In this blog post, I will walk you through the process of setting up a Windows Server deployment using Hyper-V. This includes configuring a router, setting up a Windows Server as a Domain Controller, installing DHCP, DNS, Active Directory, and WDS, and finally adding two client machines to the domain. Additionally, I automated software deployment using Group Policy (GPO).

This guide is ideal for IT professionals or enthusiasts who want to set up a complete Windows network environment from scratch.

Key learning: patience is crucial. Not everything works immediately, and troubleshooting is an essential part of IT work. Sometimes, things just need time to take effect! This is an essential skill for any network administrator.

Additionally, setting up such environments is not only useful for corporate IT infrastructure but also for offensive security testing. Understanding Windows deployments, Active Directory structures, and network policies is invaluable for penetration testers who want to simulate and exploit real-world enterprise setups.

Setting Up Hyper-V and Creating Virtual Machines

Creating a Router VM

Since this is a virtual lab environment, I needed a router VM to act as a gateway for my network. I assigned it two network interfaces, one connected to the external network and one for the internal network (10.10.0.0/24). The external interface pulled its address via DHCP, while the internal interface was set statically to 10.10.0.1/24. I then enabled NAT and DHCP relay so internal clients could reach the outside network.

Creating the Windows Server Domain Controller

Next, I installed Windows Server as a VM, assigned it the static IP 10.10.0.200, and configured it as the Domain Controller for wayne.ent.

Creating Client VMs

I then created two Windows 10 VMs, Client-001 and Client-002, assigned them IPs via DHCP, and joined both to the wayne.ent domain.

Configuring the Windows Server (SRV-DC-001)

Installing and Configuring DHCP

The DHCP server dynamically assigns IP addresses to the clients in the network. I installed the DHCP Server role via Server Manager and configured a new scope for the 10.10.0.0/24 subnet, with 10.10.0.1 as the gateway and 10.10.0.200 as the DNS server. After that, I activated the scope and authorized the DHCP server.

Installing and Configuring DNS

I installed the DNS Server role, created a forward lookup zone for wayne.ent, added a reverse lookup zone for the 10.10.0.x subnet, and configured conditional forwarders for internet name resolution.

Setting Up Active Directory (AD DS)

Active Directory is the core of our domain environment. I promoted the server to a Domain Controller, created Organizational Units for Users, Computers, and Groups, added test user accounts, and configured Group Policy Objects for security settings.

Deploying Windows via WDS

Installing Windows Deployment Services (WDS)

I set up Windows Deployment Services to allow PXE boot installations. After installing the WDS role, I configured it to respond to both known and unknown clients and enabled PXE boot support. I then mounted a Windows ISO, extracted boot.wim and install.wim, added them to WDS, and configured a PXE boot policy for new machines.

Booting Clients via PXE

I configured the Hyper-V VM's network adapter to boot via PXE, powered on the client, and pressed F12 to initiate the PXE boot. Windows 10 installed successfully through WDS.

Automating Software Deployment with Group Policy

To simplify software installation across all clients, I used Group Policy to deploy Google Chrome.

I started by downloading the Google Chrome MSI package from Google Enterprise and placing it in a shared folder at C:\Software\Chrome\GoogleChromeStandaloneEnterprise64.msi.

From there, I opened the Group Policy Management Console (gpmc.msc) and created a new GPO named "Google Chrome Deployment." Inside it, I navigated to Computer Configuration → Policies → Software Settings → Software Installation, and added the MSI package via its network path, \\SRV-DC-001\Software\Chrome\GoogleChromeStandaloneEnterprise64.msi, with the deployment mode set to Assigned.

Finally, I linked the Google Chrome Deployment GPO to the Computers OU, ran gpupdate /force, and restarted the clients. I verified the installation with:

wmic product get name | find "Google Chrome"

Troubleshooting and Final Success

Initially, the GPO didn't seem to work. gpresult /r didn't list the Chrome installer GPO, yet the software installed successfully after some time. I checked the Event Viewer for Group Policy errors, verified GPO permissions for "Domain Computers," made sure the network share was accessible, and rebooted the clients multiple times to give the GPO a chance to apply properly. In the end it just came down to waiting - sometimes policies take longer to apply than you'd expect. Eventually, Google Chrome installed successfully across all clients.

Conclusion

This setup demonstrates how to deploy a fully functional Windows network using Hyper-V. I configured a router VM with NAT and DHCP relay, set up a Windows Server as a Domain Controller with AD DS, DHCP, and DNS, installed and configured Windows Deployment Services, connected client machines via DHCP and domain join, and used Group Policy to automate software deployment.

The biggest takeaways: patience pays off, since IT setups can take time and troubleshooting is part of the job; network administration is really about structure and planning, and having a clear plan makes implementations go much smoother; enterprise environments live and die by automation, with GPO, scripting, and centralized deployments saving huge amounts of time; and offensive security benefits directly from understanding how enterprise networks are put together, since that same knowledge helps identify weak points during penetration testing and security audits.

This lab serves as a great foundation for enterprise environments or testing network deployments. If you have any questions or want to expand on this setup, feel free to reach out.

Next Steps

Future improvements could include configuring Roaming Profiles, Folder Redirection, WSUS for Windows Updates, or automating other software deployments.

Have any questions? Let me know in the comments.