Joining a Windows 11 Client to a Server 2022 Domain Controller in VirtualBox

A home-lab walkthrough in applied mode, 23 slides long. It explains why Windows 11 Home cannot join a domain - only Pro, Enterprise, and Education can - and compares the VirtualBox network modes (NAT, NAT Network, Internal, Host-only, and Bridged) to work out which one a domain-controller lab needs. From there it covers static IP addressing on a single subnet and the gotcha that causes most failures: the client's DNS must point at the domain controller, not at a router or at 8.8.8.8. It finishes with the domain-join steps and verification using ping, nslookup, and whoami, plus two traps, two checks, and a bottom-up troubleshooting checklist.

Subject: IT Support & Networking · 44 slides · applied lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. Getting Your Two VMs Talking

Title

Home Lab · Active Directory

A Windows 11 client + a Windows Server 2022 Domain Controller in VirtualBox. Today we go from "ping doesn't work" to a real domain login — and you'll know why at every step.

2. What you'll be able to do

Objectives

You already spotted the first problem yourself — Home edition can't join a domain. Nice catch. By the end of today you can:

3. The goal we're building toward

Concept

A domain is a central directory of users and computers run by a Domain Controller (DC). Once the client joins, you log in with a domain account and the server can push settings (Group Policy) to it.

Domain Controller (DC) — A Windows Server running Active Directory Domain Services. It authenticates logins and is the authority every domain-joined machine checks in with.

Everything today is the plumbing that has to be right before that join button will work.

4. Break it if you can: The goal we're building toward

Counterexample

Discussion prompt

Everything today is the plumbing that has to be right before that join button will work.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

5. Step 1 — The Right Edition

Section

Section 1

6. Why Home can't join a domain

Concept

Domain join is a business feature. Microsoft puts it — along with Group Policy and BitLocker management — only in Pro, Enterprise, and Education. Home simply has the option removed.

Windows 11 editionCan join an AD domain?
HomeNo — feature not included
ProYes
EnterpriseYes
EducationYes

So this was never a networking bug — it's an edition limit. That's exactly what you diagnosed.

7. Which is which, by Can join an AD domain?

Discrimination

Sort into buckets

Sort these by Can join an AD domain?, from memory, without looking back at Why Home can't join a domain. Telling them apart on the spot is the skill; the table is only where the answer happens to be written down.

No — feature not included
Home
Yes
Pro; Enterprise; Education
g1
Can join an AD domain? is "No — feature not included" for Home — that is what the table on "Why Home can't join a domain" records, and it is the single property separating this group from the rest.
g2
Can join an AD domain? is "Yes" for Pro, Enterprise, Education — that is what the table on "Why Home can't join a domain" records, and it is the single property separating this group from the rest.

8. Guess the shape of the answer: Confirm the edition, then fix it

Estimation

Predict first

Check first, don't guess. Press Win + R, type winver, Enter. The first line tells you the edition.

Commit before you compute: what does Confirm the edition, then fix it come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.

Correct: Alternative: upgrade Home → Pro in Settings → System → Activation

Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. Works too, but needs a valid Pro license key — more friction than the eval ISO for a throwaway lab VM.

9. Confirm the edition, then fix it

Worked example

Check first, don't guess. Press Win + R, type winver, Enter. The first line tells you the edition.

If it says Home → rebuild the client VM from the free Windows 11 Enterprise evaluation ISO

Why: Microsoft's Evaluation Center gives a 90-day Enterprise ISO with no product key needed — cleanest path for a lab and it costs nothing.

Alternative: upgrade Home → Pro in Settings → System → Activation

Why: Works too, but needs a valid Pro license key — more friction than the eval ISO for a throwaway lab VM.

Grab the ISO before the session so we don't spend paid time downloading.

10. Work backwards from the answer: Confirm the edition, then fix it

Reverse engineer

Discussion prompt

Work backwards. The example finished here:

Alternative: upgrade Home → Pro in Settings → System → Activation

What was it asked to do, and what must it have been given? Reconstruct the problem from its answer.

Hint: Every quantity in the result had to enter somewhere. Account for each one.

Answer:

Check first, don't guess. Press Win + R, type winver, Enter. The first line tells you the edition.

11. Step 2 — VirtualBox Network Mode

Section

Section 2

12. The mode decides who can talk to whom

Concept

Each VM's adapter has a mode. The mode — not the IP — decides whether the two VMs can even see each other. This is where most labs quietly break.

ModeVM ↔ VM?Internet?Good for a DC lab?
NAT (default)NoYesNo — VMs are isolated
NAT NetworkYesYesYes
Internal NetworkYesNoYes (add NAT for internet)
Host-onlyYes (+ host)NoYes
BridgedYesYesWorks, but exposes VMs to your real LAN

13. Which is which, by VM ↔ VM?

Discrimination

Sort into buckets

Sort these by VM ↔ VM?, from memory, without looking back at The mode decides who can talk to whom. Telling them apart on the spot is the skill; the table is only where the answer happens to be written down.

No
NAT (default)
Yes
NAT Network; Internal Network; Bridged
Yes (+ host)
Host-only
g1
VM ↔ VM? is "No" for NAT (default) — that is what the table on "The mode decides who can talk to whom" records, and it is the single property separating this group from the rest.
g2
VM ↔ VM? is "Yes" for NAT Network, Internal Network, Bridged — that is what the table on "The mode decides who can talk to whom" records, and it is the single property separating this group from the rest.
g3
VM ↔ VM? is "Yes (+ host)" for Host-only — that is what the table on "The mode decides who can talk to whom" records, and it is the single property separating this group from the rest.

14. Picture it first: Think of it as wiring

Picture it

Figure (svg): Two boxes labeled VM each with an arrow out to the internet but no line between them

Plain NAT: out, yes. To each other, no.

Discussion prompt

Read the picture before the words. What is this showing, and what is the one thing it is built to make obvious? Commit to an answer, then read on.

Hint: Name the parts, then say what changes between them — and if nothing changes, say what is being held still.

Answer:

Plain NAT is a hotel-room phone: each VM can call out to the internet, but no two rooms can call each other. Great for one machine, useless for a lab where two machines must talk.

15. Think of it as wiring

Intuition

Plain NAT is a hotel-room phone: each VM can call out to the internet, but no two rooms can call each other. Great for one machine, useless for a lab where two machines must talk.

Figure (svg): Two boxes labeled VM each with an arrow out to the internet but no line between them

Plain NAT: out, yes. To each other, no.

Internal Network is a private switch in a closet: plug both VMs into the same named switch (say adlab) and they're on the same wire — isolated from the outside world, perfect for a controlled lab.

16. Something is wrong here: leaving both VMs on NAT and expecting ping

Anomaly

Predict first

A student writes this, and it looks reasonable:

Both VMs use the default NAT adapter and you try to ping across.

It is wrong. Say what breaks — and say it before you turn the page.

Correct: VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.

Put both adapters on the same Internal Network named adlab (or NAT Network).

Why: VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.

17. Trap: leaving both VMs on NAT and expecting ping

Trap

The trap

Both VMs use the default NAT adapter and you try to ping across.

Each VM gets 10.0.2.15 from its own private NAT engine

Why: VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.

ping the other VM → times out, every time

Why: There is no path between two NAT adapters. No IP change fixes it — the mode is the wall.

The fix

Put both adapters on the same Internal Network named adlab (or NAT Network).

Both VMs now share one virtual switch

Why: Same segment = a real path exists between them, like two PCs on one switch.

Optionally add a second adapter set to NAT for internet

Why: Internal handles VM-to-VM; the NAT adapter handles updates/downloads — best of both.

18. Break it on purpose: leaving both VMs on NAT and expecting ping

Break the constraint

Discussion prompt

The rule this trap just fixed:

Same segment = a real path exists between them, like two PCs on one switch.

Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?

Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.

Answer:

VirtualBox gives every NAT adapter its own isolated 10.0.2.x network — they look identical but are separate sandboxes.

19. Step 3 — Addresses & DNS

Section

Section 3

20. Same subnet, static addresses

Concept

Internal Network has no DHCP server by default, so nobody hands out addresses. Set them statically, and make sure both live on the same subnet so they're considered neighbors.

subnet — A range of addresses that share a network portion. With mask 255.255.255.0 (/24), 192.168.10.x are all neighbors; anything outside .10.x is treated as remote.

Set these on the DC first, then the client.

21. Take the definitions apart: Domain Controller (DC) vs subnet

Definition probe

Sort into buckets

Every line below is part of the definition of Domain Controller (DC) or of subnet — one or the other, never both. Put each where it belongs.

Domain Controller (DC)
A Windows Server running Active Directory Domain Services.; It authenticates logins and is the authority every domain-joined machine checks in with.
subnet
A range of addresses that share a network portion.; With mask 255.255.255.0 (/24), 192.168.10.x are all neighbors; anything outside .10.x is treated as remote.
b1
A Windows Server running Active Directory Domain Services. It authenticates logins and is the authority every domain-joined machine checks in with.
b2
A range of addresses that share a network portion. With mask 255.255.255.0 (/24), 192.168.10.x are all neighbors; anything outside .10.x is treated as remote.

22. Guess the shape of the answer: The addressing scheme we'll use

Estimation

Predict first

In each VM: Settings → Network & internet → Ethernet → IP assignment → Edit → Manual → IPv4 on.

Commit before you compute: what does The addressing scheme we'll use come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.

Correct: Note the client's Preferred DNS = the DC's IP

Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. This single line is what makes the join succeed.

23. The addressing scheme we'll use

Worked example

In each VM: Settings → Network & internet → Ethernet → IP assignment → Edit → Manual → IPv4 on.

SettingDomain ControllerWindows 11 Client
IP address192.168.10.10192.168.10.20
Subnet mask255.255.255.0255.255.255.0
Gateway(blank, or NAT IP)(blank, or NAT IP)
Preferred DNS127.0.0.1 (itself)192.168.10.10 (the DC)

Note the client's Preferred DNS = the DC's IP

Why: This single line is what makes the join succeed. The next slides explain why — it's the part everyone gets wrong.

24. The #1 gotcha: DNS must point at the DC

Concept

A client doesn't find its domain by IP — it asks DNS for special SRV records that say "here's the domain controller." Only the DC's own DNS service knows those records.

SRV record — A DNS entry that advertises a service's location, e.g. _ldap._tcp.dc._msdcs.lab.local → the DC. Active Directory lives or dies by these.

So the client's DNS must be the DC's IP. Point it at the router or 8.8.8.8 and the client can browse the web fine — but it will never find the domain.

25. DNS is the lab's phone book

Intuition

Google's 8.8.8.8 is a phone book for the public internet. Your domain lab.local is unlisted there — only the DC's phone book has its number. Ask the wrong book and you get "not found," no matter how good your connection is.

Figure (svg): A client asking two phone books: 8.8.8.8 returns not found, the DC returns the address

Right book = the DC. Same question, opposite answer.

26. Something is wrong here: "ping works, so why won't it join?"

Anomaly

Predict first

A student writes this, and it looks reasonable:

Network looks healthy — but the client's DNS is set to the router / 8.8.8.8.

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Raw IP connectivity is fine — that only proves the wire, not that the domain can be located.

Set the client's Preferred DNS to the DC's IP (192.168.10.10).

Why: Raw IP connectivity is fine — that only proves the wire, not that the domain can be located.

27. Trap: "ping works, so why won't it join?"

Trap

The trap

Network looks healthy — but the client's DNS is set to the router / 8.8.8.8.

ping 192.168.10.10 succeeds

Why: Raw IP connectivity is fine — that only proves the wire, not that the domain can be located.

Join fails: "An Active Directory Domain Controller for the domain could not be contacted."

Why: The DNS query for the domain's SRV records went to a server that's never heard of lab.local.

The fix

Set the client's Preferred DNS to the DC's IP (192.168.10.10).

nslookup lab.local now resolves to the DC

Why: The query reaches the DC's DNS, which holds the AD records.

The domain join succeeds

Why: The locator found the DC via SRV records — exactly what it needed.

28. Which of these survive contact with Joining a Windows 11 Client to a Server 2022…?

Two truths and a lie

Sort into buckets

Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.

Holds up
Everything today is the plumbing that has to be right before that join button will work.; Each VM's adapter has a mode. The mode — not the IP — decides whether the two VMs can even see each other. This is where most labs quietly break.
Breaks
Both VMs use the default NAT adapter and you try to ping across.; Network looks healthy — but the client's DNS is set to the router / 8.8.8.8.
sound
These are stated as this lesson states them — each one survives the edge cases Joining a Windows 11 Client to a Server 2022 Domain Controller in VirtualBox puts it through.
flawed
Each of these is lifted from a trap in this deck: reasonable-sounding, and wrong in a way that only shows up once you rely on it.

29. Rebuild the recipe: Troubleshoot bottom-up, every time

Ranking

Put in order

These are the steps of Troubleshoot bottom-up, every time, scrambled. Put them back in order before the next slide shows you.

  1. Edition — winver says Pro/Enterprise/Education (not Home).
  2. Mode — both adapters on the same Internal/NAT Network.
  3. Address — both on one subnet; ipconfig shows 192.168.10.x.
  4. Reachability — ping the DC by IP (allow ICMP through the firewall first).
  5. DNS — client's Preferred DNS = the DC; nslookup lab.local resolves.
  6. Join — only now does Computer Name → Domain work.

Why: This is the order the recipe itself gives. Recalling the sequence without the slide in front of you is the difference between recognising the method and being able to run it — most of what goes wrong in practice is a step done out of turn.

30. Troubleshoot bottom-up, every time

Pattern

When connectivity "doesn't work," walk the layers from the bottom. Each rung must pass before the next can:

  1. Edition — winver says Pro/Enterprise/Education (not Home).
  2. Mode — both adapters on the same Internal/NAT Network.
  3. Address — both on one subnet; ipconfig shows 192.168.10.x.
  4. Reachability — ping the DC by IP (allow ICMP through the firewall first).
  5. DNS — client's Preferred DNS = the DC; nslookup lab.local resolves.
  6. Join — only now does Computer Name → Domain work.

Heads-up: a fresh Windows firewall blocks ping by default, so a failed ping isn't always a network fault — that's its own rung to check.

31. Where does it stop working: Troubleshoot bottom-up, every time

Edge cases

Discussion prompt

Troubleshoot bottom-up, every time works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".

Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.

Answer:

When connectivity "doesn't work," walk the layers from the bottom. Each rung must pass before the next can:

32. Rule out three: Check: ping works, join fails

Elimination

Eliminate the wrong options

ping 192.168.10.10 succeeds, but the domain join fails with "An Active Directory Domain Controller could not be contacted." What is the most likely fix?

3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.

  • A. Set the client's Preferred DNS to the DC's IP (192.168.10.10)
  • B. Switch both VMs from Internal Network to plain NAT
  • C. Give the client a public DNS server like 8.8.8.8
  • D. Reinstall Windows — the network stack is corrupted

Survives elimination: A

Why: A successful ping proves IP reachability, so the wire and addresses are fine. The join uses DNS SRV records to locate the DC, and only the DC's DNS holds them — so the client's Preferred DNS must be the DC's IP.

33. Check: ping works, join fails

Check

The client pings the DC by IP just fine, but joining fails with "a domain controller could not be contacted." What's the most likely cause?

Check your understanding

ping 192.168.10.10 succeeds, but the domain join fails with "An Active Directory Domain Controller could not be contacted." What is the most likely fix?

  • A. Set the client's Preferred DNS to the DC's IP (192.168.10.10) (correct)
  • B. Switch both VMs from Internal Network to plain NAT
  • C. Give the client a public DNS server like 8.8.8.8
  • D. Reinstall Windows — the network stack is corrupted

Answer: A

Why: A successful ping proves IP reachability, so the wire and addresses are fine. The join uses DNS SRV records to locate the DC, and only the DC's DNS holds them — so the client's Preferred DNS must be the DC's IP.

Why B tempts people
Plain NAT isolates each VM on its own network, so they couldn't even ping — this would break the connectivity that's currently working.
Why C tempts people
Public DNS is exactly the wrong place: 8.8.8.8 has never heard of lab.local and can't return the AD SRV records, which is the cause of the failure.
Why D tempts people
Ping already proves the network stack works; the problem is a single DNS setting, not a corrupt install.

34. Step 4 — Join & Verify

Section

Section 4

35. What has to happen first: Join the client to the domain

Ranking

Put in order

Put the moves of Join the client to the domain into the order they have to happen.

  1. Settings → System → About → Domain or workgroup → Change
  2. Select Domain, type lab.local, click OK
  3. Enter domain admin credentials when prompted, then reboot

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Opens the classic System Properties → Computer Name dialog where domain membership lives.

36. Join the client to the domain

Worked example

With editions, mode, IPs, and DNS all green, the join is the easy part.

Settings → System → About → Domain or workgroup → Change

Why: Opens the classic System Properties → Computer Name dialog where domain membership lives.

Select Domain, type lab.local, click OK

Why: This kicks off the DNS SRV lookup to find the DC — the step that fails if DNS is wrong.

Enter domain admin credentials when prompted, then reboot

Why: Joining writes a computer account into AD, which requires authority; the reboot completes membership.

37. Work backwards from the answer: Join the client to the domain

Reverse engineer

Discussion prompt

Work backwards. The example finished here:

Enter domain admin credentials when prompted, then reboot

What was it asked to do, and what must it have been given? Reconstruct the problem from its answer.

Hint: Every quantity in the result had to enter somewhere. Account for each one.

Answer:

With editions, mode, IPs, and DNS all green, the join is the easy part.

38. Guess the shape of the answer: Verify it three ways

Estimation

Predict first

After the reboot, log in as lab\someuser and prove the join with three quick commands.

Commit before you compute: what does Verify it three ways come out to? A rough magnitude and the right form is enough — the point is to have something concrete to be wrong about.

Correct: Bonus: systeminfo | findstr /C:"Domain"

Why: A prediction you can defend turns the computation into a check rather than a leap of faith — and an answer that contradicts it is caught on the spot. Shows Domain: lab.local — independent confirmation the machine is a member, not in a workgroup.

39. Verify it three ways

Worked example

After the reboot, log in as lab\someuser and prove the join with three quick commands.

CommandWhat a good result looks like
ping 192.168.10.10Replies — basic reachability to the DC
nslookup lab.localResolves to 192.168.10.10 (DNS is correct)
whoamiPrints lab\someuser, not the local PC name

Bonus: systeminfo | findstr /C:"Domain"

Why: Shows Domain: lab.local — independent confirmation the machine is a member, not in a workgroup.

If whoami shows lab\... — you joined the domain. From here we can start Group Policy.

40. Fill in: What a good result looks like for Verify it three ways

Comparison

Comparison matrix

From Verify it three ways: refill the What a good result looks like column from what you know. The rest of the table is as it appeared.

CommandWhat a good result looks like
ping 192.168.10.10Replies — basic reachability to the DC
nslookup lab.localResolves to 192.168.10.10 (DNS is correct)
whoamiPrints lab\someuser, not the local PC name

41. Rule out three: Check: which mode for the lab?

Elimination

Eliminate the wrong options

You need the DC and client VMs to communicate with each other but stay off your real home LAN. Which network mode is the best fit?

3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.

  • A. Both on the same Internal Network (e.g. "adlab")
  • B. Both on plain NAT
  • C. Both on Bridged
  • D. One on NAT, the other on Host-only

Survives elimination: A

Why: Internal Network puts both VMs on one private virtual switch so they can reach each other, while staying fully isolated from the host and the physical LAN — exactly the controlled-lab requirement.

42. Check: which mode for the lab?

Check

You want the two VMs to talk to each other and stay isolated from your real home network. Which VirtualBox mode fits best?

Check your understanding

You need the DC and client VMs to communicate with each other but stay off your real home LAN. Which network mode is the best fit?

  • A. Both on the same Internal Network (e.g. "adlab") (correct)
  • B. Both on plain NAT
  • C. Both on Bridged
  • D. One on NAT, the other on Host-only

Answer: A

Why: Internal Network puts both VMs on one private virtual switch so they can reach each other, while staying fully isolated from the host and the physical LAN — exactly the controlled-lab requirement.

Why B tempts people
Plain NAT gives each VM its own isolated network, so the two VMs can't reach each other at all — the join could never happen.
Why C tempts people
Bridged works for VM-to-VM, but it places both VMs directly on your real home LAN, which is the isolation you specifically wanted to avoid.
Why D tempts people
Mismatched modes put the VMs on different networks, so they wouldn't share a segment and couldn't communicate.

43. Connect it up: Joining a Windows 11 Client to a Server 2022 Domain Controller in VirtualBox

Connect it up

Draw it

One page, no notation unless you need it: draw how these connect — Step 1 — The Right Edition · Step 2 — VirtualBox Network Mode · Step 3 — Addresses & DNS · Step 4 — Join & Verify. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.

44. What you can do now

Recap

LayerThe one thing that must be right
EditionPro / Enterprise / Education
Network modeSame Internal / NAT Network
AddressingSame /24 subnet, static
DNSClient's Preferred DNS = the DC
Verifywhoami shows DOMAIN\user

Next session: with the client joined, we create your first Group Policy Object and watch it apply to the client — the payoff of all this setup.

Sources

  1. Microsoft Learn — Windows 11 edition comparison (domain join is Pro/Enterprise/Education only)
  2. Oracle VirtualBox Manual — Ch. 6, Virtual Networking (NAT, NAT Network, Bridged, Internal, Host-only)
  3. Microsoft Learn — Join a computer to a domain / AD DS locator uses DNS SRV records
  4. Microsoft Learn — Configure DNS for Active Directory; clients must point DNS at the DC
  5. All steps and behaviors are standard for VirtualBox 7.x + Windows 11 / Windows Server 2022; reviewed against the docs above. — Author verification, 2026-06-24 (Wyzant home-lab session prep).

Want this taught 1-on-1? Alexander tutors IT Support & Networking — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108