SCCM / ConfigMgr

Building an SCCM Lab on Windows Server 2025

A step-by-step guide to a fully working SCCM lab on Windows Server 2025 — Domain Controller, SQL Server 2022, and Primary Site Server, with verified PowerShell scripts and the usual pitfalls.

SCCM ConfigMgr Windows Server 2025 Active Directory Lab Domain Controller SQL Server 2022
2026-04-16 · Miloch · 14 min read

A dedicated test environment is mandatory when working with Microsoft Configuration Manager, not optional. Production hierarchies are unsuitable for experimentation — neither for new features, nor for task sequence changes, nor for reproducing error conditions. A properly built lab enables exactly that: risk-free testing, targeted reproduction, structured learning.

The following guide describes the complete build of an SCCM lab based on Windows Server 2025 with SQL Server 2022 and ConfigMgr Current Branch. The environment runs fully isolated on a single host machine or server and can be reverted to a defined state at any time through snapshots.

Lab Architecture

The environment consists of three virtual machines on an isolated network 192.168.100.0/24:

VMRolevCPURAMDisk
LAB-DC01Domain Controller (AD DS, DNS, DHCP)24 GB60 GB
LAB-CM01Primary Site Server + SQL Server416 GB150 GB
LAB-CL01Windows 11 test client24 GB60 GB

Minimum host requirements: eight vCPUs, 24 GB RAM, around 300 GB of free storage. A host with 32 GB RAM and an NVMe SSD is comfortable in practice; anything less works but will feel sluggish.

Network

text
Host system
  └── Hyper-V Virtual Switch "LabSwitch" (internal, no NAT)
        ├── LAB-DC01  → 192.168.100.10   (DNS + DHCP for the lab)
        ├── LAB-CM01  → 192.168.100.11
        └── LAB-CL01  → 192.168.100.50   (via DHCP)

An internal switch is chosen deliberately: lab traffic stays isolated from the production network, while the host can still communicate with all lab VMs. If internet access is required from inside the lab — for Windows Updates or product downloads, for example — a second NIC on the Domain Controller with NAT sharing can be added, or a dedicated router VM placed in front.

Domain Name

The domain used in the lab is cm.lab. The TLD .local is deliberately avoided: it is reserved for Multicast DNS by RFC 6762 and regularly causes name resolution issues in mixed environments (macOS, iOS, Bonjour). Microsoft likewise advises against .local. A short, unregistered namespace such as cm.lab, or a subdomain approach (lab.example.com on an owned domain), is the better choice.

Warning
The passwords used in this article (P@ssw0rdP@ssw0rd and similar) serve lab purposes only. In production environments, complex and unique passwords are assigned per service account, managed through a password manager or — preferably — group Managed Service Accounts (gMSA).

Prerequisites

Software

Before every major step, a snapshot of the affected VM is recommended. This saves hours when rolling back after configuration mistakes and is one of the largest benefits of a virtualised lab environment.

Step 1: Prepare Hyper-V and Create VMs

Virtual Switch

In Hyper-V Manager, under Action → Virtual Switch Manager, a new internal switch named LabSwitch is created. The internal type ensures that the host and the lab VMs can communicate, while the physical network remains excluded.

VMs

All three VMs are created through New → Virtual Machine. The following settings are mandatory:

Step 2: Build the Domain Controller (LAB-DC01)

Install Windows Server 2025

The installation uses either the Standard or Datacenter edition in the Desktop Experience variant. Core installations work as well but require a higher level of PowerShell proficiency.

After the base installation, three configuration steps are required:

  1. Rename the computer to LAB-DC01
  2. Assign a static IP: 192.168.100.10, subnet mask 255.255.255.0, gateway left empty (or pointing to a router VM)
  3. Set the primary DNS temporarily to 127.0.0.1 — the AD installation wizard will update these entries automatically after promotion

Install Active Directory

powershell
# Install AD DS and DNS role
Install-WindowsFeature -Name AD-Domain-Services,DNS -IncludeManagementTools

# Create the forest (Domain: cm.lab, NetBIOS: CM)
Install-ADDSForest `
    -DomainName "cm.lab" `
    -DomainNetbiosName "CM" `
    -ForestMode WinThreshold `
    -DomainMode WinThreshold `
    -InstallDns `
    -SafeModeAdministratorPassword (ConvertTo-SecureString "P@ssw0rdP@ssw0rd" -AsPlainText -Force) `
    -Force

The server reboots automatically. After the reboot, LAB-DC01 is the forest root DC for cm.lab.

DNS Hygiene

Two settings prevent the usual first-install complaints from the Best Practices Analyzer:

powershell
# Create a reverse lookup zone for IPv4
Add-DnsServerPrimaryZone `
    -NetworkID "192.168.100.0/24" `
    -ReplicationScope "Forest" `
    -DynamicUpdate Secure

# The DC registers its A/AAAA record automatically
Set-DnsClient -InterfaceAlias "Ethernet" -RegisterThisConnectionsAddress $true

# Force the Netlogon service to re-register its SRV records
Restart-Service Netlogon

A short sanity check confirms the zone is reachable:

powershell
Resolve-DnsName LAB-DC01.cm.lab

Set Up the DHCP Server

powershell
# Install the DHCP role
Install-WindowsFeature -Name DHCP -IncludeManagementTools

# Authorize DHCP in AD
Add-DhcpServerInDC -DnsName "LAB-DC01.cm.lab" -IPAddress 192.168.100.10

# Create the scope
Add-DhcpServerv4Scope `
    -Name "Lab Scope" `
    -StartRange 192.168.100.50 `
    -EndRange 192.168.100.200 `
    -SubnetMask 255.255.255.0 `
    -State Active

# DHCP options: DNS server and domain name
Set-DhcpServerv4OptionValue `
    -ScopeId 192.168.100.0 `
    -DnsServer 192.168.100.10 `
    -DnsDomain "cm.lab"

# DHCP service: delayed start plus automatic restart on failure
sc.exe config DHCPServer start=delayed-auto
sc.exe failure DHCPServer reset=0 actions=restart/0/restart/0/restart/0
Note
The DHCP server is deliberately set to Delayed Start. Without this delay, the service attempts to start at boot before AD is fully available, which leads to authorization errors in the event log.

KDS Root Key for gMSA

Even if the lab does not use group Managed Service Accounts initially, it is advisable to create the Key Distribution Service root key immediately. Without it, any later gMSA creation will fail.

powershell
# Create the KDS root key (AddHours -10 allows immediate use instead of waiting for replication)
Add-KdsRootKey -EffectiveTime ((Get-Date).AddHours(-10))

The procedure is documented in the Microsoft article on group Managed Service Accounts.

OUs and Service Accounts

A flat AD structure is sufficient for the lab. Separating accounts by type simplifies filtering and delegation later on:

powershell
# OU structure
New-ADOrganizationalUnit -Name "LAB"
New-ADOrganizationalUnit -Name "Clients"        -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Member Servers" -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Users"          -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Groups"         -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Administrative Accounts" -Path "OU=Users,OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Special Use Accounts"    -Path "OU=Users,OU=LAB,DC=cm,DC=lab"

# ConfigMgr service account
New-ADUser `
    -Name "svc_sccm" `
    -SamAccountName "svc_sccm" `
    -UserPrincipalName "svc_sccm@cm.lab" `
    -Path "OU=Special Use Accounts,OU=Users,OU=LAB,DC=cm,DC=lab" `
    -AccountPassword (ConvertTo-SecureString "P@ssw0rdP@ssw0rd" -AsPlainText -Force) `
    -PasswordNeverExpires $true `
    -CannotChangePassword $true `
    -Enabled $true

# Group for SCCM server computer accounts
New-ADGroup `
    -Name "CM Servers" `
    -SamAccountName "CM Servers" `
    -GroupCategory Security `
    -GroupScope Global `
    -Path "OU=Groups,OU=LAB,DC=cm,DC=lab" `
    -Description "ConfigMgr Site System Servers"
Note
In a production environment, each ConfigMgr function (Network Access, Client Push, Domain Join, SQL Reporting Services, and so on) receives its own least-privilege account. A shared account is acceptable in the lab but must be documented as such.

Step 3: Install SQL Server on LAB-CM01

Operating System and Domain Join

On LAB-CM01, Windows Server 2025 is installed. After assigning a static IP (192.168.100.11, DNS 192.168.100.10), the machine joins the domain:

powershell
Add-Computer -DomainName "cm.lab" -Credential (Get-Credential) -Restart

SQL Server 2022 Developer Edition

SQL installation is performed through the setup GUI. The following settings are relevant:

Warning
The SQL collation can only be changed after installation by rebuilding the master database — effectively a full reinstall. Selecting it correctly at install time is therefore essential.

SQL Server Management Studio (SSMS)

SSMS is downloaded and installed separately — since SQL Server 2017 it is no longer part of the SQL setup. The current release is available on the Microsoft download page.

SQL Permissions for ConfigMgr

The computer account of the site server — in the lab, the site server is identical to the SQL server, so LAB-CM01$ — requires sysadmin rights on the SQL instance. For a single-server installation, the setup grants these automatically. For a distributed SQL instance, the assignment must be done manually:

sql
-- Run on the SQL instance (only needed when SQL and site server are separated)
USE [master]
CREATE LOGIN [CM\LAB-CM01$] FROM WINDOWS
ALTER SERVER ROLE sysadmin ADD MEMBER [CM\LAB-CM01$]

Step 4: Meet the ConfigMgr Prerequisites

Before the ConfigMgr setup can start, IIS roles, the ADK, and the schema extension must be in place.

Windows Roles and Features

powershell
# IIS + BITS + Remote Differential Compression
Install-WindowsFeature `
    -Name Web-Server, Web-Asp-Net45, Web-ISAPI-Ext, Web-ISAPI-Filter, `
           Web-Net-Ext45, Web-Windows-Auth, Web-Mgmt-Console, `
           Web-WMI, Web-Scripting-Tools, `
           BITS, RDC `
    -IncludeManagementTools

# .NET 3.5 for certain ConfigMgr components (optional, but recommended)
Install-WindowsFeature -Name NET-Framework-Core

The complete and current list is maintained by Microsoft under Site and site system prerequisites. A cross-check is worthwhile when Configuration Manager version jumps, because individual entries can change.

Install the Windows ADK

The ADK must match the Windows version in use. For Windows Server 2025, the supported pairing is the Windows ADK for Windows 11 24H2. Installation order:

  1. Windows ADK setup — with the components Deployment Tools and User State Migration Tool (USMT)
  2. WinPE Add-on for the Windows ADK — separate installation after the ADK

Microsoft maintains the compatibility matrix under Support for the Windows ADK in Configuration Manager.

Extend the AD Schema for ConfigMgr

The AD schema extension is performed once from the installation media. It is irreversible — schema changes cannot be rolled back. For the lab this is uncritical; in production it is a deliberate decision.

powershell
# Run on the DC (account must be a member of the "Schema Admins" group)
& "<path-to-ConfigMgr-ISO>\SMSSETUP\BIN\X64\extadsch.exe"

# Check the result log
Get-Content "C:\ExtADSch.log" -Tail 20

System Management Container in AD

ConfigMgr publishes site information to an AD container so that clients can locate the management point through an AD lookup. This container does not exist by default and must be created manually:

powershell
# Run on the DC
Import-Module ActiveDirectory

$domainDN = (Get-ADDomain).DistinguishedName
$systemDN = "CN=System,$domainDN"
$smDN     = "CN=System Management,$systemDN"

if (-not (Get-ADObject -Filter { DistinguishedName -eq $smDN } -ErrorAction SilentlyContinue)) {
    New-ADObject -Name "System Management" -Type "container" -Path $systemDN
}

# Full control for the site server computer account
$acl = Get-Acl -Path "AD:\$smDN"
$computerAccount = New-Object System.Security.Principal.NTAccount("CM\LAB-CM01$")
$ace = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
    $computerAccount,
    [System.DirectoryServices.ActiveDirectoryRights]::GenericAll,
    [System.Security.AccessControl.AccessControlType]::Allow,
    [System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
)
$acl.AddAccessRule($ace)
Set-Acl -Path "AD:\$smDN" -AclObject $acl

Step 5: Install ConfigMgr

The ConfigMgr ISO is mounted on LAB-CM01. Setup is launched through SMSSETUP\BIN\X64\setup.exe.

The installation wizard options for a straightforward lab:

The installation typically takes 30 to 60 minutes. Progress is visible in C:\ConfigMgrSetup.log:

powershell
# Live tail of the setup log
Get-Content "C:\ConfigMgrSetup.log" -Wait -Tail 20

Common Prerequisite Failures

SQL Server collation is not supported The SQL instance uses a collation other than SQL_Latin1_General_CP1_CI_AS. The remedy is a SQL reinstall with the correct collation.

Schema extensions not found extadsch.exe has not been executed. The AD schema extension must be carried out on the DC with a Schema Admins account.

Cannot connect to SQL Server TCP/IP is disabled on the SQL instance, or a firewall is blocking the connection. In SQL Server Configuration Manager, the TCP/IP protocol is enabled and the SQL service restarted.

ADK not installed or wrong version The installed ADK version does not match the supported matrix. The correct ADK plus WinPE add-on is installed.

WSUS not installed Relevant only when the Software Update Point role is planned. For a basic lab this message is safe to ignore.

Step 6: Base Configuration

Once the installation completes, the ConfigMgr console becomes available. Three configuration steps are required before any clients can be enrolled.

Boundary and Boundary Group

Boundaries define which IP ranges belong to which site. Without a matching Boundary Group, a client cannot locate its management point.

Under Administration → Hierarchy Configuration → Boundaries, a new boundary is created with:

Under Boundary Groups, a new Boundary Group is created with:

Discovery Methods

To populate ConfigMgr with AD objects, at least two discoveries are enabled under Administration → Hierarchy Configuration → Discovery Methods:

After enabling, a discovery run can be triggered immediately via Run full discovery now.

Test the Client Installation

The test client LAB-CL01 is joined to the cm.lab domain in advance and receives an address from the lab DHCP scope. The client installation can then be triggered directly:

powershell
# Run on LAB-CL01 as a domain administrator
\\LAB-CM01\SMS_LAB\Client\ccmsetup.exe /mp:LAB-CM01.cm.lab SMSSITECODE=LAB

Progress is recorded in C:\Windows\ccmsetup\Logs\ccmsetup.log. After 10 to 15 minutes, the client appears in the console under Assets and Compliance → Devices.

Note
The Windows firewall blocks inbound SMB connections and content ports by default. For the lab, disabling the firewall on all lab VMs (Set-NetFirewallProfile -All -Enabled False) is a pragmatic simplification. In production, targeted exceptions for TCP 80/443, 445, and 10123 are deployed through GPO instead.

Step 7: Distribution Point

Without a distribution point, no packages, drivers, or applications can be deployed to clients. The role can be added to LAB-CM01 after the fact:

  1. Administration → Site Configuration → Servers and Site System Roles
  2. Select LAB-CM01 → Add Site System Roles
  3. Add the Distribution Point role
  4. Accept the default settings (HTTP is sufficient for the lab)

Content distribution for an application is then performed through right-click → Distribute Content → selecting LAB-CM01 as the target.

Common Pitfalls

Client does not appear in the console The first check is C:\Windows\ccmsetup\Logs\ccmsetup.log on the client. Typical causes: DNS resolution for the MP fails, a firewall on server or client is blocking communication, or the management point is misconfigured. A cross-check with Test-NetConnection LAB-CM01.cm.lab -Port 80 confirms reachability.

Discovery finds no systems The site server computer account (LAB-CM01$) requires read access to the OUs being searched. The default installation provides this; after OU permission changes, access may have been lost.

SQL Server connection fails The SQL Server Configuration Manager on LAB-CM01 governs the network protocols. Under SQL Server Network Configuration → Protocols for MSSQLSERVER, TCP/IP must be enabled. After enabling, the SQL service is restarted, and the SQL Server Browser is set to Automatic when a named instance is in use.

WinPE boot image is empty after ADK installation In the console, under Software Library → Operating Systems → Boot Images, a right-click on each boot image triggers Update Distribution Points. Without this step, the boot images exist in the content store but remain empty on the DP.

Next Steps

With this baseline, the lab is ready for the typical SCCM scenarios. Natural extensions are:

Rule of thumb: Before every significant configuration change, a snapshot of the affected VM is taken. The time saved during rollbacks outweighs the storage overhead many times over.


Tested with: Windows Server 2025 (24H2), SQL Server 2022 Developer Edition (16.0.4140.3), Configuration Manager Current Branch 2503, Windows ADK 11 24H2.

SCCM ConfigMgr Windows Server 2025 Active Directory Lab Domain Controller SQL Server 2022
M

Miloch

Enterprise IT, SCCM & ConfigMgr, PowerShell & Automation — building systems right.