Add an off-site secondary domain controller
A domain resting on a single controller stops when that controller does: a second directory, elsewhere, keeps authenticating.
Starting at €13/mo
Introduction
An Active Directory domain with a single controller goes down with it: no logons, no internal DNS resolution, no group policy applied. Adding a secondary domain controller means promoting a second server into the domain that already exists, then letting replication copy the directory across. On a Windows VPS, that second controller lives somewhere other than your own comms cupboard, for €13/month incl. VAT on the configuration we recommend, delivered in 10 minutes.
This is not the same subject as standing up a directory from scratch: here the domain already exists and what matters is redundancy. You get a Windows machine with full administrator access, a dedicated IPv4 address and a fallback VNC console — worth having on the day a controller promotion reboots the server and RDP does not come back straight away. For this role pick Windows Server 2025 or Windows Server 2022: Windows 11 is a client system and does not carry AD DS.
Three things we would rather put in writing. The network link between the VPS and the office network is what makes replication possible, and building it is on you: By-Hoster provides no managed tunnel service. The Microsoft licence stays on your side — we install the system, we do not sell it. And a snapshot is not a domain controller backup: it belongs just before a change, not three weeks after it.
What the machine allows, and what it will not do for you
Promoting an additional controller
The domain already exists: you add the <strong>AD DS</strong> role from Server Manager or with <code>Install-WindowsFeature AD-Domain-Services</code>, then promote the machine <strong>into the existing domain</strong> with <code>Install-ADDSDomainController</code> rather than creating a new forest. Replication then copies accounts, groups and policies over. This works because the server's administrator account is yours, on a standard system.
The DNS role follows the controller
An Active Directory domain does not run without <strong>DNS</strong>: the <strong>SRV</strong> records are what let workstations find a controller. The promotion wizard installs the DNS Server role, and directory-integrated zones replicate along with it. The VPS <strong>dedicated IPv4</strong> then gives you a stable address to declare as a secondary DNS server on member machines.
The network link stays on your side
Replication assumes the VPS and the office network can reach each other. Building that link — site-to-site tunnel, VPN, routing — is down to you or your provider: <strong>By-Hoster does not offer a managed tunnel service</strong>. We supply the machine, its dedicated IPv4 and full administrator access; the network topology and which flows you open are decided and configured on your side.
Snapshots belong before, not after
Domain controllers track a replication counter, the <strong>USNs</strong>. Restoring a controller to an earlier state can desynchronise the domain: that is <strong>USN rollback</strong>. A snapshot taken right before an operation and rolled back immediately if the attempt fails stays safe. As a backup of a production controller, no: use the restore procedures Microsoft provides for that.
When an off-site second controller earns its place
The main site is down, accounts still answer
Power cut, hardware failure, a router that dies on a Monday morning: the workstations that can still reach the VPS keep opening their sessions and resolving domain names. That is the direct benefit of a replica hosted elsewhere.
Remote workstations and home working
When part of the estate lives outside the walls, a controller reachable from beyond the office network stops everything depending on the link to headquarters. What remains is deciding how that traffic travels: that is your network topology, not ours.
Replacing the ageing office server
The classic method: promote the new controller, let replication finish, transfer the FSMO roles, then demote the old one. The domain does not start from scratch, and the old machine can be shut down cleanly once it holds nothing.
Getting the directory out of the cupboard
Plenty of small companies keep their only controller in the same room as everything else: same UPS, same power feed, same risk. The VPS lives in our DC-FR_NA(01) datacenter in Nouvelle-Aquitaine, on NVMe storage with Anti-DDoS protection.
Structuring a domain across two places
As soon as a directory spans two locations, the Active Directory Sites and Services console is where you declare subnets and site links. The usual Microsoft tooling behaves exactly as on a physical server, because the machine is yours.
Prototyping replication before committing
Build the link, promote, check replication, measure what your line actually delivers: the server arrives in 10 minutes, reinstalls from the client area, has no commitment and comes with a 48-hour money-back guarantee.
Frequently asked questions
The Windows range starts at €8/month incl. VAT with Windows - Core (4 vCores, 8 GB of RAM, 50 GB SSD, 500 Mbps), which is enough for a domain controller on its own. As soon as AD DS shares the machine with other roles we recommend Windows - Plus at €13/month (8 vCores, 16 GB, 200 GB), the most popular configuration. Above that: Max at €26 (32 GB) and Titan at €49.99 (64 GB, 1000 Mbps). Annual billing takes 10% off. The Microsoft licence is not included.
In order: first establish the network link between the VPS and the network where the domain lives, point the server at the DNS of the existing controller, install the AD DS role, then run Install-ADDSDomainController with domain administrator credentials. The server reboots and replication starts. Then declare it as a secondary DNS server on member machines. The VNC console stays available if RDP does not come back after the restart.
You need a network link between the two in one form or another: Active Directory replication does not make do with a single port, and exposing a domain controller straight to the Internet is not a reasonable idea. That link is your responsibility: By-Hoster does not provide a managed tunnel service. You do have full administrator access, so you can build whatever your architecture calls for, including on a Windows machine dedicated to that role.
Workstations that can still reach the second controller keep authenticating and resolving domain names — that is the whole point of the replica. An important nuance: the FSMO roles held by the unavailable controller do not move on their own. Some directory operations degrade until they do, and seizing a role is a manual step not to be taken lightly. Prepare and test that scenario before you need it.
No. A replica reproduces the domain faithfully, deletions included: an object removed by mistake disappears on both sides. Redundancy protects against a failure, not against a human error. On our side, only snapshots are documented — there is no automatic backup and no off-site retention — and on a domain controller they are used before a change, because of USN rollback. Keep your own directory backup strategy.
Yes, and it is on you. By-Hoster installs the operating system but neither supplies nor resells Microsoft licences: a second domain controller is a second Windows Server instance and must be covered as such. A useful reminder while we are here: Windows Server allows 2 concurrent administrative RDP sessions; beyond that, application RDP access for several users requires Microsoft RDS CAL licences, which we do not supply either.
Our published rule of thumb: 4 GB minimum for light use, and 8 GB as soon as you add business software, SQL Server Express or several concurrent users. All our Windows plans already start at 8 GB, which covers a domain controller on its own: it is a service answering LDAP and DNS queries, not a compute engine. As soon as AD DS shares the machine with other roles — files, business application, database — move to 16 GB with Windows - Plus.
No. Windows 11 is a client system, not designed to host a multi-user service, and it does not carry the AD DS role: a Windows 11 workstation joins a domain, it does not host one. For this role choose Windows Server 2025 or Windows Server 2022, both offered at checkout at no extra cost. If a Windows 11 has already been ordered, reinstalling from the client area lets you switch system.
Windows Server 2025 is the latest LTSC release: mainstream support until 13 November 2029, security updates until 14 November 2034. Windows Server 2022 still makes sense if a vendor has not validated 2025 yet: mainstream until 13 October 2026, security until 14 October 2031. Both are offered at no extra cost. Windows Server 2019 is no longer installable here. Check on your side that your domain functional level accepts the version you target.
On the machine we host, in our single DC-FR_NA(01) datacenter in Nouvelle-Aquitaine, France, operated directly by the association's technical team, virtualised with KVM on Proxmox. Replicated accounts, groups and policies stay under French jurisdiction, within the GDPR framework, with no transfer outside the European Union. Your other controllers stay wherever they are: we can only speak for the server we operate. By-Hoster is a French non-profit association founded in 2023 (RNA W162005815).