This project demonstrates the deployment and administration of a small business Windows domain in a virtualized home-lab environment. I built the environment from the ground up using Hyper-V, Windows Server 2022, Windows 11 Pro, Active Directory Domain Services, DNS, DHCP, Group Policy, SMB shares, and NTFS permissions.
The fictional organization used for the lab is Cabrera Technologies, with the internal domain cabreralab.test.
- Deploy a Windows Server 2022 domain controller.
- Configure a private Hyper-V network for the lab.
- Install and configure Active Directory Domain Services and DNS.
- Design an organizational unit structure for a small business.
- Create departmental users and security groups.
- Apply least-privilege SMB and NTFS permissions.
- Join a Windows 11 Pro workstation to the domain.
- Deploy security settings and mapped drives through Group Policy.
- Configure DHCP for automatic client addressing.
- Reproduce, diagnose, and resolve a DNS configuration problem.
flowchart TD
Host["Windows 11 Pro Host<br>Hyper-V"]
Switch["LAB-SWITCH<br>10.10.10.0/24"]
DC["DC01<br>10.10.10.10<br>AD DS · DNS · DHCP · File Services"]
Client["CLIENT01<br>DHCP Client<br>Windows 11 Pro"]
Host --> Switch
Switch --> DC
Switch --> Client
| Component | Configuration |
|---|---|
| Hypervisor | Microsoft Hyper-V |
| Domain controller | DC01 — Windows Server 2022 Standard Evaluation |
| Client | CLIENT01 — Windows 11 Pro |
| Domain | cabreralab.test |
| NetBIOS name | CABRERALAB |
| Network | 10.10.10.0/24 |
| Server address | 10.10.10.10 |
| DHCP scope | 10.10.10.100–10.10.10.200 |
| Client DNS | 10.10.10.10 |
The lab was deployed from the ground up using the following workflow:
- Created the virtual lab environment in Hyper-V.
- Deployed Windows Server 2022 as
DC01. - Configured a static IP address and internal lab networking.
- Installed Active Directory Domain Services and DNS.
- Promoted
DC01to a domain controller forcabreralab.test. - Created the organizational unit structure, users, and security groups.
- Configured departmental SMB shares and NTFS permissions.
- Created and linked Group Policy Objects for workstation security and drive mapping.
- Installed and configured DHCP for automatic client addressing.
- Deployed
CLIENT01with Windows 11 Pro and joined it to the domain. - Tested domain authentication, Group Policy, drive mapping, permissions, DHCP, and DNS.
- Simulated and resolved a client DNS configuration issue.
Cabrera Technologies
├── Users
│ ├── IT
│ ├── Human Resources
│ ├── Finance
│ └── Sales
├── Computers
│ ├── Workstations
│ └── Servers
├── Groups
├── Service Accounts
└── Disabled Accounts
Global security groups were created for role-based access:
GG_IT_UsersGG_HR_UsersGG_Finance_UsersGG_Sales_UsersGG_HelpDesk_Tier1
Departmental SMB shares were created on DC01:
| Share | Authorized group | NTFS access |
|---|---|---|
\\DC01\IT |
GG_IT_Users | Modify |
\\DC01\HR |
GG_HR_Users | Modify |
\\DC01\Finance |
GG_Finance_Users | Modify |
\\DC01\Sales |
GG_Sales_Users | Modify |
\\DC01\Public |
Domain Users | Modify |
SYSTEM and Administrators retain Full Control. Departmental users receive
Modify instead of Full Control so they cannot change permissions or ownership.
The following policies were implemented:
- Machine inactivity limit: 600 seconds.
- Guest account disabled.
- Linked to the Workstations OU.
- Password history: 5 passwords.
- Maximum password age: 90 days.
- Minimum password age: 1 day.
- Minimum password length: 10 characters.
- Complexity requirements enabled.
- Account lockout after 5 invalid attempts.
- Lockout duration and reset counter: 15 minutes.
Group Policy Preferences and item-level targeting automatically map:
| Group | Drive |
|---|---|
| Domain Users | P: → \\DC01\Public |
| GG_IT_Users | I: → \\DC01\IT |
| GG_HR_Users | H: → \\DC01\HR |
| GG_Finance_Users | F: → \\DC01\Finance |
| GG_Sales_Users | S: → \\DC01\Sales |
For example, an IT user receives only the Public and IT drives.
DC01 provides DHCP leases from 10.10.10.100 through 10.10.10.200. Clients
receive 10.10.10.10 as their DNS server, allowing them to locate domain
services and resolve cabreralab.test.
The configuration was validated using:
ipconfig /all
nslookup cabreralab.test
dcdiag /test:dns
Get-DhcpServerv4ScopeSymptoms
CLIENT01could not resolvecabreralab.test.- Domain resources were unavailable.
Cause
The client was configured to use a public DNS server. Public DNS servers do not contain records for the private Active Directory domain.
Resolution
- Restored automatic DNS configuration from DHCP.
- Flushed the local DNS cache.
- Released and renewed the DHCP lease.
- Verified that the client received
10.10.10.10as DNS. - Confirmed successful domain resolution.
ipconfig /flushdns
ipconfig /release
ipconfig /renew
nslookup cabreralab.testThe completed environment was validated by:
- Joining CLIENT01 to
cabreralab.test. - Signing in with a domain user.
- Confirming that Group Policy applied successfully.
- Verifying automatic drive mapping based on group membership.
- Confirming access to authorized shares.
- Confirming Access Denied for unauthorized departmental shares.
- Confirming a valid DHCP lease and internal DNS resolution.
- Running a successful domain controller DNS health check.
- Windows Server administration
- Active Directory Domain Services
- DNS and DHCP
- Hyper-V virtualization
- TCP/IP configuration and troubleshooting
- Organizational units and identity administration
- Security groups and role-based access control
- SMB shares and NTFS permissions
- Group Policy Objects and Group Policy Preferences
- Windows domain joins
- PowerShell and command-line diagnostics
- Technical documentation
Selected screenshots demonstrating the deployment, configuration, and validation
of the Active Directory environment. The complete set of implementation evidence
is available in the screenshots directory.
The cabreralab.test domain was successfully deployed on DC01 using Windows
Server 2022 and Active Directory Domain Services.
Organizational Units were created to separate users, computers, departments, service accounts, and disabled accounts.
CLIENT01 was successfully joined to the cabreralab.test domain.
Domain authentication was validated by signing in to CLIENT01 using a domain user account.
Departmental permissions were tested to verify that authorized users could access their assigned resources while unauthorized access was denied.
Group Policy was successfully applied to CLIENT01, including automatic departmental drive mapping based on security group membership.
DC01 was configured as the DHCP server for the lab network.
A DNS misconfiguration was intentionally reproduced and resolved to demonstrate a common Active Directory troubleshooting scenario.
Final testing confirmed that Active Directory, DNS, DHCP, Group Policy, authentication, permissions, and domain services were functioning correctly.
Carlos Cabrera
CompTIA A+ Certified | IT Support and Systems Administration










