReplicate <string []> Note: There is no equivalent option in the UI. 如果您安裝使用 UI,或者 IFM,將會複寫所有應用程式的磁碟分割。If you install using the UI, or using IFM, then all application partitions will be replicated. 指定要複製的應用程式 directory 磁碟分割。Specifies the application directory partitions to replicate. 只有當您指定套用此引數-InstallationMediaPath若要安裝的媒體 (IFM) 引數。This argument is applied only when you specify the -InstallationMediaPath argument to install from media (IFM). 根據預設,所有應用程式會將磁碟分割依據他們自己的範圍。By default, all application partitions will replicate based on their own scopes.

提供的值為字串陣列。Supply values as a string array. 例如:For example:

程式碼-Code -

-ApplicationPartitionsToReplicate 」 partition1 」、 「 partition2 」、 「 partition3 」-ApplicationPartitionsToReplicate "partition1","partition2","partition3"
確認Confirm 會提示您先執行 cmdlet 確認。Prompts you for confirmation before running the cmdlet.
CreateDnsDelegation請注意:當您執行新增-ADDSReadOnlyDomainController cmdlet 不能指定此引數。CreateDnsDelegation Note: You cannot specify this argument when you run the Add-ADDSReadOnlyDomainController cmdlet. 表示是否要建立新的 DNS 伺服器,您的網域控制站以及安裝的參考 DNS 委派。Indicates whether to create a DNS delegation that references the new DNS server that you are installing along with the domain controller. 有效的 Active Directory 」 整合 DNS 只。Valid for Active Directory"integrated DNS only. 委派記錄只可以建立的使用者且無障礙 online Microsoft DNS 伺服器。Delegation records can be created only on Microsoft DNS servers that are online and accessible. 委派記錄無法建立的最上層網域,例如.com、.gov、.biz、.edu 或兩個字母國家代碼網域.nz 和.au 屬於網域。Delegation records cannot be created for domains that are immediately subordinate to top-level domains such as .com, .gov, .biz, .edu or two-letter country code domains such as .nz and .au.

根據環境自動計算預設值。The default is computed automatically based on the environment.
認證 ** **請注意:需要目前使用者的認證是否不足,無法執行此作業。Credential Note: Required only if the credentials of the current user are insufficient to perform the operation. 指定可以登入網域,核對按照取得認證和 PSCredential 物件。Specifies the domain account that can logon to the domain, according to the rules of Get-Credential and a PSCredential object.

如果未指定值,會使用目前的使用者的認證。If no value is specified, the credentials of the current user are used.
CriticalReplicationOnlyCriticalReplicationOnly 指定 AD DS 安裝操作是否會執行只重大複製再重新開機,然後再繼續。Specifies whether the AD DS installation operation performs only critical replication before reboot and then continues. 安裝完成後,電腦重新開機,就會發生重要複寫。The noncritical replication happens after the installation finishes and the computer reboots.

不建議使用此引數。Using this argument is not recommended.

還有不相當於在使用者介面 (UI),此選項。There is no equivalent for this option in the user interface (UI).
DatabasePathDatabasePath 指定完整非 「 磁碟包含網域資料庫,例如,在本機電腦的硬碟上路徑通用命名規格 (UNC) C:\Windows\NTDS。Specifies the fully qualified, non"Universal Naming Convention (UNC) path to a directory on a fixed disk of the local computer that contains the domain database, for example, C:\Windows\NTDS.

預設值是%SYSTEMROOT%\NTDSThe default is %SYSTEMROOT%\NTDS. 重要事項:時,您可以將使用復原檔案系統 (ReFS) 格式化磁碟區 AD DS 資料庫並登入檔案,有任何特定好處裝載上 ReFS AD DS,您取得以外的恢復正常優點裝載 ReFS 上的任何資料。Important: While you can store the AD DS database and log files on volume formatted with Resilient File System (ReFS), there are no specific benefits for hosting AD DS on ReFS, other than the normal benefits of resiliency you get for hosting any data on ReFS.
DelegatedAdministratorAccountNameDelegatedAdministratorAccountName 指定的使用者或群組,可以安裝及管理 RODC 的名稱。Specifies the name of the user or group that can install and administer the RODC.

根據預設,僅限群組成員的網域系統管理員可以管理 RODC。By default, only members of the Domain Admins group can administer an RODC.
DenyPasswordReplicationAccountName < 字串 [>DenyPasswordReplicationAccountName <string []> 指定帳號,群組帳號,並其密碼不提供複製到此 RODC 電腦帳號的名稱。Specifies the names of user accounts, group accounts, and computer accounts whose passwords are not to be replicated to this RODC. 使用空字串 」 」 如果您不希望拒絕複寫的任何使用者或電腦的認證。Use an empty string "" if you do not want to deny the replication of credentials of any users or computers. 根據預設,系統管理員,伺服器電信業者、 備份電信業者、 Account 電信業者,並拒絕 RODC 密碼複寫群組拒絕。By default, Administrators, Server Operators, Backup Operators, Account Operators, and the Denied RODC Password Replication Group are denied. 根據預設,拒絕 RODC 密碼複寫群組包含憑證發行者、 網域系統管理員,企業系統管理員、 企業網域控制站、 企業唯讀網域控制站、 群組原則 Creator 擁有者、 krbtgt 帳號及架構系統管理員。By default, the Denied RODC Password Replication Group includes Cert Publishers, Domain Admins, Enterprise Admins, Enterprise Domain Controllers, Enterprise Read-Only Domain Controllers, Group Policy Creator Owners, the krbtgt account, and Schema Admins.

提供的值為字串陣列。Supply values as a string array. 例如:For example:

程式碼-Code -

-DenyPasswordReplicationAccountName 」 RegionalAdmins 」、 「 AdminPCs 」-DenyPasswordReplicationAccountName "RegionalAdmins","AdminPCs"
DnsDelegationCredential 請注意: cmdlet 新增-ADDSReadOnlyDomainController 執行時,您就不能指定此引數。DnsDelegationCredential Note: You cannot specify this argument when you run the Add-ADDSReadOnlyDomainController cmdlet. 指定的使用者名稱和密碼建立 DNS 委派,按照取得認證和 PSCredential 物件。Specifies the user name and password for creating DNS delegation, according to the rules of Get-Credential and a PSCredential object.
DomainMode {Win2003 和 #124;Win2008 與 #124;Win2008R2 與 #124;Win2012 與 #124;Win2012R2}DomainMode {Win2003 | Win2008 | Win2008R2 | Win2012 | Win2012R2}

Or

DomainMode {2 與 #124; 3 和 #124; 4 與 #124; 5 和 #124; 6}DomainMode {2 | 3 | 4 | 5 | 6}
建立新的網域期間指定的網域功能層級。Specifies the domain functional level during the creation of a new domain.

層級不得低於的樹系功能的層級,但很高正常運作的網域。The domain functional level cannot be lower than the forest functional level, but it can be higher.

自動計算和為現有的樹系功能等級或值設定為預設值-ForestModeThe default value is automatically computed and set to the existing forest functional level or the value that is set for -ForestMode.
網域名稱DomainName

所需的安裝-ADDSForest 和安裝-ADDSDomainController cmdlet。Required for Install-ADDSForest and Install-ADDSDomainController cmdlets.
指定您要安裝的其他網域控制站的網域的 FQDN。Specifies the FQDN of the domain in which you want to install an additional domain controller.
DomainNetbiosNameDomainNetbiosName

如果超過 15 字元 FQDN 前置詞名稱所需安裝-ADDSForest。Required for Install-ADDSForest if FQDN prefix name is longer than 15 characters.
安裝-ADDSForest 搭配使用。Use with Install-ADDSForest. 指定新的樹系根網域 NetBIOS 的名稱。Assigns a NetBIOS name to the new forest root domain.
DomainType {ChildDomain 和 #124;TreeDomain} 或 {子女和 #124; 樹}DomainType {ChildDomain | TreeDomain} or {child | tree} 表示您想要建立網域類型: 現有中新的網域樹狀結構樹系的現有的網域或新的樹系的子女。Indicates the type of domain that you want to create: a new domain tree in an existing forest, a child of an existing domain, or a new forest.

DomainType 預設值是 ChildDomain。The default for DomainType is ChildDomain.
推動Force 當此參數指定允許完成執行 cmdlet 將會隱藏起來任何期間的安裝和加入的網域控制站可能通常會顯示警告。When this parameter is specified any warnings that might normally appear during the installation and addition of the domain controller will be suppressed to allow the cmdlet to complete its execution. 此參數可能包含指令碼安裝時,很有幫助。This parameter can be useful to include when scripting installation.
ForestMode {Win2003 和 #124;Win2008 與 #124;Win2008R2 與 #124;Win2012 與 #124;Win2012R2}ForestMode {Win2003 | Win2008 | Win2008R2 | Win2012 | Win2012R2}

Or

ForestMode {2 與 #124; 3 和 #124; 4 與 #124; 5 和 #124; 6}ForestMode {2 | 3 | 4 | 5 | 6}
當您建立新的樹系,指定的樹系功能層級。Specifies the forest functional level when you create a new forest.

預設值是 Win2012。The default value is Win2012.
InstallationMediaPathInstallationMediaPath 表示的安裝媒體,可用於安裝新的網域控制站的位置。Indicates the location of the installation media that will be used to install a new domain controller.
InstallDnsInstallDns 指定 DNS 伺服器服務應該安裝和設定的網域控制站。Specifies whether the DNS Server service should be installed and configured on the domain controller.

新的樹系的預設值是$True並安裝 DNS 伺服器。For a new forest, the default is $True and DNS Server is installed.

新的子女網域或網域樹,如果已主控家長網域 (或的網域樹森林根網域),會儲存 DNS 網域名稱預設值為此參數則 $True。For a new child domain or domain tree, if the parent domain (or forest root domain for a domain tree) already hosts and stores the DNS names for the domain, then the default for this parameter is $True.

網域控制站安裝在現有的網域中,此參數是否左未指定及目前網域已經主控儲存網域中的 DNS 名稱,然後的預設值為此參數$TrueFor a domain controller installation in an existing domain, if this parameter is left unspecified and the current domain already hosts and stores the DNS names for the domain, then the default for this parameter is $True. 或者,如果 DNS 網域名稱裝載 Active Directory 以外,預設值是$False並不安裝任何 DNS 伺服器。Otherwise, if DNS domain names are hosted outside of Active Directory, the default is $False and no DNS Server is installed.
LogPathLogPath 指定,非-注意到 directory 包含網域登入檔案,例如,在本機電腦的硬碟上C:\Windows\LogsSpecifies the fully qualified, non-UNC path to a directory on a fixed disk of the local computer that contains the domain log files, for example, C:\Windows\Logs.

預設值是%SYSTEMROOT%\NTDSThe default is %SYSTEMROOT%\NTDS. 重要事項:未儲存的資料復原檔案系統 (ReFS) 格式化的磁碟區上的 Active Directory 登入檔案。Important: Do not store the Active Directory log files on a data volume formatted with Resilient File System (ReFS).
MoveInfrastructureOperationMasterRoleIfNecessaryMoveInfrastructureOperationMasterRoleIfNecessary 指定要傳輸到您要建立 」 中目前置於主機通用案例 」 並不想讓的網域控制站的網域控制站的基礎結構主機操作主角 (也稱為彈性的單一主機操作或 FSMO),您是否要建立通用伺服器。Specifies whether to transfer the infrastructure master operations master role (also known as flexible single master operations or FSMO) to the domain controller that you are creating"in case it is currently hosted on a global catalog server"and you do not plan to make the domain controller that you are creating a global catalog server. 指定基礎結構主角傳輸到您所建立轉送是需要; 網域控制站此參數若是如此,指定NoGlobalCatalog如果您想要保留目前所在的基礎結構主角選項。Specify this parameter to transfer the infrastructure master role to the domain controller that you are creating in case the transfer is needed; in this case, specify the NoGlobalCatalog option if you want the infrastructure master role to remain where it currently is.
NewDomainName ** **請注意:所需的安裝-ADDSDomain 只。NewDomainName Note: Required only for Install-ADDSDomain. 指定新的網域單一網域名稱。Specifies the single domain name for the new domain.

例如,如果您想要建立新的子女網域名為emea.corp.fabrikam.com,您應該會指定emea為這個引數。For example, if you want to create a new child domain named emea.corp.fabrikam.com, you should specify emea as the value of this argument.
NewDomainNetbiosNameNewDomainNetbiosName

如果超過 15 字元 FQDN 前置詞名稱所需安裝-ADDSDomain。Required for Install-ADDSDomain if FQDN prefix name is longer than 15 characters.
安裝-ADDSDomain 搭配使用。Use with Install-ADDSDomain. 將 NetBIOS 名稱指派給新的網域。Assigns a NetBIOS name to the new domain. 預設值源自的值「 NewDomainNameThe default value is derived from the value of "NewDomainName.
NoDnsOnNetworkNoDnsOnNetwork 指定 DNS 服務不是可用的網路。Specifies that DNS service is not available on the network. 使用此參數才並未設定 IP 設定,這台電腦的網路介面卡的名稱解析 DNS 伺服器的名稱。This parameter is used only when the IP setting of the network adapter for this computer is not configured with the name of a DNS server for name resolution. 這表示 DNS 伺服器,將會在這台電腦的名稱解析安裝。It indicates that a DNS server will be installed on this computer for name resolution. 否則,IP 設定的網路介面卡的第一次必須 DNS 伺服器位址設定。Otherwise, the IP settings of the network adapter must first be configured with the address of a DNS server.

省略 (預設值) 此參數,表示 client 的 TCP/IP 設定此伺服器上的網路介面卡將會使用連絡 DNS 伺服器。Omitting this parameter (the default) indicates that the TCP/IP client settings of the network adapter on this server computer will be used to contact a DNS server. 因此,如果您不指定此參數,確定 TCP/IP client 設定的第一次設定慣用 DNS 伺服器位址。Therefore, if you are not specifying this parameter, ensure that TCP/IP client settings are first configured with a preferred DNS server address.
NoGlobalCatalogNoGlobalCatalog 指定您不想要為通用伺服器的網域控制站。Specifies that you do not want the domain controller to be a global catalog server.

執行 Windows Server 2012 」 的網域控制站安裝通用使用預設。Domain controllers that run Windows Server 2012 are installed with the global catalog by default. 亦即,這會自動執行而不需要的計算,除非您指定:In other words, this runs automatically without computation, unless you specify:

程式碼-Code -

-NoGlobalCatalog-NoGlobalCatalog
NoRebootOnCompletionNoRebootOnCompletion 指定要命令,無論成功完成電腦重新開機。Specifies whether to restart the computer upon completion of the command, regardless of success. 根據預設,電腦將會重新開機。By default, the computer will restart. 若要防止伺服器重新,指定:To prevent the server from restarting, specify:

程式碼-Code -

-NoRebootOnCompletion: $True-NoRebootOnCompletion:$True

還有不相當於在使用者介面 (UI),此選項。There is no equivalent for this option in the user interface (UI).
ParentDomainName ** **請注意:所需的安裝-ADDSDomain cmdletParentDomainName Note: Required for Install-ADDSDomain cmdlet 指定現有家長網域的 FQDN。Specifies the FQDN of an existing parent domain. 當您安裝新的網域樹或子女網域,您可以使用此引數。You use this argument when you install a child domain or new domain tree.

例如,如果您想要建立新的子女網域名為emea.corp.fabrikam.com,您應該會指定corp.fabrikam.com為這個引數。For example, if you want to create a new child domain named emea.corp.fabrikam.com, you should specify corp.fabrikam.com as the value of this argument.
ReadOnlyReplicaReadOnlyReplica 指定要安裝的唯讀網域控制站 (RODC)。Specifies whether to install a read-only domain controller (RODC).
ReplicationSourceDCReplicationSourceDC 代表您要從中複製的網域資訊的合作夥伴網域控制站的 FQDN。Indicates the FQDN of the partner domain controller from which you replicate the domain information. 預設會自動運算。The default is automatically computed.
SafeModeAdministratorPasswordSafeModeAdministratorPassword 當您的電腦開始使用 「 安全模式 」 或 「 安全模式下,例如 Directory 服務還原模式的 variant 會提供系統管理員密碼。Supplies the password for the administrator account when the computer is started in Safe Mode or a variant of Safe Mode, such as Directory Services Restore Mode.

預設會是空白的密碼。The default is an empty password. 您必須輸入密碼。You must supply a password. 必須 System.Security.SecureString 格式,例如所提供的讀取主機-assecurestring 或 ConvertTo-SecureString 提供密碼。The password must be supplied in a System.Security.SecureString format, such as that provided by read-host -assecurestring or ConvertTo-SecureString.

SafeModeAdministratorPassword 引數作業特殊: 如果未指定為引數,cmdlet 會提示您輸入並確認遮罩的密碼。The SafeModeAdministratorPassword argument's operation is special:If not specified as an argument, the cmdlet prompts you to enter and confirm a masked password. 執行 cmdlet 互動時,這是慣用的使用方式。如果指定不值,而且有其他引數指定給 cmdlet、 cmdlet 會提示您輸入而確認遮罩的密碼。This is the preferred usage when running the cmdlet interactively.If specified without a value, and there are no other arguments specified to the cmdlet, the cmdlet prompts you to enter a masked password without confirmation. 執行 cmdlet 互動時,這是不慣用的使用方式。如果指定值,值必須安全字串。This is not the preferred usage when running the cmdlet interactively.If specified with a value, the value must be a secure string. 執行 cmdlet 互動時,這是不慣用的使用方式。例如您可以手動提示密碼提示安全字串的使用者使用朗讀主機 cmdlet:-safemodeadministratorpassword (讀取主機-命令提示字元中 」 的密碼: 「-assecurestring) 您也可以提供安全字串為轉換明文變數,雖然這是非常不建議使用。This is not the preferred usage when running the cmdlet interactively.For example, you can manually prompt for a password by using the Read-Host cmdlet to prompt the user for a secure string:-safemodeadministratorpassword (read-host -prompt "Password:" -assecurestring)You can also provide a secure string as a converted clear-text variable, although this is highly discouraged. -safemodeadministratorpassword (convertto securestring 「 Password1 「-asplaintext-強制)-safemodeadministratorpassword (convertto-securestring "Password1" -asplaintext -force)
站台名稱SiteName

所需的新增-addsreadonlydomaincontrolleraccount cmdletRequired for the Add-addsreadonlydomaincontrolleraccount cmdlet
指定的網域控制站會安裝所在的網站。Specifies the site where the domain controller will be installed. 有任何「 站台名稱引數當您執行安裝-ADDSForest因為建立的第一個網站預設先網站的名稱。There is no "sitename argument when you run Install-ADDSForest because the first site created is Default-First-Site-Name.

網站名稱必須存在時引數提供-站台名稱The site name must already exist when provided as an argument to -sitename. Cmdlet 不會建立該網站。The cmdlet will not create the site.
SkipAutoConfigureDNSSkipAutoConfigureDNS 略過 DNS client 設定、 轉送程式,以及根提示自動設定。Skips automatic configuration of DNS client settings, forwarders, and root hints. 此引數才有效的 DNS 伺服器服務已安裝或使用自動安裝-InstallDNSThis argument is in effect only if the DNS Server service is already installed or automatically installed with -InstallDNS.
SystemKeySystemKey 指定您要從中複製資料媒體系統鍵。Specifies the system key for the media from which you replicate the data.

預設值是The default is none.

資料必須朗讀主機-assecurestring 或 ConvertTo-SecureString 所提供的格式。Data must be in format provided by read-host -assecurestring or ConvertTo-SecureString.
SysvolPathSysvolPath 例如,在本機電腦的硬碟指定,非-注意到 directory C:\Windows\SYSVOLSpecifies the fully qualified, non-UNC path to a directory on a fixed disk of the local computer, for example, C:\Windows\SYSVOL.

預設值是%SYSTEMROOT%\SYSVOLThe default is %SYSTEMROOT%\SYSVOL. 重要事項: SYSVOL 無法儲存的資料復原檔案系統 (ReFS) 格式化的磁碟區上。Important: SYSVOL cannot be stored on a data volume formatted with Resilient File System (ReFS).
SkipPreChecksSkipPreChecks 不會執行開始安裝之前的必要條件檢查。Does not run the prerequisite checks before starting installation. 不建議使用此設定。It is not advisable to use this setting.
WhatIfWhatIf 如果是執行 cmdlet 會發生的事情顯示。Shows what would happen if the cmdlet runs. Cmdlet 不會執行。The cmdlet is not run.

指定 Windows PowerShell 認證Specifying Windows PowerShell Credentials

您可以指定認證,而不會顯示他們在螢幕上的一般使用取得認證You can specify credentials without revealing them in plain text on screen by using Get-credential.

這項操作-SafeModeAdministratorPassword 和 LocalAdministratorPassword 引數是特殊:The operation for the -SafeModeAdministratorPassword and LocalAdministratorPassword arguments is special:

  • 如果無法為引數指定,cmdlet 會提示您輸入並確認遮罩的密碼。If not specified as an argument, the cmdlet prompts you to enter and confirm a masked password. 執行 cmdlet 互動時,這是慣用的使用方式。This is the preferred usage when running the cmdlet interactively.

  • 如果指定值,值必須安全字串。If specified with a value, the value must be a secure string. 執行 cmdlet 互動時,這是不慣用的使用方式。This is not the preferred usage when running the cmdlet interactively.

例如,您可以手動提示密碼使用朗讀主機cmdlet 提示使用者安全字串For example, you can manually prompt for a password by using the Read-Host cmdlet to prompt the user for a secure string

-SafeModeAdministratorPassword (Read-Host -Prompt "DSRM Password:" -AsSecureString)

警告

在前一個選項不會確認密碼、 小心謹慎: 看不到密碼。As the previous option does not confirm the password, use extreme caution: the password is not visible.

您也可以提供安全字串為轉換明文變數,雖然這是高度建議:You can also provide a secure string as a converted clear-text variable, although this is highly discouraged:

-SafeModeAdministratorPassword (ConvertTo-SecureString "Password1" -AsPlainText -Force)

警告

不建議提供或儲存明文密碼。Providing or storing a clear text password is not recommended. 任何人指令碼執行這個命令或在您身邊尋找知道網域控制站 DSRM 的密碼。Anyone running this command in a script or looking over your shoulder knows the DSRM password of that domain controller. 有了這個認知,他們可以模擬本身的網域控制站及他們的權限提高至 Active Directory 森林中的最高層級。With that knowledge, they can impersonate the domain controller itself and elevate their privilege to the highest level in an Active Directory forest.

使用測試 cmdletUsing test cmdlets

每個 ADDSDeployment cmdlet 已測試 cmdlet 相對應。Each ADDSDeployment cmdlet has a corresponding test cmdlet. 測試 cmdlet 執行的必要條件檢查安裝作業。未安裝設定設定。The test cmdlets runs only the prerequisite checks for the installation operation; no installation settings are configured. 每個測試 cmdlet 引數是對應安裝 cmdlet,一樣,但「 SkipPreChecks不適用於 cmdlet 測試。The arguments for each test cmdlet are the same as for the corresponding installation cmdlet, but "SkipPreChecks is not available for test cmdlets.

測試 cmdletTest cmdlet 描述Description
Test-ADDSForestInstallationTest-ADDSForestInstallation 執行適用於安裝新的 Active Directory 樹系的必要條件。Runs the prerequisites for installing a new Active Directory forest.
Test-ADDSDomainInstallationTest-ADDSDomainInstallation 執行 Active Directory 中安裝新的網域的必要條件。Runs the prerequisites for installing a new domain in Active Directory.
Test-ADDSDomainControllerInstallationTest-ADDSDomainControllerInstallation 執行 Active Directory 中安裝網域控制站的必要條件。Runs the prerequisites for installing a domain controller in Active Directory.
Test-ADDSReadOnlyDomainControllerAccountCreationTest-ADDSReadOnlyDomainControllerAccountCreation (RODC) account 執行新增唯讀網域控制站的必要條件。Runs the prerequisites for adding a read-only domain controller (RODC) account.

安裝新的樹系根網域使用 Windows PowerShellInstalling a new forest root domain using Windows PowerShell

適用於安裝新的樹系的命令語法如下所示。The command syntax for installing a new forest is as follows. 選擇性引數會出現在方括弧。Optional arguments appear within square brackets.

Install-ADDSForest [-SkipPreChecks] -DomainName <string> -SafeModeAdministratorPassword <SecureString> [-CreateDNSDelegation] [-DatabasePath <string>] [-DNSDelegationCredential <PS Credential>] [-NoDNSOnNetwork] [-DomainMode <DomainMode> {Win2003 | Win2008 | Win2008R2 | Win2012}] [-DomainNetBIOSName <string>] [-ForestMode <ForestMode> {Win2003 | Win2008 | Win2008R2 | Win2012}] [-InstallDNS] [-LogPath <string>] [-NoRebootOnCompletion] [-SkipAutoConfigureDNS] [-SYSVOLPath] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]  

注意

如果您想要變更的 15 字元名稱所自動根據 DNS 網域名稱前置詞或名稱超過 15 字元需要-DomainNetBIOSName 引數。The -DomainNetBIOSName argument is required if you want to change the 15-character name that is automatically generated based on the DNS domain name prefix or if the name exceeds 15 characters.

例如,安裝新的樹系名 corp.contoso.com 和安全地提供 DSRM 密碼提示,請輸入:For example, to install a new forest named corp.contoso.com and be securely prompted to provide the DSRM password, type:

Install-ADDSForest -DomainName "corp.contoso.com"   

注意

當您執行安裝-ADDSForest 預設會安裝 DNS 伺服器。DNS server is installed by default when you run Install-ADDSForest.

若要安裝新的樹系名 corp.contoso.com、 contoso.com 網域中建立 DNS 委派、 網域正常運作的層級設定為 Windows Server 2008 R2 森林功能層級設定為 Windows Server 2008、 安裝 D:\ 磁碟機上的 Active Directory 資料庫和 SYSVOL、 安裝登入 E:\ 磁碟機上的檔案並將提示提供 Directory 服務還原模式密碼並輸入:To install a new forest named corp.contoso.com, create a DNS delegation in the contoso.com domain, set domain functional level to Windows Server 2008 R2 and set forest functional level to Windows Server 2008, install the Active Directory database and SYSVOL on the D:\ drive, install the log files on the E:\ drive, and be prompted to provide the Directory Services Restore Mode password and type:

Install-ADDSForest -DomainName corp.contoso.com -CreateDNSDelegation -DomainMode Win2008 -ForestMode Win2008R2 -DatabasePath "d:\NTDS" -SYSVOLPath "d:\SYSVOL" -LogPath "e:\Logs"   

安裝新的子女或樹網域使用 Windows PowerShellInstalling a new child or tree domain using Windows PowerShell

適用於安裝新的網域命令語法如下所示。The command syntax for installing a new domain is as follows. 選擇性引數會出現在方括弧。Optional arguments appear within square brackets.

Install-ADDSDomain [-SkipPreChecks] -NewDomainName <string> -ParentDomainName <string> -SafeModeAdministratorPassword <SecureString> [-ADPrepCredential <PS Credential>] [-AllowDomainReinstall] [-CreateDNSDelegation] [-Credential <PS Credential>] [-DatabasePath <string>] [-DNSDelegationCredential <PS Credential>] [-NoDNSOnNetwork] [-DomainMode <DomainMode> {Win2003 | Win2008 | Win2008R2 | Win2012}] [DomainType <DomainType> {Child Domain | TreeDomain} [-InstallDNS] [-LogPath <string>] [-NoGlobalCatalog] [-NewDomainNetBIOSName <string>] [-NoRebootOnCompletion] [-ReplicationSourceDC <string>] [-SiteName <string>] [-SkipAutoConfigureDNS] [-Systemkey <SecureString>] [-SYSVOLPath] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]  

注意

-認證引數只有需要當您未目前登入的企業系統管理員群組成員。The -credential argument is only required when you are not currently logged on as a member of the Enterprise Admins group.

-NewDomainNetBIOSName如果您想要變更自動根據 DNS 網域名稱前置詞的 15 字元名稱或名稱超過 15 字元,則需要引數。The -NewDomainNetBIOSName argument is required if you want to change the automatically generated 15-character name based on the DNS domain name prefix or if the name exceeds 15 characters.

例如使用 corp\EnterpriseAdmin1 的憑證來建立新的子女網域名稱 child.corp.contoso.com,安裝 DNS 伺服器、 corp.contoso.com 網域中建立 DNS 委派、 網域正常運作的層級設定為 Windows Server 2003、 進行網域控制站通用伺服器名休斯頓網站、 DC1.corp.contoso.com 當做複寫來源網域控制站、 安裝 D:\ 磁碟機上的 Active Directory 資料庫和 SYSVOL登入上安裝檔案 E:\ 磁碟機,並提供 Directory 服務還原模式的密碼,但不是會提示您確認命令中,輸入提示:For example, to use credentials of corp\EnterpriseAdmin1 to create a new child domain named child.corp.contoso.com, install DNS server, create a DNS delegation in the corp.contoso.com domain, set domain functional level to Windows Server 2003, make the domain controller a global catalog server in a site named Houston, use DC1.corp.contoso.com as the replication source domain controller, install the Active Directory database and SYSVOL on the D:\ drive, install the log files on the E:\ drive, and be prompted to provide the Directory Services Restore Mode password but not prompted to confirm the command, type:

Install-ADDSDomain -SafeModeAdministratorPassword -Credential (get-credential corp\EnterpriseAdmin1) -NewDomainName child -ParentDomainName corp.contoso.com -InstallDNS -CreateDNSDelegation -DomainMode Win2003 -ReplicationSourceDC DC1.corp.contoso.com -SiteName Houston -DatabasePath "d:\NTDS" "SYSVOLPath "d:\SYSVOL" -LogPath "e:\Logs" -Confirm:$False  

安裝其他 (複本) 網域控制站使用 Windows PowerShellInstalling an additional (replica) domain controller using Windows PowerShell

安裝其他的網域控制站的命令語法如下所示。The command syntax for installing an additional domain controller is as follows. 選擇性引數會出現在方括弧。Optional arguments appear within square brackets.

Install-ADDSDomainController -DomainName <string> [-SkipPreChecks] -SafeModeAdministratorPassword <SecureString> [-ADPrepCredential <PS Credential>] [-AllowDomainControllerReinstall] [-ApplicationPartitionsToReplicate <string[]>] [-CreateDNSDelegation] [-Credential <PS Credential>] [-CriticalReplicationOnly] [-DatabasePath <string>] [-DNSDelegationCredential <PS Credential>] [-NoDNSOnNetwork] [-NoGlobalCatalog] [-InstallationMediaPath <string>] [-InstallDNS] [-LogPath <string>] [-MoveInfrastructureOperationMasterRoleIfNecessary] [-NoRebootOnCompletion] [-ReplicationSourceDC <string>] [-SiteName <string>] [-SkipAutoConfigureDNS] [-SystemKey <SecureString>] [-SYSVOLPath <string>] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]  

若要安裝的網域控制站和 DNS 伺服器 corp.contoso.com 網域中,並提示您提供系統管理員認證網域和 DSRM 密碼,輸入To install a domain controller and DNS server in the corp.contoso.com domain and be prompted to supply the domain Administrator credentials and the DSRM password, type:

Install-ADDSDomainController -Credential (Get-Credential CORP\Administrator) -DomainName "corp.contoso.com"

如果您的電腦已經加入網域與您的網域管理群組成員,您可以使用:If the computer is already domain joined and you are a member of the Domain Admins group, you can use:

Install-ADDSDomainController -DomainName "corp.contoso.com"  

若要會提示輸入的網域名稱,請輸入:To be prompted for the domain name, type:

Install-ADDSDomainController -Credential (Get-Credential) -DomainName (Read-Host "Domain to promote into")

下列命令會使用 Contoso\EnterpriseAdmin1 認證安裝名為波士頓網站寫入網域控制站和通用伺服器、 安裝的 DNS 伺服器、 contoso.com 網域中建立 DNS 委派、 安裝媒體 c:\ADDS IFM 資料夾中儲存的、 安裝 D:\ 磁碟機上的 Active Directory 資料庫和 SYSVOL,請安裝登入 E:\ 磁碟機上的檔案有伺服器會自動重新開機之後 AD DS 安裝完成後,並提示您提供 Directory 服務還原模式的密碼:The following command will use credentials of Contoso\EnterpriseAdmin1 to install a writable domain controller and a global catalog server in a site named Boston, install DNS server, create a DNS delegation in the contoso.com domain, install from media that is stored in the c:\ADDS IFM folder, install the Active Directory database and SYSVOL on the D:\ drive, install the log files on the E:\ drive, have the server automatically restart after AD DS installation is complete, and be prompted to provide the Directory Services Restore Mode password:

Install-ADDSDomainController -Credential (Get-Credential CONTOSO\EnterpriseAdmin1) -CreateDNSDelegation -DomainName corp.contoso.com -SiteName Boston -InstallationMediaPath "c:\ADDS IFM" -DatabasePath "d:\NTDS" -SYSVOLPath "d:\SYSVOL" -LogPath "e:\Logs"   

執行階段的 RODC 安裝使用 Windows PowerShellPerforming a staged RODC installation using Windows PowerShell

命令語法建立 RODC account 如下所示。The command syntax to create an RODC account is as follows. 選擇性引數會出現在方括弧。Optional arguments appear within square brackets.

Add-ADDSReadOnlyDomainControllerAccount [-SkipPreChecks] -DomainControllerAccuntName <string> -DomainName <string> -SiteName <string> [-AllowPasswordReplicationAccountName <string []>] [-NoGlobalCatalog] [-Credential <PS Credential>] [-DelegatedAdministratorAccountName <string>] [-DenyPasswordReplicationAccountName <string []>] [-InstallDNS] [-ReplicationSourceDC <string>] [-Force] [-WhatIf] [-Confirm] [<Common Parameters>]  

以下是命令語法 RODC 過去連接伺服器。The command syntax to attach a server to an RODC account is as follows. 選擇性引數會出現在方括弧。Optional arguments appear within square brackets.

Install-ADDSDomainController -DomainName <string> [-SkipPreChecks] -SafeModeAdministratorPassword <SecureString> [-ADPrepCredential <PS Credential>] [-ApplicationPartitionsToReplicate <string[]>] [-Credential <PS Credential>] [-CriticalReplicationOnly] [-DatabasePath <string>] [-NoDNSOnNetwork] [-InstallationMediaPath <string>] [-InstallDNS] [-LogPath <string>] [-MoveInfrastructureOperationMasterRoleIfNecessary] [-NoRebootOnCompletion] [-ReplicationSourceDC <string>] [-SkipAutoConfigureDNS] [-SystemKey <SecureString>] [-SYSVOLPath <string>] [-UseExistingAccount] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]  

例如,為您建立 RODC 帳號名 RODC1:For example, to create an RODC account named RODC1:

Add-ADDSReadOnlyDomainControllerAccount -DomainControllerAccountName RODC1 -DomainName corp.contoso.com -SiteName Boston DelegatedAdministratoraccountName PilarA  

然後執行下列命令,以您想要附加到 RODC1 account 的伺服器上。Then run the following commands on the server that you want to attach to the RODC1 account. 無法加入網域的伺服器。The server cannot be joined to the domain. 首先,請安裝 AD DS 伺服器角色與管理工具:First, install the AD DS server role and management tools:

Install-WindowsFeature -Name AD-Domain-Services -IncludeManagementTools

執行下列命令,以建立 RODC:The run the following command to create the RODC:

Install-ADDSDomainController -DomainName corp.contoso.com -SafeModeAdministratorPassword (Read-Host -Prompt "DSRM Password:" -AsSecureString) -Credential (Get-Credential Corp\PilarA) -UseExistingAccount

Y以確認或包含[確認以避免確認提示引數。Press Y to confirm or include the "confirm argument to prevent the confirmation prompt.

使用伺服器管理員安裝 AD DSInstalling AD DS by using Server Manager

AD DS 可以在 Windows Server 2012 中安裝在伺服器管理員中,後面 Active Directory Domain Services 組態精靈,這是在 Windows Server 2012 中的新開始使用新增角色精靈。AD DS can be installed in Windows Server 2012 by using the Add Roles Wizard in Server Manager, followed by the Active Directory Domain Services Configuration Wizard, which is new beginning in Windows Server 2012 . Active Directory Domain Services 安裝精靈 (dcpromo.exe) 會取代開始在 Windows Server 2012 中。The Active Directory Domain Services Installation Wizard (dcpromo.exe) is deprecated beginning in Windows Server 2012 .

下列章節有關如何建立伺服器集區,才能安裝及管理 AD DS 在多部伺服器,以及如何使用精靈安裝 AD DS。The following sections explain how to create server pools in order to install and manage AD DS on multiple servers, and how to use the wizards to install AD DS.

建立伺服器集區Creating server pools

伺服器管理員可集區其他網路上的伺服器,只要的電腦上執行伺服器管理員可存取。Server Manager can pool other servers on the network as long as they are accessible from the computer running Server Manager. 之後共用,您可以選擇那些伺服器遠端安裝 AD DS,或在伺服器管理員中可能任何其他設定選項。Once pooled, you choose those servers for remote installation of AD DS or any other configuration options possible within Server Manager. 伺服器管理員會自動執行電腦集區本身。The computer running Server Manager automatically pools itself. 如需伺服器集區的詳細資訊,請查看新增伺服器伺服器管理員以For more information about server pools, see Add Servers to Server Manager.

注意

為了管理伺服器管理員使用群組伺服器,或相反加入網域的電腦,則需要額外的設定步驟。In order to manage a domain-joined computer using Server Manager on a workgroup server, or vice-versa, additional configuration steps are needed. 如需詳細資訊,請查看 「 新增和管理工作群組中的伺服器 」 中新增伺服器伺服器管理員以For more information, see "Add and manage servers in workgroups" in Add Servers to Server Manager.

安裝 AD DSInstalling AD DS

管理認證Administrative credentials

安裝 AD DS 的認證需求會在您選擇要部署的設定視而有所不同。The credential requirements to install AD DS vary depending on which deployment configuration you choose. 如需詳細資訊,請查看認證需求執行 Adprep.exe 並安裝 Active Directory Domain ServicesFor more information, see Credential requirements to run Adprep.exe and install Active Directory Domain Services.

使用下列程序安裝 AD DS 使用 GUI 方法。Use the following procedures to install AD DS using the GUI method. 在本機或遠端步驟執行。The steps can be performed locally or remotely. 適用於更多需下列步驟進行,查看下列主題:For more detailed explanation of these steps, see the following topics:

若要使用伺服器管理員安裝 AD DSTo install AD DS by using Server Manager
  1. 在伺服器管理員中,按一下管理,按一下 [新增角色與功能到開始畫面新增角色精靈。In Server Manager, click Manage and click Add Roles and Features to start the Add Roles Wizard.

  2. 在您開始之前頁面上,按一下 [On the Before you begin page, click Next.

  3. 選擇安裝類型頁面上,按一下 [以角色為基礎,或為基礎的功能的安裝,然後按一下 [下一步On the Select installation type page, click Role-based or feature-based installation and then click Next.

  4. 選取目的伺服器頁面上,按一下 [選取伺服器伺服器集區的,按一下您要安裝 AD DS,然後按一下 [伺服器名稱下一步On the Select destination server page, click Select a server from the server pool, click the name of the server where you want to install AD DS and then click Next.

    若要選取 [遠端伺服器,第一次建立集區伺服器,並加入遠端伺服器。To select remote servers, first create a server pool and add the remote servers to it. 如需有關建立伺服器集區的詳細資訊,請查看新增伺服器伺服器管理員以For more information about creating server pools, see Add Servers to Server Manager.

  5. 選取伺服器角色頁面上,按一下 [ Active Directory Domain Services,然後在 [新增角色與功能精靈對話方塊中,按一下新增功能,,然後按一下 [下一步On the Select server roles page, click Active Directory Domain Services, then on the Add Roles and Features Wizard dialog box, click Add Features, and then click Next.

  6. 選擇功能頁面上,選取您想要安裝按一下任何其他功能On the Select features page, select any additional features you want to install and click Next.

  7. Active Directory Domain Services頁面上,檢視的資訊,然後按一下On the Active Directory Domain Services page, review the information and then click Next.

  8. 確認安裝選項頁面上,按安裝On the Confirm installation selections page, click Install.

  9. 結果頁面上,確認已成功完成,再按一下安裝此為網域控制站伺服器升級以開始 Active Directory Domain Services 組態精靈。On the Results page, verify that the installation succeeded, and click Promote this server to a domain controller to start the Active Directory Domain Services Configuration Wizard.

    安裝 AD DS

    重要

    如果您不需要從 Active Directory Domain Services 組態精靈關閉新增角色精靈此時,您可以重新它,即可在伺服器管理員中的工作。If you close Add Roles Wizard at this point without starting the Active Directory Domain Services Configuration Wizard, you can restart it by clicking Tasks in Server Manager.

    安裝 AD DS

  10. 部署組態頁面上,選擇下列其中一個選項:On the Deployment Configuration page, choose one of the following options:

    • 如果您安裝其他網域控制站現有網域中,按一下 [現有的網域中加入的網域控制站,並輸入網域 (例如,emea.corp.contoso.com) 的名稱,或按選取...選擇加入網域和認證 (例如,指定為網域管理群組成員),然後按一下 [If you are installing an additional domain controller in an existing domain, click Add a domain controller to an existing domain, and type the name of the domain (for example, emea.corp.contoso.com) or click Select... to choose a domain, and credentials (for example, specify an account that is a member of the Domain Admins group) and then click Next.

      注意

      只有當電腦已加入網域,而且您執行的是本機安裝預設提供的網域目前使用者的認證的名稱。The name of the domain and current user credentials are supplied by default only if the machine is domain-joined and you are performing a local installation. 如果您遠端伺服器上安裝 AD DS,您需要設計來指定憑證。If you are installing AD DS on a remote server, you need to specify the credentials, by design. 如果不足以執行安裝目前使用者的認證,請按一下變更...以指定不同的認證。If current user credentials are not sufficient to perform the installation, click Change... in order to specify different credentials.

      如需詳細資訊,請查看安裝複本 Windows Server 2012 網域控制站在現有的網域和 #40;層級 200 和 #41;.For more information, see Install a Replica Windows Server 2012 Domain Controller in an Existing Domain (Level 200).

    • 如果您安裝新的子女網域,按一下 [現有的樹系新增新的網域選取網域型,選取子網域、 輸入瀏覽至父系網域 DNS 名稱 (例如,corp.contoso.com) 的名稱、 輸入相對新的子女網域名稱 (例如 emea) 輸入認證,以建立新的網域,並按一下 [使用下一步If you are installing a new child domain, click Add a new domain to an existing forest, for Select domain type, select Child Domain, type or browse to the name of the parent domain DNS name (for example, corp.contoso.com), type the relative name of the new child domain (for example emea), type credentials to use to create the new domain, and then click Next.

      如需詳細資訊,請查看安裝新 Windows Server 2012 Active Directory 子女或樹網域和 #40;層級 200 和 #41;.For more information, see Install a New Windows Server 2012 Active Directory Child or Tree Domain (Level 200).

    • 如果您安裝新的網域樹,按一下 [新增新的網域現有的樹系選取網域型,選取樹網域輸入根網域 (例如,corp.contoso.com) 的名稱、 輸入新的網域 (例如,fabrikam.com) 輸入認證,以用來建立新的網域,並按一下 [DNS 名稱下一步If you are installing a new domain tree, click Add new domain to an existing forest, for Select domain type, choose Tree Domain, type the name of the root domain (for example, corp.contoso.com), type the DNS name of the new domain (for example, fabrikam.com), type credentials to use to create the new domain, and then click Next.

      如需詳細資訊,請查看安裝新 Windows Server 2012 Active Directory 子女或樹網域和 #40;層級 200 和 #41;.For more information, see Install a New Windows Server 2012 Active Directory Child or Tree Domain (Level 200).

    • 如果您安裝新的樹系,按新增新的樹系,然後輸入名稱根網域 (例如,corp.contoso.com)。If you are installing a new forest, click Add a new forest and then type the name of the root domain (for example, corp.contoso.com).

      如需詳細資訊,請查看安裝新 Windows Server 2012 Active Directory 樹系和 #40;層級 200 和 #41;.For more information, see Install a New Windows Server 2012 Active Directory Forest (Level 200).

  11. 網域控制站選項頁面上,選擇下列其中一個選項:On the Domain Controller Options page, choose one of the following options:

    • 如果您要建立新的樹系或網域,選擇網域和森林功能層級,請按一下網域名稱系統 」 (DNS) 伺服器,指定 DSRM 密碼,然後按下一步If you are creating a new forest or domain, select the domain and forest functional levels, click Domain Name System (DNS) server, specify the DSRM password, and then click Next.

    • 如果您要加入的網域控制站現有的網域,按一下 [網域名稱系統 」 (DNS) 伺服器全球 Catalog (GC),或朗讀只網域控制站 (RODC)視需要選擇網站的名稱,並輸入 DSRM 密碼,然後按一下下一步If you are adding a domain controller to an existing domain, click Domain Name System (DNS) server, Global Catalog (GC), or Read Only Domain Controller (RODC) as needed, choose the site name, and type the DSRM password and then click Next.

    適用於相關的選項,在此頁面上的不同條件在無法使用或的詳細資訊,請查看網域控制站選項For more information about which options on this page are available or not available under different conditions, see Domain Controller Options.

  12. DNS 選項(,才會出現在您安裝的 DNS 伺服器) 頁面上,按一下 [更新 DNS 委派視。On the DNS Options page (which appears only if you install a DNS server), click Update DNS delegation as needed. 如果您執行動作時,提供認證所建立的 DNS 委派記錄家長 DNS 區域中的權限。If you do, provide credentials that have permission to create DNS delegation records in the parent DNS zone.

    如果無法連絡主控家長區域的 DNS 伺服器,更新 DNS 委派選項。If a DNS server that hosts the parent zone cannot be contacted, the Update DNS Delegation option is not available.

    如需有關您是否需要更新 DNS 委派的詳細資訊,請查看了解區域委派For more information about whether you need to update the DNS delegation, see Understanding Zone Delegation. 如果您嘗試更新 DNS 委派和發生錯誤,請查看DNS 選項If you attempt to update the DNS delegation and encounter an error, see DNS Options.

  13. RODC 選項頁面 (,才會出現在您安裝 RODC)、 群組或使用者將管理 RODC、 新增或移除帳號,從 [允許] 或 [拒絕密碼複寫群組],然後按一下帳號的名稱指定On the RODC Options page (which appears only if you install an RODC), specify the name of a group or user who will manage the RODC, add accounts to or remove accounts from the Allowed or Denied password replication groups, and then click Next.

    如需詳細資訊,請查看密碼複寫原則For more information, see Password Replication Policy.

  14. 的其他選項頁面上,選擇下列其中一個選項:On the Additional Options page, choose one of the following options:

    • 如果您要建立新的網域中,輸入新的 NetBIOS 名稱或驗證預設 NetBIOS 網域名稱,然後按一下下一步If you are creating a new domain, type a new NetBIOS name or verify the default NetBIOS name of the domain, and then click Next.

    • 如果您要加入的網域控制站現有的網域,選取您想要複寫 AD DS 安裝資料的 (或允許選取任何網域控制站精靈) 的網域控制站。If you are adding a domain controller to an existing domain, select the domain controller that you want to replicate the AD DS installation data from (or allow the wizard to select any domain controller). 如果您從媒體安裝,請按一下安裝媒體路徑的輸入並確認安裝來源檔案的路徑,然後按一下 [If you are installing from media, click Install from media path type and verify the path to the installation source files, and then click Next.

      您無法使用安裝媒體 (IFM) 來安裝網域中的第一個網域控制站的。You cannot use install from media (IFM) to install the first domain controller in a domain. IFM 跨不同的作業系統版本無法運作。IFM does not work across different operating system versions. 亦即,才能安裝其他網域控制站使用 IFM 執行 Windows Server 2012,您必須在 Windows Server 2012 網域控制站建立備份的媒體。In other words, in order to install an additional domain controller that runs Windows Server 2012 by using IFM, you must create the backup media on a Windows Server 2012 domain controller. 如需 IFM 的詳細資訊,請查看安裝其他的網域控制站使用 IFM 的For more information about IFM, see Installing an Additional Domain Controller by Using IFM.

  15. 路徑頁面上,輸入 Active Directory 資料庫、 登入檔案,以及 SYSVOL 資料夾位置 (或接受預設的位置),按On the Paths page, type the locations for the Active Directory database, log files, and SYSVOL folder (or accept default locations), and click Next.

    重要

    不要使用復原檔案系統 (ReFS) 格式化是資料磁碟區上儲存的 Active Directory 資料庫、 登入檔案或 SYSVOL 資料夾。Do not store the Active Directory database, log files, or SYSVOL folder on a data volume formatted with Resilient File System (ReFS).

  16. 準備選項頁面上,輸入認證,才能執行 adprep 滿足。On the Preparation Options page, type credentials that are sufficient to run adprep. 如需詳細資訊,請查看認證需求執行 Adprep.exe 並安裝 Active Directory Domain ServicesFor more information, see Credential requirements to run Adprep.exe and install Active Directory Domain Services.

  17. 評論選項頁面,確認您的選取項目,按檢視指令碼如果您想要的設定匯出 Windows PowerShell 指令碼,然後按一下 [下一步On the Review Options page, confirm your selections, click View script if you want to export the settings to a Windows PowerShell script, and then click Next.

  18. 必要條件檢查頁面,確認該必要條件驗證完成,然後按安裝On the Prerequisites Check page, confirm that prerequisite validation completed and then click Install.

  19. 結果頁面上確認為網域控制站伺服器已經設定成功。On the Results page, verify that the server was successfully configured as a domain controller. 伺服器將會自動重新啟動完成 AD DS 安裝。The server will be restarted automatically to complete the AD DS installation.

執行暫存 RODC 安裝使用圖形使用者介面Performing a Staged RODC Installation using the Graphical User Interface

階段的 RODC 安裝可讓您建立 RODC 兩個階段中。A staged RODC installation allows you to create an RODC in two stages. 在第一階段,網域管理群組成員建立 RODC account。In the first stage, a member of the Domain Admins group creates an RODC account. 在第二個階段中,RODC account 附加伺服器。In the second stage, a server is attached to the RODC account. 第二個階段可以完成的網域管理群組或委派的網域使用者或群組成員。The second stage can be completed by a member of the Domain Admins group or a delegated domain user or group.

若要使用的 Active Directory 管理工具建立 RODC accountTo create an RODC account by using the Active Directory management tools

  1. 您可以建立 RODC account 使用 Active Directory 管理中心 Active Directory 使用者或電腦。You can create the RODC account using Active Directory Administrative Center or Active Directory Users and Computers.

    1. 按一下[開始],按一下 [系統管理工具],然後按一下 [ Active Directory 管理中心Click Start, click Administrative Tools, and then click Active Directory Administrative Center.

    2. 在瀏覽窗格中 (左窗格中),按一下 [的網域名稱。In the navigation pane (left pane), click the name of the domain.

    3. 在 [管理清單 (中央窗格) 中,按一下 [網域控制站組織單位。In the Management list (center pane), click the Domain Controllers OU.

    4. 在 [工作] 窗格上 (右窗格),按一下預先建立唯讀網域控制站帳號In the Tasks Pane (right pane), click Pre-create a read-only domain controller account.

    -或者--Or-

    1. 按一下[開始],按一下系統管理工具],然後按一下 [ Active Directory 使用者與電腦Click Start, click Administrative Tools, and then click Active Directory Users and Computers.

    2. 任一以滑鼠右鍵按一下網域控制站單位 (組織單位) 或按一下網域控制站組織單位,然後按一下 [動作Either right-click the Domain Controllers organizational unit (OU) or click the Domain Controllers OU, and then click Action.

    3. 按一下預先建立唯讀網域控制站 accountClick Pre-create Read-only Domain Controller account.

  2. 歡迎 Active Directory Domain Services 安裝精靈頁面上,如果您想要修改密碼複寫原則 (PRP),選取的預設進階模式安裝使用,然後按一下 [下一步On the Welcome to the Active Directory Domain Services Installation Wizard page, if you want to modify the default the Password Replication Policy (PRP), select Use advanced mode installation, and then click Next.

  3. 網路認證頁面上,在指定 account 認證使用來執行安裝,按一下 [我目前登入認證,或按一下其他憑證,,然後按一下 [設定On the Network Credentials page, under Specify the account credentials to use to perform the installation, click My current logged on credentials or click Alternate credentials, and then click Set. Windows 安全性對話方塊方塊中,可以安裝其他網域控制站 account 提供使用者名稱和密碼。In the Windows Security dialog box, provide the user name and password for an account that can install the additional domain controller. 若要安裝的其他網域控制站,您必須的企業系統管理員或網域管理群組成員。To install an additional domain controller, you must be a member of the Enterprise Admins group or the Domain Admins group. 當您完成提供的認證,請按下一步When you are finished providing credentials, click Next.

  4. 電腦名稱指定頁面上,輸入電腦名稱會 RODC 的伺服器。On the Specify the Computer Name page, type the computer name of the server that will be the RODC.

  5. 選擇網站頁面上,從清單中選取網站或選取要安裝的網域控制站台中對應至執行精靈中,電腦的 IP 位址的選項,然後按一下On the Select a Site page, select a site from the list or select the option to install the domain controller in the site that corresponds to the IP address of the computer on which you are running the wizard, and then click Next.

  6. 其他網域控制站選項頁面,進行下列選項,然後再按一下:On the Additional Domain Controller Options page, make the following selections, and then click Next:

    • DNS 伺服器:,讓您的網域控制站可做的網域名稱系統 」 (DNS) 伺服器預設選取此選項。DNS server: This option is selected by default so that your domain controller can function as a Domain Name System (DNS) server. 如果您不想要的 DNS 伺服器的網域控制站,請清除此選項。If you do not want the domain controller to be a DNS server, clear this option. 不過,如果您不要安裝 RODC 和 RODC DNS 伺服器角色是分公司只網域控制站、 分公司使用者將無法執行離線中樞網站的寬形區域網路 (WAN) 時的名稱解析。However, if you do not install the DNS server role on the RODC and the RODC is the only domain controller in the branch office, users in the branch office will not be able to perform name resolution when the wide area network (WAN) to the hub site is offline.

    • 通用: 預設選取此選項。Global catalog: This option is selected by default. 通用將磁碟分割唯讀 directory 網域控制站新增,它可以讓通用搜尋功能。It adds the global catalog, read-only directory partitions to the domain controller, and it enables global catalog search functionality. 如果您不想要通用伺服器的網域控制站,請清除此選項。If you do not want the domain controller to be a global catalog server, clear this option. 不過,如果您不要安裝通用伺服器分公司或讓通用群組成員資格快取的網站,包括 RODC,使用者分公司中的將無法登入網域離線 WAN 中樞網站時。However, if you do not install a global catalog server in the branch office or enable universal group membership caching for the site that includes the RODC, users in the branch office will not be able to log on to the domain when the WAN to the hub site is offline.

    • 唯讀模式網域控制站Read-only domain controller. 當您建立 RODC 帳號時,預設會選取此選項,您無法將它清除。When you create an RODC account, this option is selected by default and you cannot clear it.

  7. 如果您選取 [使用進階模式安裝核取方塊歡迎使用頁面上,指定密碼複寫原則頁面隨即顯示。If you selected the Use advanced mode installation check box on the Welcome page, the Specify the Password Replication Policy page appears. 根據預設,不 account 密碼會複寫 rodc,,安全性相關 (例如網域管理群組成員) 明確拒絕從得更容易遇到複製到 RODC 其密碼。By default, no account passwords are replicated to the RODC, and security-sensitive accounts (such as members of the Domain Admins group) are explicitly denied from ever having their passwords replicated to the RODC.

    新增其他帳號原則,請按一下新增,然後按一下 [允許複製到此 RODC account 的密碼或按一下 [複製到此 RODC 拒絕 account 的密碼,然後選取 [帳號。To add other accounts to policy, click Add, then click Allow passwords for the account to replicate to this RODC or click Deny passwords for the account from replicating to this RODC and then select the accounts.

    在完成 (或接受預設設定),按一下 [下一步When complete (or to accept the default setting), click Next.

  8. RODC 委派安裝及管理頁面上,輸入 [使用者或群組的人員將會伺服器附加至 RODC 帳號,您所建立的名稱。On the Delegation of RODC Installation and Administration page, type the name of the user or the group who will attach the server to the RODC account that you are creating. 您可以輸入只有一個的安全性原則的名稱。You can type the name of only one security principal.

    若要搜尋 directory 特定的使用者或群組,請按一下設定To search the directory for a specific user or group, click Set. 選取使用者或群組中,輸入名稱的使用者或群組。In Select User or Group, type the name of the user or group. 我們建議您委派 RODC 安裝及管理到群組。We recommend that you delegate RODC installation and administration to a group.

    此使用者或群組也會有本機系統管理員權限在 RODC 之後安裝。This user or group will also have local administrative rights on the RODC after the installation. 如果您不指定的使用者或群組,將無法伺服器附加至 account 只有的網域管理員群組或企業系統管理員群組成員。If you do not specify a user or group, only members of the Domain Admins group or the Enterprise Admins group will be able to attach the server to the account.

    當您完成時,請按下一步When you are finished, click Next.

  9. 摘要頁面上,檢視您的選擇。On the Summary page, review your selections. 按一下若要變更任何選取項目。Click Back to change any selections, if necessary.

    若要儲存您選取的設定,您可以使用自動化後續 AD DS 作業,請按一下 [回應檔案設定匯出To save the settings that you selected to an answer file that you can use to automate subsequent AD DS operations, click Export settings. 輸入您的回應檔案的名稱,然後按一下儲存Type a name for your answer file, and then click Save.

    當您確定您的選擇是否正確,請按下一步以建立 RODC 帳號。When you are sure that your selections are accurate, click Next to create the RODC account.

  10. 完成 Active Directory Domain Services 安裝精靈頁面上,按完成]On the Completing the Active Directory Domain Services Installation Wizard page, click Finish.

建立 RODC 帳號之後,您可以完成 RODC 安裝過去附加伺服器。After an RODC account is created, you can attach a server to account to complete the RODC installation. 可以將位於 RODC 分公司完成此第二個階段。This second stage can be completed in the branch office where the RODC will be located. 您在執行此程序地方伺服器必須未加入網域。The server where you perform this procedure must not be joined to the domain. 從 Windows Server 2012 中,您使用新增角色精靈在伺服器管理員中 RODC 過去連接伺服器。Beginning in Windows Server 2012 , you use the Add Roles Wizard in Server Manager to attach a server to an RODC account.

若要使用伺服器管理員 RODC 過去附加伺服器To attach a server to an RODC account using Server Manager

  1. 本機系統管理員身分登入。Log on as local Administrator.

  2. 在伺服器管理員中,按一下新增角色與功能In Server Manager, click Add roles and features.

  3. 在您開始之前頁面上,按一下 [On the Before you begin page, click Next.

  4. 選擇安裝類型頁面上,按一下 [以角色為基礎,或為基礎的功能的安裝,然後按一下 [下一步On the Select installation type page, click Role-based or feature-based installation and then click Next.

  5. 選取目的伺服器頁面上,按一下 [選取伺服器伺服器集區的,按一下您要安裝 AD DS,然後按一下 [伺服器名稱下一步On the Select destination server page, click Select a server from the server pool, click the name of the server where you want to install AD DS and then click Next.

  6. 選擇伺服器角色頁面上,按一下 [ Active Directory Domain Services,按一下 [新增功能,然後按一下下一步On the Select server roles page, click Active Directory Domain Services, click Add Features and then click Next.

  7. 選擇功能頁面上,選取您想要安裝按一下任何其他功能On the Select features page, select any additional features that you want to install and click Next.

  8. Active Directory Domain Services頁面上,檢視的資訊,然後按一下On the Active Directory Domain Services page, review the information and then click Next.

  9. 確認安裝選項頁面上,按安裝On the Confirm installation selections page, click Install.

  10. 結果頁面上確認已成功安裝,並按一下 [此為網域控制站伺服器升級開始 Active Directory Domain Services 組態精靈。On the Results page, verify Installation succeeded, and click Promote this server to a domain controller to start the Active Directory Domain Services Configuration Wizard.

    重要

    如果您不需要從 Active Directory Domain Services 組態精靈關閉新增角色精靈此時,您可以重新它,即可在伺服器管理員中的工作。If you close Add Roles Wizard at this point without starting the Active Directory Domain Services Configuration Wizard, you can restart it by clicking Tasks in Server Manager.

    (media/Install-Active-Directory-Domain-Services--Level-100-/ADDS_SMI_Tasks.gif)(media/Install-Active-Directory-Domain-Services--Level-100-/ADDS_SMI_Tasks.gif)

  11. 部署設定頁面上,按一下 [現有的網域中加入的網域控制站,輸入 (例如,emea.contoso.com) 的網域名稱和認證 (例如,指定委派給管理及安裝 RODC account),然後按一下 [下一步On the Deployment Configuration page, click Add a domain controller to an existing domain, type the name of the domain (for example, emea.contoso.com) and credentials (for example, specify an account that is delegated to manage and install the RODC), and then click Next.

  12. 網域控制站選項頁面上,按使用現有 RODC account、 輸入並確認 Directory 服務還原模式密碼,然後按一下下一步On the Domain Controller Options page, click Use existing RODC account, type and confirm the Directory Services Restore Mode password, and then click Next.

  13. 的其他選項頁面上,如果您從媒體安裝按安裝媒體路徑的輸入並確認安裝來源檔案的路徑,然後選取您想要複寫 AD DS 安裝資料的 (或允許選取任何網域控制站精靈) 的網域控制站,然後按一下 [下一步On the Additional Options page, if you are installing from media, click Install from media path type and verify the path to the installation source files, select the domain controller that you want to replicate the AD DS installation data from (or allow the wizard to select any domain controller) and then click Next.

  14. 路徑頁面上,輸入位置 Active Directory 資料庫、 登入檔案,以及 SYSVOL 資料夾,或接受預設的位置,然後按一下On the Paths page, type the locations for the Active Directory database, log files, and SYSVOL folder, or accept default locations, and then click Next.

  15. 評論選項頁面,確認您的選項,按一下 [檢視指令碼來設定匯出 Windows PowerShell 指令碼,然後按一下 [下一步On the Review Options page, confirm your selections, click View Script to export the settings to a Windows PowerShell script, and then click Next.

  16. 必要條件檢查頁面,確認該必要條件驗證完成,然後按安裝On the Prerequisites Check page, confirm that prerequisite validation completed and then click Install.

    若要到 AD DS 安裝完成時,會自動重新伺服器。To complete the AD DS installation, the server will restart automatically.

也了See Also

疑難排解網域控制站部署Troubleshooting Domain Controller Deployment
安裝新的 Windows Server 2012 Active Directory 森林與 #40;層級 200 和 #41;Install a New Windows Server 2012 Active Directory Forest (Level 200)
安裝新的 Windows Server 2012 Active Directory 子女或樹網域和 #40;層級 200 和 #41;Install a New Windows Server 2012 Active Directory Child or Tree Domain (Level 200)
安裝複本 Windows Server 2012 網域控制站在現有的網域和 #40;層級 200 和 #41;Install a Replica Windows Server 2012 Domain Controller in an Existing Domain (Level 200)