A home-lab walkthrough in applied mode, 23 slides long. It explains why Windows 11 Home cannot join a domain - only Pro, Enterprise, and Education can - and compares the VirtualBox network modes (NAT, NAT Network, Internal, Host-only, and Bridged) to work out which one a domain-controller lab needs. From there it covers static IP addressing on a single subnet and the gotcha that causes most failures: the client's DNS must point at the domain controller, not at a router or at 8.8.8.8. It finishes with the domain-join steps and verification using ping, nslookup, and whoami, plus two traps, two checks, and a bottom-up troubleshooting checklist.
Subject: IT Support & Networking · 44 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
Home Lab · Active Directory
A Windows 11 client + a Windows Server 2022 Domain Controller in VirtualBox. Today we go from "ping doesn't work" to a real domain login — and you'll know why at every step.
Objectives
You already spotted the first problem yourself — Home edition can't join a domain. Nice catch. By the end of today you can:
Concept
A domain is a central directory of users and computers run by a Domain Controller (DC). Once the client joins, you log in with a domain account and the server can push settings (Group Policy) to it.
Domain Controller (DC) — A Windows Server running Active Directory Domain Services. It authenticates logins and is the authority every domain-joined machine checks in with.
Everything today is the plumbing that has to be right before that join button will work.
Counterexample
Discussion prompt
Everything today is the plumbing that has to be right before that join button will work.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Section
Section 1
Concept
Domain join is a business feature. Microsoft puts it — along with Group Policy and BitLocker management — only in Pro, Enterprise, and Education. Home simply has the option removed.
| Windows 11 edition | Can join an AD domain? |
|---|---|
| Home | No — feature not included |
| Pro | Yes |
| Enterprise | Yes |
| Education | Yes |
So this was never a networking bug — it's an edition limit. That's exactly what you diagnosed.
Discrimination
Sort into buckets
Sort these by Can join an AD domain?, from memory, without looking back at Why Home can't join a domain. Telling them apart on the spot is the skill; the table is only where the answer happens to be written down.
Estimation
Predict first
Check first, don't guess. Press Win + R, type winver, Enter. The first line tells you the edition.
Commit before you compute: what does Confirm the edition, then fix it come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.
Correct: Alternative: upgrade Home → Pro in Settings → System → Activation
Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. Works too, but needs a valid Pro license key — more friction than the eval ISO for a throwaway lab VM.
Worked example
Check first, don't guess. Press Win + R, type winver, Enter. The first line tells you the edition.
If it says Home → rebuild the client VM from the free Windows 11 Enterprise evaluation ISO
Why: Microsoft's Evaluation Center gives a 90-day Enterprise ISO with no product key needed — cleanest path for a lab and it costs nothing.
Alternative: upgrade Home → Pro in Settings → System → Activation
Why: Works too, but needs a valid Pro license key — more friction than the eval ISO for a throwaway lab VM.
Grab the ISO before the session so we don't spend paid time downloading.
Reverse engineer
Discussion prompt
Work backwards. The example finished here:
Alternative: upgrade Home → Pro in Settings → System → Activation
What was it asked to do, and what must it have been given? Reconstruct the problem from its answer.
Hint: Every quantity in the result had to enter somewhere. Account for each one.
Answer:
Check first, don't guess. Press Win + R, type winver, Enter. The first line tells you the edition.
Section
Section 2
Concept
Each VM's adapter has a mode. The mode — not the IP — decides whether the two VMs can even see each other. This is where most labs quietly break.
| Mode | VM ↔ VM? | Internet? | Good for a DC lab? |
|---|---|---|---|
| NAT (default) | No | Yes | No — VMs are isolated |
| NAT Network | Yes | Yes | Yes |
| Internal Network | Yes | No | Yes (add NAT for internet) |
| Host-only | Yes (+ host) | No | Yes |
| Bridged | Yes | Yes | Works, but exposes VMs to your real LAN |
Discrimination
Sort into buckets
Sort these by VM ↔ VM?, from memory, without looking back at The mode decides who can talk to whom. Telling them apart on the spot is the skill; the table is only where the answer happens to be written down.
Picture it
Figure (svg): Two boxes labeled VM each with an arrow out to the internet but no line between them
Discussion prompt
Read the picture before the words. What is this showing, and what is the one thing it is built to make obvious? Commit to an answer, then read on.
Hint: Name the parts, then say what changes between them — and if nothing changes, say what is being held still.
Answer:
Plain NAT is a hotel-room phone: each VM can call out to the internet, but no two rooms can call each other. Great for one machine, useless for a lab where two machines must talk.
Intuition
Plain NAT is a hotel-room phone: each VM can call out to the internet, but no two rooms can call each other. Great for one machine, useless for a lab where two machines must talk.
Figure (svg): Two boxes labeled VM each with an arrow out to the internet but no line between them
Internal Network is a private switch in a closet: plug both VMs into the same named switch (say adlab) and they're on the same wire — isolated from the outside world, perfect for a controlled lab.
Anomaly
Predict first
A student writes this, and it looks reasonable:
Both VMs use the default NAT adapter and you try to ping across.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.
Put both adapters on the same Internal Network named adlab (or NAT Network).
Why: VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.
Trap
Both VMs use the default NAT adapter and you try to ping across.
Each VM gets 10.0.2.15 from its own private NAT engine
Why: VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.
ping the other VM → times out, every time
Why: There is no path between two NAT adapters. No IP change fixes it — the mode is the wall.
Put both adapters on the same Internal Network named adlab (or NAT Network).
Both VMs now share one virtual switch
Why: Same segment = a real path exists between them, like two PCs on one switch.
Optionally add a second adapter set to NAT for internet
Why: Internal handles VM-to-VM; the NAT adapter handles updates/downloads — best of both.
Break the constraint
Discussion prompt
The rule this trap just fixed:
Same segment = a real path exists between them, like two PCs on one switch.
Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?
Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.
Answer:
VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.
Section
Section 3
Concept
Internal Network has no DHCP server by default, so nobody hands out addresses. Set them statically, and make sure both live on the same subnet so they're considered neighbors.
subnet — A range of addresses that share a network portion. With mask 255.255.255.0 (/24), 192.168.10.x are all neighbors; anything outside .10.x is treated as remote.
Set these on the DC first, then the client.
Definition probe
Sort into buckets
Every line below is part of the definition of Domain Controller (DC) or of subnet — one or the other, never both. Put each where it belongs.
Estimation
Predict first
In each VM: Settings → Network & internet → Ethernet → IP assignment → Edit → Manual → IPv4 on.
Commit before you compute: what does The addressing scheme we'll use come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.
Correct: Note the client's Preferred DNS = the DC's IP
Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. This single line is what makes the join succeed.
Worked example
In each VM: Settings → Network & internet → Ethernet → IP assignment → Edit → Manual → IPv4 on.
| Setting | Domain Controller | Windows 11 Client |
|---|---|---|
| IP address | 192.168.10.10 | 192.168.10.20 |
| Subnet mask | 255.255.255.0 | 255.255.255.0 |
| Gateway | (blank, or NAT IP) | (blank, or NAT IP) |
| Preferred DNS | 127.0.0.1 (itself) | 192.168.10.10 (the DC) |
Note the client's Preferred DNS = the DC's IP
Why: This single line is what makes the join succeed. The next slides explain why — it's the part everyone gets wrong.
Concept
A client doesn't find its domain by IP — it asks DNS for special SRV records that say "here's the domain controller." Only the DC's own DNS service knows those records.
SRV record — A DNS entry that advertises a service's location, e.g. _ldap._tcp.dc._msdcs.lab.local → the DC. Active Directory lives or dies by these.
So the client's DNS must be the DC's IP. Point it at the router or 8.8.8.8 and the client can browse the web fine — but it will never find the domain.
Intuition
Google's 8.8.8.8 is a phone book for the public internet. Your domain lab.local is unlisted there — only the DC's phone book has its number. Ask the wrong book and you get "not found," no matter how good your connection is.
Figure (svg): A client asking two phone books: 8.8.8.8 returns not found, the DC returns the address
Anomaly
Predict first
A student writes this, and it looks reasonable:
Network looks healthy — but the client's DNS is set to the router / 8.8.8.8.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Raw IP connectivity is fine — that only proves the wire, not that the domain can be located.
Set the client's Preferred DNS to the DC's IP (192.168.10.10).
Why: Raw IP connectivity is fine — that only proves the wire, not that the domain can be located.
Trap
Network looks healthy — but the client's DNS is set to the router / 8.8.8.8.
ping 192.168.10.10 succeeds
Why: Raw IP connectivity is fine — that only proves the wire, not that the domain can be located.
Join fails: "An Active Directory Domain Controller for the domain could not be contacted."
Why: The DNS query for the domain's SRV records went to a server that's never heard of lab.local.
Set the client's Preferred DNS to the DC's IP (192.168.10.10).
nslookup lab.local now resolves to the DC
Why: The query reaches the DC's DNS, which holds the AD records.
The domain join succeeds
Why: The locator found the DC via SRV records — exactly what it needed.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Ranking
Put in order
These are the steps of Troubleshoot bottom-up, every time, scrambled. Put them back in order before the next slide shows you.
winver says Pro/Enterprise/Education (not Home).ipconfig shows 192.168.10.x.ping the DC by IP (allow ICMP through the firewall first).nslookup lab.local resolves.Why: This is the order the recipe itself gives. Recalling the sequence without the slide in front of you is the difference between recognising the method and being able to run it — most of what goes wrong in practice is a step done out of turn.
Pattern
When connectivity "doesn't work," walk the layers from the bottom. Each rung must pass before the next can:
winver says Pro/Enterprise/Education (not Home).ipconfig shows 192.168.10.x.ping the DC by IP (allow ICMP through the firewall first).nslookup lab.local resolves.Heads-up: a fresh Windows firewall blocks ping by default, so a failed ping isn't always a network fault — that's its own rung to check.
Edge cases
Discussion prompt
Troubleshoot bottom-up, every time works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
When connectivity "doesn't work," walk the layers from the bottom. Each rung must pass before the next can:
Elimination
Eliminate the wrong options
ping 192.168.10.10 succeeds, but the domain join fails with "An Active Directory Domain Controller could not be contacted." What is the most likely fix?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: A successful ping proves IP reachability, so the wire and addresses are fine. The join uses DNS SRV records to locate the DC, and only the DC's DNS holds them — so the client's Preferred DNS must be the DC's IP.
Check
The client pings the DC by IP just fine, but joining fails with "a domain controller could not be contacted." What's the most likely cause?
Check your understanding
ping 192.168.10.10 succeeds, but the domain join fails with "An Active Directory Domain Controller could not be contacted." What is the most likely fix?
Answer: A
Why: A successful ping proves IP reachability, so the wire and addresses are fine. The join uses DNS SRV records to locate the DC, and only the DC's DNS holds them — so the client's Preferred DNS must be the DC's IP.
Section
Section 4
Ranking
Put in order
Put the moves of Join the client to the domain into the order they have to happen.
lab.local, click OKWhy: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Opens the classic System Properties → Computer Name dialog where domain membership lives.
Worked example
With editions, mode, IPs, and DNS all green, the join is the easy part.
Settings → System → About → Domain or workgroup → Change
Why: Opens the classic System Properties → Computer Name dialog where domain membership lives.
Select Domain, type lab.local, click OK
Why: This kicks off the DNS SRV lookup to find the DC — the step that fails if DNS is wrong.
Enter domain admin credentials when prompted, then reboot
Why: Joining writes a computer account into AD, which requires authority; the reboot completes membership.
Reverse engineer
Discussion prompt
Work backwards. The example finished here:
Enter domain admin credentials when prompted, then reboot
What was it asked to do, and what must it have been given? Reconstruct the problem from its answer.
Hint: Every quantity in the result had to enter somewhere. Account for each one.
Answer:
With editions, mode, IPs, and DNS all green, the join is the easy part.
Estimation
Predict first
After the reboot, log in as lab\someuser and prove the join with three quick commands.
Commit before you compute: what does Verify it three ways come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.
Correct: Bonus: systeminfo | findstr /C:"Domain"
Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. Shows Domain: lab.local — independent confirmation the machine is a member, not in a workgroup.
Worked example
After the reboot, log in as lab\someuser and prove the join with three quick commands.
| Command | What a good result looks like |
|---|---|
| ping 192.168.10.10 | Replies — basic reachability to the DC |
| nslookup lab.local | Resolves to 192.168.10.10 (DNS is correct) |
| whoami | Prints lab\someuser, not the local PC name |
Bonus: systeminfo | findstr /C:"Domain"
Why: Shows Domain: lab.local — independent confirmation the machine is a member, not in a workgroup.
If whoami shows lab\... — you joined the domain. From here we can start Group Policy.
Comparison
Comparison matrix
From Verify it three ways: refill the What a good result looks like column from what you know. The rest of the table is as it appeared.
| Command | What a good result looks like |
|---|---|
| ping 192.168.10.10 | Replies — basic reachability to the DC |
| nslookup lab.local | Resolves to 192.168.10.10 (DNS is correct) |
| whoami | Prints lab\someuser, not the local PC name |
Elimination
Eliminate the wrong options
You need the DC and client VMs to communicate with each other but stay off your real home LAN. Which network mode is the best fit?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: Internal Network puts both VMs on one private virtual switch so they can reach each other, while staying fully isolated from the host and the physical LAN — exactly the controlled-lab requirement.
Check
You want the two VMs to talk to each other and stay isolated from your real home network. Which VirtualBox mode fits best?
Check your understanding
You need the DC and client VMs to communicate with each other but stay off your real home LAN. Which network mode is the best fit?
Answer: A
Why: Internal Network puts both VMs on one private virtual switch so they can reach each other, while staying fully isolated from the host and the physical LAN — exactly the controlled-lab requirement.
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — Step 1 — The Right Edition · Step 2 — VirtualBox Network Mode · Step 3 — Addresses & DNS · Step 4 — Join & Verify. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
winver and know Home can't join — use Pro/Enterprise.| Layer | The one thing that must be right |
|---|---|
| Edition | Pro / Enterprise / Education |
| Network mode | Same Internal / NAT Network |
| Addressing | Same /24 subnet, static |
| DNS | Client's Preferred DNS = the DC |
| Verify | whoami shows DOMAIN\user |
Next session: with the client joined, we create your first Group Policy Object and watch it apply to the client — the payoff of all this setup.
Want this taught 1-on-1? Alexander tutors IT Support & Networking — $55/session, free consultation.