Last Updated on April 24, 2019

This guide is especially made for server admins and people who want to create a domain at their office, company or university. We will teach you how to create a domain and add users to it step by step, but first, read the next section if you want to know what exactly a domain.

So, what’s a domain?

A domain is a network. As a higher level network than Homegroups and Workgroups, it does require the presence of a computer running Windows Server (Windows Server 2012 R2 and 2016 are the most common now) and the other computer running Pro or Enterprise versions of Windows (Windows 10 Pro / Enterprise are the most powerful ones now).

Linking these machines using a domain makes it very easy for the user to work on any computer without feeling any difference: He or she just need to enter their username and password and they’ll find their personal version of the operating system (settings, files …etc).

This kind of network is very useful because you don’t have to offer every employee/student a private computer, their local account will be on the domain ready and easy to be accessed from any computer on the domain only by entering their credentials on the lock screen.

Here’s a full guide on how to create a domain and if you need help with how to join a domain, or want to send an explanation on that to the users in your network, check out this guide.

OK then, how do I create a domain?

First of all, make sure your Windows is activated. Follow these steps to do it:

  • Right-click on This PC in your start menu and select Properties.
  • If it’s activated, you’ll find it saying “Windows is activated” and you’ll see the product key. If it says Windows is not activated you’ll need to enter your key.

Now, let’s set a password for your administrator account.

Before creating a domain, Microsoft must ensure its safety. That’s why your administrator account must be protected by a password. Here’s how to set it:

  • Open Administrative tools from your Start menu.
  • Open Computer Management.
  • Select Local Users and Groups from the left pane and then double-click on the Users folder.
  • Right-click on Administrator and select Set Password... .
  • Click Proceed.
  • Enter and confirm your password. It must contain 8 characters at least, a combination of letters, symbols and numbers.
  • Click Ok.

Now, let’s create our domain

  • Open Server Manager from your taskbar or Start menu.
  • Click Add roles and features.
  • Click Next.
  • Leave it as it is by default (Role-based or featured-based installation) and click Next.
  • On the Server Selection page, you’ll find the Select a server from the server pool and the default server there. Select it and click Next.
  • Check Active Directory Domain Services.
  • In the pop-up window, click Add Features.
  • Now once checked, click Next.
  • Make sure Group Policy Management is checked and click Next.
  • Click Next.
  • Confirm all your selections and click Install.
  • Wait until the installation finishes then click Close.
  • Once done, you’ll see a notification on the flag icon. Click on it and select Promote this server to a domain controller.
  • Select Add a new forest and enter the domain name ending with .local and then click Next.
  • Create a DSRM password and confirm it then click Next.
  • Ignore the DNS warning and click Next.
  • Confirm the NetBIOS domain name (created by default) and click Next.
  • Confirm your paths and click Next.
  • Review your selections and click Next.
  • Click Install (Once finished, the computer will reboot automatically).

Now the domain is ready, let’s create a user to enable a computer on the network to join it.

How to create a user to join a domain?

  • Open Administrative Tools from your start menu.
  • Open Active Directory Users and Computers.
  • Go to the Users folder under your domain name from the left pane, right-click and choose New > User.
  • Enter the user First name, User logon name (You’ll provide the user this one) and click Next.
  • Enter a password and retype it, you’ll be able to choose from a set of options: You can force the user to change the password him/herself the first time he/she joins the domain, you can disallow them to change their password, you can make the password permanent without expiration and finally you can disable this account until you enable it back yourself as the domain admin.

Now, what should you provide to the user to join the domain?

  • The domain name.
  • The user logon name.
  • The user’s password.
  • Finally the server IP and let him/her set it as their primary DNS. This can make the connection to the server more reliable.

Here’s how to know you IP:

  • Right-click on your network icon at the clock area and then click Open Network and Sharing Center.
  • Click on the Connection you’re working on (Ethernet or the WIFI name).
  • Click on Details.
  • Now your IP is the IPv4 Address, give it to the user.


How to create a domain on Windows Server
4.3 (85.71%) 7 vote[s]

Still stuck? Ask your question in our forum!

About Author


Mina studies communications and electronics engineering and works as a technical support. He keeps himself up to date with the latest developments and news in technology. He loves helping people with their daily tech issues, so he's always ready to go the extra mile.


        • Avatar

          Well, if you’re using a standard Windows xp, vista, 7, 8, 8.1 or 10 versions, it’s impossible to upgrade your activation. The server series is not related to the normal one and you’ll need to purchase a new license for it.

  1. Avatar

    I have the windows 10 versions and based on what I’ve read, it is impossible to upgrade my activation. Could there be a chance to upgrade mine by using a different way? Just curious and hoping there could one possibility. Anyway, thanks for sharing!

    • Avatar

      Hello Ronnie, if you mean upgrading from Windows 10 to windows server, it’s really impossible. You can only upgrade from different Windows 10 versions like from Home edition to pro edition.

  2. Avatar

    Hi . I have a computer with Windows Server 2016 Datacenter activated . Can you tell me what I need to do for my domain . I need to put it online like . do I need a public ip?

    • Avatar
      Mina Magued Mounir on

      Hello Denis, I searched online and found that you need a static ip on your router, which means it won’t change if you turn off your router or restart it. Make sure you have this option by contacting your service provider. I found that video (there are many of these explaining the whole process), it’s a little old but I think it explains everything.
      Check it and tell me if you need more help. Good luck!

    • Avatar
      Mina Magued Mounir on

      Hello Lemba, please follow the steps one by now again and see if you did everything correctly, if the problem persists, please send us more information about the error you’re facing like a screenshot or something on our forums

  3. Avatar


    I want to access my data on my server without being on the same network. Need I an public IP for this? There’s another method?

    • Avatar
      Mina Magued Mounir on

      Hello Felipe, well, the easy solution is definitely having a fixed public ip, but I think I know another option:
      This one is probably free but you have to reactivate it monthly, which is a “no ip” hostname, it’s a service by Microsoft which captures your ip address every 5 minutes and sends it to a hostname. You can always replace your required “fixed public ip” with this “hostname” that you created download the no-ip app on your computer which is called “DUC” and this way, the hostname will always be carrying your current dynamic ip address. If you want to understand more, check this URL:
      I hope this will help you, good luck!

  4. Avatar


    i tried my client system workgroup to domain but i am getting an error called ‘The session is timed out’

    can u solve me the issue?

  5. Avatar

    Hi i want to understand that do we have to keep server as well as client machines in the same network once we create domain and wants to join client machine in domain.

    • Avatar
      Mina Magued Mounir on

      Hello Salman, yes you have to. Especially the server, it has to remain online all the time and of course on the same network as the client machines so that it can monitor them and control each one’s permissions. Some people are offering some ways in order to connect to the domain outside of your LAN network using customized settings or via VPN but I haven’t tested that and I don’t think it’s secured but I’ll take a look at it and tell you what I find.

  6. Avatar


    if we are creating the domain like “” then which operating system have to install and how to create the domain.

    • Avatar
      Mina Magued Mounir on

      Hello mallayya, you can create domains using Linux servers or Windows Servers, you have to decide which one you need because they’re both widely used. You’ll need to register your domain using a domain service, you’ll pay for it in general. Check this guide in order to know more about it:

  7. Avatar

    How do I set up 2 domains on one server, control user accounts & devices under one AD forest (if possible), add PCs to the domains where at the login screen the user has to pick which domain they want to log into? Based on which domain they pick will determine which email they utilize & which files they can access from the file server.

    I have users & PCs at a location where 2 different organizations share the space & equipment, but I need to separate the profiles. The last person setup local accounts on the PCs directly & I am working to move them to a true network & file server system.

    • Avatar
      Mina Magued Mounir on

      Hello J., you can’t create two separate domains on the same server, but you can create one big domain and then two sub-domains and then a computer can only be to one sub-domain. If this is okay with you, tell me and I’ll do my best to provide you with more information on how to do that.

Leave A Reply