A dedicated test environment is mandatory when working with Microsoft Configuration Manager, not optional. Production hierarchies are unsuitable for experimentation — neither for new features, nor for task sequence changes, nor for reproducing error conditions. A properly built lab enables exactly that: risk-free testing, targeted reproduction, structured learning.
The following guide describes the complete build of an SCCM lab based on Windows Server 2025 with SQL Server 2022 and ConfigMgr Current Branch. The environment runs fully isolated on a single host machine or server and can be reverted to a defined state at any time through snapshots.
Lab Architecture
The environment consists of three virtual machines on an isolated network 192.168.100.0/24:
| VM | Role | vCPU | RAM | Disk |
|---|---|---|---|---|
LAB-DC01 | Domain Controller (AD DS, DNS, DHCP) | 2 | 4 GB | 60 GB |
LAB-CM01 | Primary Site Server + SQL Server | 4 | 16 GB | 150 GB |
LAB-CL01 | Windows 11 test client | 2 | 4 GB | 60 GB |
Minimum host requirements: eight vCPUs, 24 GB RAM, around 300 GB of free storage. A host with 32 GB RAM and an NVMe SSD is comfortable in practice; anything less works but will feel sluggish.
Network
Host system
└── Hyper-V Virtual Switch "LabSwitch" (internal, no NAT)
├── LAB-DC01 → 192.168.100.10 (DNS + DHCP for the lab)
├── LAB-CM01 → 192.168.100.11
└── LAB-CL01 → 192.168.100.50 (via DHCP)
An internal switch is chosen deliberately: lab traffic stays isolated from the production network, while the host can still communicate with all lab VMs. If internet access is required from inside the lab — for Windows Updates or product downloads, for example — a second NIC on the Domain Controller with NAT sharing can be added, or a dedicated router VM placed in front.
Domain Name
The domain used in the lab is cm.lab. The TLD .local is deliberately avoided: it is reserved for Multicast DNS by RFC 6762 and regularly causes name resolution issues in mixed environments (macOS, iOS, Bonjour). Microsoft likewise advises against .local. A short, unregistered namespace such as cm.lab, or a subdomain approach (lab.example.com on an owned domain), is the better choice.
P@ssw0rdP@ssw0rd and similar) serve lab purposes only. In production environments, complex and unique passwords are assigned per service account, managed through a password manager or — preferably — group Managed Service Accounts (gMSA).
Prerequisites
Software
- Hypervisor: Hyper-V (included in Windows 10/11 Pro and Enterprise) or VMware Workstation Pro
- Windows Server 2025: evaluation build from the Microsoft Evaluation Center (180-day trial)
- SQL Server 2022: Developer Edition, free of charge from Microsoft
- Configuration Manager: evaluation build from the Microsoft Evaluation Center
- Windows 11 24H2: ISO for the test client
- Windows ADK 11 24H2 plus matching WinPE add-on
Recommended Approach
Before every major step, a snapshot of the affected VM is recommended. This saves hours when rolling back after configuration mistakes and is one of the largest benefits of a virtualised lab environment.
Step 1: Prepare Hyper-V and Create VMs
Virtual Switch
In Hyper-V Manager, under Action → Virtual Switch Manager, a new internal switch named LabSwitch is created. The internal type ensures that the host and the lab VMs can communicate, while the physical network remains excluded.
VMs
All three VMs are created through New → Virtual Machine. The following settings are mandatory:
- Generation 2 (UEFI, Secure Boot) — without exception
LabSwitchas the network adapter- Dynamic memory disabled — ConfigMgr reacts poorly to memory ballooning, especially during site installation and SQL operation
Step 2: Build the Domain Controller (LAB-DC01)
Install Windows Server 2025
The installation uses either the Standard or Datacenter edition in the Desktop Experience variant. Core installations work as well but require a higher level of PowerShell proficiency.
After the base installation, three configuration steps are required:
- Rename the computer to
LAB-DC01 - Assign a static IP:
192.168.100.10, subnet mask255.255.255.0, gateway left empty (or pointing to a router VM) - Set the primary DNS temporarily to
127.0.0.1— the AD installation wizard will update these entries automatically after promotion
Install Active Directory
# Install AD DS and DNS role
Install-WindowsFeature -Name AD-Domain-Services,DNS -IncludeManagementTools
# Create the forest (Domain: cm.lab, NetBIOS: CM)
Install-ADDSForest `
-DomainName "cm.lab" `
-DomainNetbiosName "CM" `
-ForestMode WinThreshold `
-DomainMode WinThreshold `
-InstallDns `
-SafeModeAdministratorPassword (ConvertTo-SecureString "P@ssw0rdP@ssw0rd" -AsPlainText -Force) `
-Force
The server reboots automatically. After the reboot, LAB-DC01 is the forest root DC for cm.lab.
DNS Hygiene
Two settings prevent the usual first-install complaints from the Best Practices Analyzer:
# Create a reverse lookup zone for IPv4
Add-DnsServerPrimaryZone `
-NetworkID "192.168.100.0/24" `
-ReplicationScope "Forest" `
-DynamicUpdate Secure
# The DC registers its A/AAAA record automatically
Set-DnsClient -InterfaceAlias "Ethernet" -RegisterThisConnectionsAddress $true
# Force the Netlogon service to re-register its SRV records
Restart-Service Netlogon
A short sanity check confirms the zone is reachable:
Resolve-DnsName LAB-DC01.cm.lab
Set Up the DHCP Server
# Install the DHCP role
Install-WindowsFeature -Name DHCP -IncludeManagementTools
# Authorize DHCP in AD
Add-DhcpServerInDC -DnsName "LAB-DC01.cm.lab" -IPAddress 192.168.100.10
# Create the scope
Add-DhcpServerv4Scope `
-Name "Lab Scope" `
-StartRange 192.168.100.50 `
-EndRange 192.168.100.200 `
-SubnetMask 255.255.255.0 `
-State Active
# DHCP options: DNS server and domain name
Set-DhcpServerv4OptionValue `
-ScopeId 192.168.100.0 `
-DnsServer 192.168.100.10 `
-DnsDomain "cm.lab"
# DHCP service: delayed start plus automatic restart on failure
sc.exe config DHCPServer start=delayed-auto
sc.exe failure DHCPServer reset=0 actions=restart/0/restart/0/restart/0
KDS Root Key for gMSA
Even if the lab does not use group Managed Service Accounts initially, it is advisable to create the Key Distribution Service root key immediately. Without it, any later gMSA creation will fail.
# Create the KDS root key (AddHours -10 allows immediate use instead of waiting for replication)
Add-KdsRootKey -EffectiveTime ((Get-Date).AddHours(-10))
The procedure is documented in the Microsoft article on group Managed Service Accounts.
OUs and Service Accounts
A flat AD structure is sufficient for the lab. Separating accounts by type simplifies filtering and delegation later on:
# OU structure
New-ADOrganizationalUnit -Name "LAB"
New-ADOrganizationalUnit -Name "Clients" -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Member Servers" -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Users" -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Groups" -Path "OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Administrative Accounts" -Path "OU=Users,OU=LAB,DC=cm,DC=lab"
New-ADOrganizationalUnit -Name "Special Use Accounts" -Path "OU=Users,OU=LAB,DC=cm,DC=lab"
# ConfigMgr service account
New-ADUser `
-Name "svc_sccm" `
-SamAccountName "svc_sccm" `
-UserPrincipalName "svc_sccm@cm.lab" `
-Path "OU=Special Use Accounts,OU=Users,OU=LAB,DC=cm,DC=lab" `
-AccountPassword (ConvertTo-SecureString "P@ssw0rdP@ssw0rd" -AsPlainText -Force) `
-PasswordNeverExpires $true `
-CannotChangePassword $true `
-Enabled $true
# Group for SCCM server computer accounts
New-ADGroup `
-Name "CM Servers" `
-SamAccountName "CM Servers" `
-GroupCategory Security `
-GroupScope Global `
-Path "OU=Groups,OU=LAB,DC=cm,DC=lab" `
-Description "ConfigMgr Site System Servers"
Step 3: Install SQL Server on LAB-CM01
Operating System and Domain Join
On LAB-CM01, Windows Server 2025 is installed. After assigning a static IP (192.168.100.11, DNS 192.168.100.10), the machine joins the domain:
Add-Computer -DomainName "cm.lab" -Credential (Get-Credential) -Restart
SQL Server 2022 Developer Edition
SQL installation is performed through the setup GUI. The following settings are relevant:
- Instance name — default (
MSSQLSERVER). ConfigMgr supports named instances, but the default is simpler. - Collation —
SQL_Latin1_General_CP1_CI_AS. This collation is mandatory for ConfigMgr; any deviation causes the ConfigMgr setup to abort. - SQL Server Agent — startup type Automatic. Required by ConfigMgr for maintenance tasks.
- SQL Server service account —
NT Service\MSSQLSERVERor a domain account. The default service account is sufficient for the lab. - TempDB files — file count equal to the number of logical cores, capped at eight. This is standard best practice and is proposed by the SQL setup itself.
SQL Server Management Studio (SSMS)
SSMS is downloaded and installed separately — since SQL Server 2017 it is no longer part of the SQL setup. The current release is available on the Microsoft download page.
SQL Permissions for ConfigMgr
The computer account of the site server — in the lab, the site server is identical to the SQL server, so LAB-CM01$ — requires sysadmin rights on the SQL instance. For a single-server installation, the setup grants these automatically. For a distributed SQL instance, the assignment must be done manually:
-- Run on the SQL instance (only needed when SQL and site server are separated)
USE [master]
CREATE LOGIN [CM\LAB-CM01$] FROM WINDOWS
ALTER SERVER ROLE sysadmin ADD MEMBER [CM\LAB-CM01$]
Step 4: Meet the ConfigMgr Prerequisites
Before the ConfigMgr setup can start, IIS roles, the ADK, and the schema extension must be in place.
Windows Roles and Features
# IIS + BITS + Remote Differential Compression
Install-WindowsFeature `
-Name Web-Server, Web-Asp-Net45, Web-ISAPI-Ext, Web-ISAPI-Filter, `
Web-Net-Ext45, Web-Windows-Auth, Web-Mgmt-Console, `
Web-WMI, Web-Scripting-Tools, `
BITS, RDC `
-IncludeManagementTools
# .NET 3.5 for certain ConfigMgr components (optional, but recommended)
Install-WindowsFeature -Name NET-Framework-Core
The complete and current list is maintained by Microsoft under Site and site system prerequisites. A cross-check is worthwhile when Configuration Manager version jumps, because individual entries can change.
Install the Windows ADK
The ADK must match the Windows version in use. For Windows Server 2025, the supported pairing is the Windows ADK for Windows 11 24H2. Installation order:
- Windows ADK setup — with the components Deployment Tools and User State Migration Tool (USMT)
- WinPE Add-on for the Windows ADK — separate installation after the ADK
Microsoft maintains the compatibility matrix under Support for the Windows ADK in Configuration Manager.
Extend the AD Schema for ConfigMgr
The AD schema extension is performed once from the installation media. It is irreversible — schema changes cannot be rolled back. For the lab this is uncritical; in production it is a deliberate decision.
# Run on the DC (account must be a member of the "Schema Admins" group)
& "<path-to-ConfigMgr-ISO>\SMSSETUP\BIN\X64\extadsch.exe"
# Check the result log
Get-Content "C:\ExtADSch.log" -Tail 20
System Management Container in AD
ConfigMgr publishes site information to an AD container so that clients can locate the management point through an AD lookup. This container does not exist by default and must be created manually:
# Run on the DC
Import-Module ActiveDirectory
$domainDN = (Get-ADDomain).DistinguishedName
$systemDN = "CN=System,$domainDN"
$smDN = "CN=System Management,$systemDN"
if (-not (Get-ADObject -Filter { DistinguishedName -eq $smDN } -ErrorAction SilentlyContinue)) {
New-ADObject -Name "System Management" -Type "container" -Path $systemDN
}
# Full control for the site server computer account
$acl = Get-Acl -Path "AD:\$smDN"
$computerAccount = New-Object System.Security.Principal.NTAccount("CM\LAB-CM01$")
$ace = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
$computerAccount,
[System.DirectoryServices.ActiveDirectoryRights]::GenericAll,
[System.Security.AccessControl.AccessControlType]::Allow,
[System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
)
$acl.AddAccessRule($ace)
Set-Acl -Path "AD:\$smDN" -AclObject $acl
Step 5: Install ConfigMgr
The ConfigMgr ISO is mounted on LAB-CM01. Setup is launched through SMSSETUP\BIN\X64\setup.exe.
The installation wizard options for a straightforward lab:
- Installation type — Install a Configuration Manager primary site
- Product key — Evaluation edition (180 days), or an existing key
- Prerequisite downloads — point to a local folder; the prereq files are cached there
- Site code —
LAB(three alphanumeric characters) - Site name —
Lab Site - Installation folder —
C:\Program Files\Microsoft Configuration Manager - Database server —
LAB-CM01(default instance) - SMS Provider —
LAB-CM01 - Client communication — HTTPS or HTTP; HTTP is sufficient for the lab
- Site system roles — Management Point and Distribution Point on
LAB-CM01
The installation typically takes 30 to 60 minutes. Progress is visible in C:\ConfigMgrSetup.log:
# Live tail of the setup log
Get-Content "C:\ConfigMgrSetup.log" -Wait -Tail 20
Common Prerequisite Failures
SQL Server collation is not supported
The SQL instance uses a collation other than SQL_Latin1_General_CP1_CI_AS. The remedy is a SQL reinstall with the correct collation.
Schema extensions not found
extadsch.exe has not been executed. The AD schema extension must be carried out on the DC with a Schema Admins account.
Cannot connect to SQL Server
TCP/IP is disabled on the SQL instance, or a firewall is blocking the connection. In SQL Server Configuration Manager, the TCP/IP protocol is enabled and the SQL service restarted.
ADK not installed or wrong version
The installed ADK version does not match the supported matrix. The correct ADK plus WinPE add-on is installed.
WSUS not installed
Relevant only when the Software Update Point role is planned. For a basic lab this message is safe to ignore.
Step 6: Base Configuration
Once the installation completes, the ConfigMgr console becomes available. Three configuration steps are required before any clients can be enrolled.
Boundary and Boundary Group
Boundaries define which IP ranges belong to which site. Without a matching Boundary Group, a client cannot locate its management point.
Under Administration → Hierarchy Configuration → Boundaries, a new boundary is created with:
- Type: IP address range
- Range:
192.168.100.1–192.168.100.254
Under Boundary Groups, a new Boundary Group is created with:
- The boundary added as a member
- Site system:
LAB-CM01as the management point
Discovery Methods
To populate ConfigMgr with AD objects, at least two discoveries are enabled under Administration → Hierarchy Configuration → Discovery Methods:
- Active Directory System Discovery — container
DC=cm,DC=lab, hourly - Active Directory User Discovery — identical container path
After enabling, a discovery run can be triggered immediately via Run full discovery now.
Test the Client Installation
The test client LAB-CL01 is joined to the cm.lab domain in advance and receives an address from the lab DHCP scope. The client installation can then be triggered directly:
# Run on LAB-CL01 as a domain administrator
\\LAB-CM01\SMS_LAB\Client\ccmsetup.exe /mp:LAB-CM01.cm.lab SMSSITECODE=LAB
Progress is recorded in C:\Windows\ccmsetup\Logs\ccmsetup.log. After 10 to 15 minutes, the client appears in the console under Assets and Compliance → Devices.
Set-NetFirewallProfile -All -Enabled False) is a pragmatic simplification. In production, targeted exceptions for TCP 80/443, 445, and 10123 are deployed through GPO instead.
Step 7: Distribution Point
Without a distribution point, no packages, drivers, or applications can be deployed to clients. The role can be added to LAB-CM01 after the fact:
- Administration → Site Configuration → Servers and Site System Roles
- Select
LAB-CM01→ Add Site System Roles - Add the Distribution Point role
- Accept the default settings (HTTP is sufficient for the lab)
Content distribution for an application is then performed through right-click → Distribute Content → selecting LAB-CM01 as the target.
Common Pitfalls
Client does not appear in the console
The first check is C:\Windows\ccmsetup\Logs\ccmsetup.log on the client. Typical causes: DNS resolution for the MP fails, a firewall on server or client is blocking communication, or the management point is misconfigured. A cross-check with Test-NetConnection LAB-CM01.cm.lab -Port 80 confirms reachability.
Discovery finds no systems
The site server computer account (LAB-CM01$) requires read access to the OUs being searched. The default installation provides this; after OU permission changes, access may have been lost.
SQL Server connection fails
The SQL Server Configuration Manager on LAB-CM01 governs the network protocols. Under SQL Server Network Configuration → Protocols for MSSQLSERVER, TCP/IP must be enabled. After enabling, the SQL service is restarted, and the SQL Server Browser is set to Automatic when a named instance is in use.
WinPE boot image is empty after ADK installation In the console, under Software Library → Operating Systems → Boot Images, a right-click on each boot image triggers Update Distribution Points. Without this step, the boot images exist in the content store but remain empty on the DP.
Next Steps
With this baseline, the lab is ready for the typical SCCM scenarios. Natural extensions are:
- Software Update Point — requires WSUS on the site server
- Operating System Deployment (OSD) — build a task sequence and perform a bare-metal installation against another test client
- PSADT packages as ConfigMgr applications — including detection rules and user experience
- Co-management with Intune — once an Entra ID tenant is available
Rule of thumb: Before every significant configuration change, a snapshot of the affected VM is taken. The time saved during rollbacks outweighs the storage overhead many times over.
Tested with: Windows Server 2025 (24H2), SQL Server 2022 Developer Edition (16.0.4140.3), Configuration Manager Current Branch 2503, Windows ADK 11 24H2.