Windows Server DHCP Infrastructure

Windows Server DHCP Infrastructure project cover

Project CategoryNetwork Infrastructure
PlatformMicrosoft Windows Server 2022
Core TechnologiesDHCP, Active Directory, DNS, IPv4
Project FocusCentralized IP address allocation, client configuration, and DHCP administration

Project Overview

Deployed an Active Directory-authorized DHCP service with a managed IPv4 scope, exclusions, scope options, reservations, lease monitoring, client validation, PowerShell verification, and audit logging.

1. Business Scenario

A growing organization requires a centralized method for assigning and managing IP addresses across its internal network.

Manually assigning static IP addresses to every workstation creates several operational problems:

To address these challenges, a dedicated Windows Server DHCP solution was deployed.

The DHCP server automatically assigns valid TCP/IP configurations to client devices and provides centralized control over IP address allocation.

2. Project Objectives

The main objectives of this project were to:

3. Lab Environment

3.1 Virtualization Platform

3.2 Operating Systems

3.3 Domain Environment

3.4 Server Roles

3.5 DC01

The domain controller provided the following services:

3.6 DHCP01

The DHCP server provided:

3.7 W11-CLIENT01

The Windows 11 virtual machine was used to test:

4. DHCP Server Architecture Diagram

DHCP Server Architecture Diagram

DHCP Server architecture showing DC01, DHCP01, W11-CLIENT01, Active Directory integration, DNS services, DHCP scope configuration, and the DORA lease process.

5. IP Addressing Plan (Actual Lab Values)

The following addressing structure reflects the actual values configured and verified in the lab, as confirmed by the configuration and PowerShell screenshots.

Device or Purpose Addressing Method Address Used in the Lab
Network address Static 192.168.10.0/24
Domain Controller (DC01) Static 192.168.10.10
DHCP Server (DHCP01) Static 192.168.10.20
Default Gateway Static / lab-defined 192.168.10.1
DHCP Scope Start Dynamic 192.168.10.100
DHCP Scope End Dynamic 192.168.10.200
Exclusion Range Dynamic pool exclusion 192.168.10.100 – 192.168.10.110
Client Lease Obtained (W11-CLIENT01) Dynamic 192.168.10.111
Primary DNS Server Static 192.168.10.10
DNS Domain Name DHCP option yasserteach.local
Subnet Mask DHCP option 255.255.255.0
DHCP Lease Duration Scope setting 8 days

The infrastructure servers were assigned static IP addresses. Client devices received their network configuration dynamically from the DHCP server.

6. Project Implementation

6.1 Prepare the Virtual Machines

Three virtual machines were prepared in VMware Workstation:

Each virtual machine was configured with:

All virtual machines were connected to the same VMware virtual network. This was an important requirement because DHCP initially depends on broadcast traffic. If the client and the DHCP server are connected to different isolated virtual networks, the DHCP Discover message will not reach the server.

6.2 Confirm the Existing Domain Controller Environment

Before deploying DHCP, the existing domain controller environment was reviewed to confirm that the core Active Directory services required by the DHCP deployment were already in place. DC01 had been configured with:

The screenshot below documents the existing DC01 role configuration that provided the Active Directory and DNS foundation for the DHCP lab. Network and DNS settings were subsequently validated during DHCP01 connectivity and name-resolution testing.

Windows Server DHCP Infrastructure project screenshot

Existing DC01 environment — Active Directory Domain Services and DNS Server roles providing the domain and internal name-resolution services required by the DHCP deployment.

6.3 Install Windows Server 2022 on DHCP01

Windows Server 2022 was installed on the second virtual machine. After installation, the initial server configuration was completed. The following settings were configured:

The server was renamed to: DHCP01. The server was restarted after the computer name was changed.

Windows Server DHCP Infrastructure project screenshot

Computer Name/Domain Changes — renaming the server to DHCP01 (still in WORKGROUP, prior to joining the domain).

6.4 Configure a Static IP Address on DHCP01

A DHCP server must use a static IP address. A dynamic address should not be used because the DHCP server's own IP address must remain consistent for:

The Ethernet adapter properties were opened, followed by Internet Protocol Version 4 (TCP/IPv4). A static configuration was assigned — the actual values used in the lab:

IP Address: 192.168.10.20 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.10.1 Preferred DNS: 192.168.10.10

The preferred DNS server was configured as the IP address of DC01. This was necessary because DC01 hosted the DNS zone for yasserteach.local.

Windows Server DHCP Infrastructure project screenshot

Internet Protocol Version 4 (TCP/IPv4) Properties — the actual static configuration applied on DHCP01.

Windows Server DHCP Infrastructure project screenshot

Verifying the static configuration and DNS server via PowerShell, and a successful ping test to DC01 (192.168.10.10).

6.5 Test Communication with the Domain Controller

Before joining the DHCP server to the domain, network connectivity was tested. The following command tested connectivity using the domain controller's IP address:

ping 192.168.10.10

Name resolution was then tested using the server name:

ping DC01

The domain name was also tested:

ping yasserteach.local

Additional DNS verification was performed with:

nslookup DC01.yasserteach.local

Windows Server DHCP Infrastructure project screenshot

Command Prompt — ping 192.168.10.10 from DHCP01, confirming successful Layer 3 connectivity to DC01.

Successful IP communication confirmed Layer 3 connectivity. Successful hostname resolution confirmed that the DHCP server was using the correct internal DNS server.

6.6 Join DHCP01 to the Active Directory Domain

After confirming connectivity and DNS resolution, DHCP01 was joined to the Active Directory domain: yasserteach.local. Domain administrator credentials were provided when prompted. After the successful domain join, the server displayed a confirmation message welcoming it to the domain. DHCP01 was restarted to complete the domain membership process.

Windows Server DHCP Infrastructure project screenshot

Joining DHCP01 to the yasserteach.local domain via Computer Name/Domain Changes.

After the restart, the server was accessed using a domain account:

YASSERTEACH\yasser

Windows Server DHCP Infrastructure project screenshot

Signing in to DHCP01 using a YASSERTEACH domain account.

Domain membership was verified using:

systeminfo | findstr /B /C:"Domain"

Expected result: Domain: yasserteach.local

Windows Server DHCP Infrastructure project screenshot

systeminfo confirming domain membership: Domain: yasserteach.local.

6.7 Install the DHCP Server Role

The DHCP Server role was installed from Server Manager. The following process was used:

  1. Opened Server Manager

  2. Selected Manage

  3. Selected Add Roles and Features

  4. Selected Role-based or feature-based installation

  5. Selected DHCP01

  6. Selected DHCP Server

  7. Added the required management tools

  8. Continued through the wizard

  9. Selected Install

  10. Waited for the installation to complete

Windows Server DHCP Infrastructure project screenshot

Add Roles and Features Wizard — installing the DHCP Server role with management tools.

The DHCP role could also be installed using PowerShell:

Install-WindowsFeature DHCP -IncludeManagementTools

The installation status could be verified using:

Get-WindowsFeature DHCP

6.8 Complete the DHCP Post-Installation Configuration

After installing the DHCP role, Server Manager displayed a post-deployment notification. The notification was opened and the DHCP post-installation configuration wizard was completed. The wizard performed two important tasks:

The following local security groups were created: DHCP Administrators, DHCP Users. The server was authorized using domain administrative credentials.

Windows Server DHCP Infrastructure project screenshot

DHCP post-installation configuration wizard confirming security groups created and the server authorized.

7. DHCP Authorization in Active Directory

7.1 Why DHCP Authorization Is Required

In an Active Directory environment, a Windows DHCP server must be authorized before it can distribute IP addresses. DHCP authorization protects the network from unauthorized or rogue DHCP servers. A rogue DHCP server could distribute incorrect settings such as:

Authorization ensures that only approved DHCP servers can respond to client requests.

7.2 Verify DHCP Authorization

The DHCP management console was opened by running:

dhcpmgmt.msc

The server status was reviewed. An authorized server normally displays a green status indicator. Authorization could also be verified using PowerShell:

Get-DhcpServerInDC

Expected information included:

If manual authorization was required, the following command could be used (using the actual DHCP01 address):

Add-DhcpServerInDC ` -DnsName "DHCP01.yasserteach.local" ` -IPAddress 192.168.10.20

8. Create an IPv4 DHCP Scope

An IPv4 scope was created to define the pool of addresses that could be assigned to clients. The DHCP management console was opened:

Server Manager → Tools → DHCP

The following path was expanded: DHCP → DHCP01 → IPv4. The IPv4 node was right-clicked and New Scope was selected.

8.1 Scope Name and Description

A descriptive scope name was entered — Corporate Client Network — with the description: "Provides dynamic IPv4 configuration to internal domain client devices." A professional scope name makes it easier for administrators to identify the network purpose.

8.2 Configure the IP Address Range

The dynamic IP address range configured in the lab:

Start IP Address: 192.168.10.100 End IP Address: 192.168.10.200 Prefix Length: /24 Subnet Mask: 255.255.255.0

Windows Server DHCP Infrastructure project screenshot

New Scope Wizard — configuring the IPv4 address range (192.168.10.100 – 192.168.10.200).

8.3 Configure Exclusions

An exclusion range was configured to prevent DHCP from assigning specific addresses. The actual exclusion range configured in the lab:

192.168.10.100 – 192.168.10.110

Excluded addresses can be used for:

Although the excluded addresses are inside the configured scope range, they are removed from the allocatable DHCP pool so they can be kept available for infrastructure devices and other manually managed addresses.

Windows Server DHCP Infrastructure project screenshot

New Scope Wizard — Add Exclusions and Delay (192.168.10.100 – 192.168.10.110).

8.4 Configure Lease Duration

The DHCP lease duration configured in the lab was 8 days, confirmed later via Get-DhcpServerv4Scope. The lease duration determines how long a client can use an assigned address before renewing it. A longer lease is suitable for stable corporate networks where devices remain connected for long periods. A shorter lease may be more appropriate for:

For this lab, the default lease duration was sufficient.

9. Configure DHCP Scope Options

DHCP scope options provide clients with additional network information. The following options were configured.

9.1 Option 003: Router

The default gateway address configured:

192.168.10.1

This option tells clients where to send traffic destined for other networks. In a completely isolated host-only lab without routing, the gateway may be omitted or configured according to the virtual network design.

9.2 Option 006: DNS Servers

The internal DNS server configured:

192.168.10.10

This was the IP address of DC01. Using the domain controller as the DNS server allowed clients to resolve:

Using a public DNS server directly on a domain client could prevent Active Directory domain discovery and internal name resolution.

Windows Server DHCP Infrastructure project screenshot

New Scope Wizard — Domain Name and DNS Servers, configured with 192.168.10.10.

9.3 Option 015: DNS Domain Name

The internal DNS domain was configured as: yasserteach.local. This option provides clients with the domain suffix used for internal DNS queries.

9.4 Scope Option Summary

Option Name Configured Value
003 Router 192.168.10.1
006 DNS Servers 192.168.10.10 (DC01)
015 DNS Domain Name yasserteach.local

Windows Server DHCP Infrastructure project screenshot

DHCP console — Scope Options showing the configured Router, DNS Servers, and DNS Domain Name values.

10. Activate the DHCP Scope

After reviewing the scope settings, the scope was activated. An inactive scope cannot distribute IP addresses. The activated scope appeared under: IPv4 → Corporate Client Network. The scope contained the following management sections:

The scope status was verified as active.

Windows Server DHCP Infrastructure project screenshot

DHCP console showing the Corporate Client Network scope with an Active status.

11. Verify the DHCP Server Service

The DHCP Server service was checked using the Services console and PowerShell:

Get-Service DHCPServer

Expected status: Running / Automatic. If required, the service could be started using:

Start-Service DHCPServer

The startup type could be configured using:

Set-Service DHCPServer -StartupType Automatic

12. Prepare the Windows 11 DHCP Client

A Windows 11 virtual machine was used to test the DHCP deployment. The Windows 11 network adapter was connected to the same VMware host-only network as DC01 and DHCP01. The IPv4 adapter configuration was changed to "Obtain an IP address automatically" and "Obtain DNS server address automatically", allowing the computer to request its network configuration from the DHCP server.

13. Request a DHCP Lease

The existing network configuration was released:

ipconfig /release

Windows Server DHCP Infrastructure project screenshot

ipconfig /release on W11-CLIENT01.

A new DHCP lease was requested:

ipconfig /renew

Windows Server DHCP Infrastructure project screenshot

ipconfig /renew — the client received IPv4 address 192.168.10.111.

The complete client configuration was displayed using:

ipconfig /all

The output was reviewed to confirm the following:

Actual output obtained on W11-CLIENT01:

DHCP Enabled: Yes IPv4 Address: 192.168.10.111 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.10.1 DHCP Server: 192.168.10.20 DNS Servers: 192.168.10.10 Connection-specific DNS Suffix: yasserteach.local

Windows Server DHCP Infrastructure project screenshot

ipconfig /all on W11-CLIENT01 — full lease details (IP 192.168.10.111, DHCP Server 192.168.10.20).

14. Understand the DHCP Lease Process

W11-CLIENT01 Discover Offer Request Acknowledge Lease Assigned

When the Windows 11 client requested an IP address, the DHCP process followed the DORA sequence.

14.1 DHCP Discover

The client broadcast a DHCP Discover message to locate available DHCP servers.

14.2 DHCP Offer

DHCP01 responded with an available IP address and configuration information.

14.3 DHCP Request

The client requested the offered IP address.

14.4 DHCP Acknowledgment

DHCP01 approved the request and created the lease.

The process is summarized as: Discover → Offer → Request → Acknowledge. This process is commonly known as DHCP DORA.

15. Verify the DHCP Lease on the Server

On DHCP01, the following location was opened: DHCP Console → IPv4 → Corporate Client Network → Address Leases. The Windows 11 client appeared in the lease list. The lease record contained information such as:

This confirmed that the DHCP server had successfully issued and recorded the client lease.

Windows Server DHCP Infrastructure project screenshot

DHCP Address Leases console — W11-CLIENT01 listed with IP 192.168.10.111.

16. Connectivity Testing

After the client received its DHCP configuration, several connectivity tests were performed.

16.1 Test the DHCP Server

ping DHCP01

16.2 Test the Domain Controller by IP Address

ping 192.168.10.10

16.3 Test the Domain Controller by Hostname

ping DC01

16.4 Test the Domain Name

ping yasserteach.local

16.5 Test DNS Resolution

nslookup DC01.yasserteach.local

16.6 Display the DNS Configuration

ipconfig /all

These tests verified: client-to-server communication, TCP/IP configuration, internal DNS resolution, domain connectivity, and correct DHCP option distribution.

17. Create a DHCP Reservation

A DHCP reservation was created to provide a specific client with the same IP address whenever it requested a lease. Reservations are useful for devices that require predictable addresses but should remain centrally managed through DHCP. Examples include:

17.1 Obtain the Client MAC Address

On the Windows 11 client, the following command was used:

ipconfig /all

The physical address of the Ethernet adapter was recorded — the actual MAC address of W11-CLIENT01:

00-0C-29-21-DD-8A

The MAC address could also be displayed using:

getmac

17.2 Create the Reservation

On DHCP01, the following location was opened: IPv4 → Corporate Client Network → Reservations. A new reservation was created with:

Reservation Name: W11-CLIENT01 IP Address: 192.168.10.111 MAC Address: 00-0C-29-21-DD-8A Description: Reserved address for Windows 11 test client Supported Type: Both

The reserved IP address (192.168.10.111) was the same address the client had already been leasing, taken from the scope range.

17.3 Test the Reservation

On the Windows 11 client, the existing address was released and renewed:

ipconfig /release ipconfig /renew

The configuration was checked again with ipconfig /all. The client received the reserved IP address (192.168.10.111). The DHCP console was also reviewed to verify that the reservation was active, and the reservation configuration was included in the final PowerShell verification sequence.

18. DHCP Management Verification

The following DHCP components were reviewed after implementation.

18.1 Address Pool

Confirmed the configured dynamic address range and exclusions.

Windows Server DHCP Infrastructure project screenshot

DHCP console — Address Pool section under the Corporate Client Network scope, used to review the configured allocation range and exclusions.

18.2 Address Leases

Confirmed the addresses currently assigned to clients.

18.3 Reservations

Confirmed the permanently mapped client address.

18.4 Scope Options

Confirmed the gateway, DNS server, and DNS domain settings.

18.5 Server Authorization

Confirmed that DHCP01 was authorized in Active Directory.

18.6 DHCP Service

Confirmed that the DHCP Server service was running automatically.

19. PowerShell Verification Commands

The following PowerShell commands can be used to verify and document the deployment.

19.1 Display Authorized DHCP Servers

Get-DhcpServerInDC

19.2 Display IPv4 Scopes

Get-DhcpServerv4Scope

Windows Server DHCP Infrastructure project screenshot

PowerShell output — Get-DhcpServerv4Scope (192.168.10.0, Active, 192.168.10.100–200, 8 day lease) and Get-DhcpServerDatabase.

19.3 Display the DHCP Address Pool

Get-DhcpServerv4ExclusionRange ` -ComputerName DHCP01 ` -ScopeId 192.168.10.0

19.4 Display Scope Options

Get-DhcpServerv4OptionValue ` -ComputerName DHCP01 ` -ScopeId 192.168.10.0

19.5 Display Active Leases

Get-DhcpServerv4Lease ` -ComputerName DHCP01 ` -ScopeId 192.168.10.0

19.6 Export the DHCP Configuration

Export-DhcpServer -ComputerName DHCP01 -File "C:\DHCP-EXPORT.xml" -Leases -Force

Windows Server DHCP Infrastructure project screenshot

PowerShell — exporting the DHCP configuration and lease data to C:\DHCP-EXPORT.xml for backup and documentation.

19.7 Display Reservations

Get-DhcpServerv4Reservation ` -ComputerName DHCP01 ` -ScopeId 192.168.10.0

19.8 Check the DHCP Service

Get-Service DHCPServer

19.9 Display DHCP Server Statistics

Get-DhcpServerv4Statistics ` -ComputerName DHCP01

20. Troubleshooting Performed

During the project, network communication and DHCP functionality were affected by the virtual network configuration. The main troubleshooting areas included:

20.1 Servers Could Not Communicate Correctly

Symptom: The servers were installed correctly, but communication between the virtual machines was inconsistent. IP-based connectivity and name-based connectivity did not always produce the same results.

Root Cause: The virtual machines were not initially operating through the correct common VMware virtual network. DHCP requires the client broadcast traffic to reach the DHCP server; if the virtual machines are connected to different VMware network segments, DHCP requests cannot reach DHCP01.

Resolution: The network adapters for the virtual machines were reviewed and connected to the same VMware host-only network. The affected virtual machines were powered on again after the virtual network configuration was corrected, and connectivity was retested using ping <server-IP>, ping DC01, and ping DHCP01. Communication was successfully restored.

20.2 IP Connectivity Worked but Name Resolution Failed

Symptom: The server could communicate with the domain controller using its IP address, but hostname or domain resolution failed (ping by IP address succeeded; ping by hostname failed).

Root Cause: The affected server or client was not using the domain controller as its preferred DNS server. Active Directory clients must query the internal DNS server hosting the Active Directory DNS zone.

Resolution: The preferred DNS server was changed to the IP address of DC01 (192.168.10.10). The DNS client cache was cleared (ipconfig /flushdns) and DNS registration was refreshed (ipconfig /registerdns). Name resolution was tested again with nslookup DC01.yasserteach.local and ping DC01 — the hostname resolved successfully.

20.3 DHCP Server Was Installed but Did Not Distribute Addresses

Verification Performed: DHCP Server role installation, DHCP service status, DHCP server authorization, scope activation, available addresses in the pool, client and server VMware network, client automatic IPv4 configuration, and DHCP scope options were all checked.

Resolution: The DHCP server was authorized in Active Directory, the IPv4 scope was activated, and all virtual machines were placed on the same VMware host-only network. The Windows 11 client then successfully received an address using ipconfig /release and ipconfig /renew.

20.4 Windows Firewall Was Reviewed

Windows Firewall rules were checked during troubleshooting to confirm that required DHCP and network traffic was not being blocked. However, firewall rules were not treated as the only possible cause — the virtual network configuration, DNS settings, DHCP authorization, and active scope configuration were also validated. This troubleshooting approach helped identify the underlying network configuration problem instead of repeatedly applying the same firewall checks.

21. Security Considerations

Several security practices were applied or considered during the deployment.

21.1 Active Directory Authorization

Only an authorized DHCP server was permitted to distribute addresses.

21.2 Dedicated Server Role

The DHCP role was deployed on a dedicated member server rather than directly on the domain controller. This improves role separation, troubleshooting, security administration, service management, and future scalability.

21.3 Controlled Address Pool

Only a defined range of addresses (192.168.10.100–200) was made available for dynamic assignment.

21.4 Exclusion Ranges

Infrastructure addresses (192.168.10.100–110) were protected from accidental DHCP allocation.

21.5 Centralized DNS Distribution

Clients were configured to use the internal DNS server (DC01, 192.168.10.10) rather than arbitrary external DNS services.

21.6 Least Privilege Administration

DHCP management can be delegated through the DHCP Administrators group. Administrators do not necessarily need full Domain Admin privileges for routine DHCP management.

21.7 Monitoring Leases

Active leases and reservations can be reviewed to identify unexpected or unauthorized devices.

21.8 Audit Logging

DHCP audit logging can be used to record lease operations and server activity. The default DHCP log location is C:\Windows\System32\dhcp.

Windows Server DHCP Infrastructure project screenshot

Get-DhcpServerAuditLog — audit log configuration on DHCP01.

Windows Server DHCP Infrastructure project screenshot

Event Viewer — Microsoft-Windows-DHCP-Server Operational log recording server policy events.

22. DHCP Best Practices Applied

The project followed several Windows Server DHCP best practices:

23. Validation Checklist

Validation Item Result
DHCP01 has a static IP address Successful
DHCP01 uses DC01 as DNS Successful
DHCP01 joined yasserteach.local Successful
DHCP Server role installed Successful
DHCP management tools installed Successful
DHCP server authorized in Active Directory Successful
IPv4 scope created Successful
Address pool configured Successful
Exclusion range configured Successful
Lease duration configured Successful
DHCP scope options configured Successful
Scope activated Successful
DHCP Server service running Successful
Windows client configured for automatic addressing Successful
Windows client received a valid lease Successful
Correct subnet mask received Successful
Correct DNS server received Successful
Correct DNS suffix received Successful
Client appeared under Address Leases Successful
Client communicated with DC01 Successful
Client resolved internal DNS names Successful
DHCP reservation created and tested Successful

24. Final Results

The Windows Server DHCP deployment was completed successfully. The final solution provided:

The Windows 11 client successfully obtained its network configuration from DHCP01. The client was able to:

25. Skills Demonstrated

26. Technologies Used

27. Project Outcome

The completed lab delivered a centralized, Active Directory-authorized DHCP service that consistently assigned IPv4 configuration to Windows clients from a controlled scope. Exclusions, scope options, reservations, lease monitoring, PowerShell verification, audit logging, and client-side validation were used to confirm the deployment end to end.

The final implementation demonstrates practical administration of a core Windows infrastructure service, including integration with Active Directory and DNS, operational verification, troubleshooting, security controls, and recoverable configuration export.

28. Short Project Summary

28.1 Enterprise DHCP Server Deployment

Deployed a dedicated Windows Server 2022 DHCP server in an Active Directory domain environment. Configured a centralized IPv4 scope, exclusions, lease duration, gateway, internal DNS server, and DNS domain options. Authorized the DHCP server in Active Directory and validated automatic address allocation using a Windows 11 client.

Created and tested a DHCP reservation, monitored active leases, and resolved VMware virtual networking and DNS name-resolution issues. The final solution provided centralized, consistent, and scalable network configuration for domain client devices.

29. Resume Project Description

29.1 Enterprise DHCP Server Deployment — Windows Server 2022