A hands-on IT Infrastructure and Windows Server administration lab built to simulate a small enterprise environment using Windows Server, Active Directory, DNS, DHCP, Group Policy, File Services, and Windows 11 Pro.
The project was built from scratch in a virtualized environment using VirtualBox, with a Windows client connected to the Active Directory domain.
This project was created to develop practical skills in:
- Windows Server Administration
- Active Directory Domain Services (AD DS)
- Domain Controller Management
- DNS Administration
- DHCP Configuration
- User and Group Management
- Organizational Units (OUs)
- Group Policy (GPO)
- File Server and Shared Folders
- NTFS and Share Permissions
- Least Privilege
- Windows Domain Join
- Software Deployment
- Network Troubleshooting
- IT Support Troubleshooting
- Backup and Recovery Fundamentals
The main objective was not only to configure the environment, but also to troubleshoot problems that occurred during implementation and understand how the different infrastructure services interact.
flowchart LR
DC["Windows Server 2022<br/>DC01<br/><br/>Active Directory<br/>DNS<br/>DHCP<br/>Group Policy<br/>File Services"]
NET["VirtualBox Network<br/><br/>lab.local"]
CLIENT["Windows 11 Pro<br/>Domain-Joined Client"]
DC <--> NET
NET <--> CLIENT
| Component | Configuration |
|---|---|
| Server OS | Windows Server 2022 |
| Client OS | Windows 11 Pro |
| Virtualization | Oracle VirtualBox |
| Active Directory Domain | lab.local |
| Domain Controller | DC01 |
| Server IP | 192.168.20.10 |
| Client IP | 192.168.20.100 |
| DNS | Windows Server / Domain Controller |
| DHCP | Windows Server DHCP |
| Authentication | Active Directory |
| Network | VirtualBox + Ethernet connectivity |
IP addresses shown above are from the lab environment and are used for documentation purposes only.
- Windows Server 2022
- Windows 11 Pro
- Active Directory Domain Services (AD DS)
- DNS
- DHCP
- Group Policy
- Windows File Services
- TCP/IP
- IP Addressing
- DHCP
- DNS
- NAT
- Internal Network
- Host-Only Networking
- Bridged Networking
- Ethernet
- Oracle VirtualBox
- ipconfig
- ping
- nslookup
- gpupdate
- nltest
- Windows Event Viewer
- Server Manager
- DNS Manager
- DHCP Manager
- Active Directory Users and Computers
The lab started by installing and configuring Windows Server as the central infrastructure server.
The server was configured as a Domain Controller and became the main authentication and network services server for the lab.
- Installed Windows Server
- Configured server networking
- Installed Active Directory Domain Services
- Promoted the server to a Domain Controller
- Created the lab.local domain
- Configured DNS
- Configured DHCP
- Verified domain services
- Created and managed domain objects
The lab.local Active Directory environment was structured to simulate a basic organizational environment.
- Created Active Directory domain
- Created Organizational Units
- Created user accounts
- Created security groups
- Added users to groups
- Tested domain authentication
- Tested standard domain-user login
flowchart TD
DOMAIN["lab.local"]
DOMAIN --> IT["IT OU"]
IT --> USERS["IT-Users OU"]
USERS --> YASSER["Yasser<br/>Domain User"]
DOMAIN --> GROUP["IT-Support<br/>Security Group"]
A dedicated IT-Support security group was also created and used for access management.
Group Policy was used to simulate centralized Windows administration.
- Password Policy
- Account Lockout Policy
- User and computer policy management
- Group Policy application
- gpupdate /force
- Domain policy troubleshooting
The lab also included testing situations where Group Policy could not communicate correctly with the Domain Controller.
The environment was used to practice common Active Directory account-management tasks.
- Password policy configuration
- Password reset
- Account lockout
- Unlocking accounts
- Testing failed login scenarios
- Standard User vs Administrator
- Least Privilege principles
The goal was to understand how an IT Support technician would handle common user-account incidents in a domain environment.
A file-sharing environment was configured to practice Windows access control.
- Created shared folders
- Configured NTFS permissions
- Configured Share permissions
- Tested user access
- Tested restricted access
- Applied least-privilege principles
User β Security Group β Share Permissions β NTFS Permissions β Effective Access
This provided practical experience with the difference between Share Permissions and NTFS Permissions.
Software deployment through Group Policy was also practiced.
flowchart LR
GPO["Group Policy"]
CC["Computer Configuration"]
SS["Software Settings"]
SI["Software Installation"]
MSI["Assigned MSI Package"]
CLIENT["Domain Client"]
INSTALL["Software Installed"]
GPO --> CC
CC --> SS
SS --> SI
SI --> MSI
MSI --> CLIENT
CLIENT --> INSTALL
The deployment was tested on the domain client after restarting the computer.
DNS was an important component of the lab because Active Directory relies heavily on DNS for domain services and locating the Domain Controller.
- DNS zone verification
- lab.local Forward Lookup Zone
- Domain name resolution
- Domain Controller name resolution
- nslookup
- DNS troubleshooting
Example:
nslookup DC01.lab.local
The client successfully resolved the Domain Controller through DNS.
Windows Server DHCP was configured to automatically provide network configuration to clients.
- DHCP installation
- DHCP authorization
- Scope configuration
- IP address assignment
- DHCP client testing
- DHCP renewal
- DHCP troubleshooting
One of the real troubleshooting scenarios involved clients receiving:
169.254.x.x
This APIPA address indicated that the client was not receiving a valid DHCP lease.
The Windows 11 Pro client was successfully joined to:
lab.local
flowchart LR
CLIENT["Windows 11 Pro"]
NETWORK["Network Connectivity"]
DNS["DNS<br/>lab.local"]
DC["DC01<br/>Domain Controller"]
AD["Active Directory"]
AUTH["Domain User<br/>Authentication"]
CLIENT --> NETWORK
NETWORK --> DNS
DNS --> DC
DC --> AD
AD --> AUTH
The client was successfully authenticated using a domain user account.
One of the most valuable parts of the project was troubleshooting real problems instead of only following configuration steps.
- Virtual machines stopping unexpectedly
- Host resource / VM execution problems
- DHCP clients receiving 169.254.x.x APIPA addresses
- DHCP renewal failures
- Ping failures between network interfaces
- Firewall blocking ICMP traffic
- Connectivity problems between physical and virtual network environments
- Domain Join authentication errors
- Domain Controller connectivity problems
- Group Policy communication failures
These issues were investigated using tools such as:
ipconfigpingnslookupnltestgpupdate /force
along with Windows administrative tools and network adapter configuration.
The final environment was tested using:
nltest /dsgetdc:lab.local
and:
nltest /sc_verify:lab.local
These tests were used to verify that the client could locate the Domain Controller and that the domain secure channel was functioning correctly.
DNS resolution was also tested using:
nslookup DC01.lab.local
The project also included basic backup and recovery concepts to understand how Windows infrastructure should be protected against configuration or system failures.
The focus was on understanding:
- Backup concepts
- Recovery planning
- System availability
- Importance of infrastructure documentation
- Recovery considerations for Windows Server environments
This project strengthened my understanding of how enterprise IT infrastructure components work together.
Active Directory is highly dependent on DNS for locating domain services and Domain Controllers.
An incorrectly configured DHCP environment can result in APIPA addresses and loss of connectivity.
Instead of changing random settings, I learned to isolate the problem by checking:
IP Configuration β Network Connectivity β DNS Resolution β Domain Controller Connectivity β Authentication β Group Policy
Users should receive only the access required to perform their responsibilities.
The project helped me develop a troubleshooting mindset based on eliminating possible causes one by one.
Screenshots documenting the lab configuration are organized into the following categories:
These screenshots demonstrate the actual configuration and successful testing of the environment.
The repository is organized into the following sections:
README.mdβ Main project documentationscreenshots/β Screenshots documenting the labscreenshots/active-directory/β Active Directory configurationscreenshots/dns/β DNS configurationscreenshots/dhcp/β DHCP configurationscreenshots/group-policy/β Group Policy configurationscreenshots/file-server/β File Server and permissionsscreenshots/troubleshooting/β Troubleshooting evidence.gitignoreβ Files and folders excluded from Git
The main goals of this project were to:
- Build a realistic Windows infrastructure environment
- Gain hands-on Active Directory experience
- Practice Windows Server administration
- Understand DNS and DHCP dependencies
- Practice centralized administration using Group Policy
- Understand Windows permissions
- Develop practical troubleshooting skills
- Create documented infrastructure experience suitable for an IT Support / Infrastructure role
Possible future extensions include:
- Adding additional domain clients
- Creating multiple departments and OUs
- Expanding Group Policy configurations
- Implementing more advanced file-server permissions
- Adding monitoring
- Implementing Windows Server backup scenarios
- Adding additional networking scenarios
- Practicing more advanced Active Directory administration
This project demonstrates practical experience with:
- Windows Server Administration
- Active Directory
- DNS
- DHCP
- Group Policy
- User & Group Management
- Organizational Units
- File Server Administration
- NTFS Permissions
- Share Permissions
- Least Privilege
- Domain Join
- Network Troubleshooting
- IT Support Troubleshooting
- VirtualBox
This lab was built as a hands-on learning and portfolio project to demonstrate practical Windows infrastructure, Active Directory administration, networking, security, and troubleshooting skills.
Yasser Obaid
Computer Engineering Graduate | IT Support | Infrastructure | Networking
GitHub: Yasser-Obaid








