Real-world project: AD, GPO, RDS setup – looking for best practices
11:50 12 Dec 2025

I’m a student working on a real infrastructure project in a company. The setup is based on:

– VMware ESXi 6.7

– Windows Server 2016 (AD/GPO)

– Windows Server (RDS)

Goal:

Centralize all user work on one RDS VM (VM2): RDP sessions, user data, applications installed once, GPOs, permissions, etc.

The first VM (VM1) hosts AD + GPO.

What I already did:

– Created AD users/groups

– Joined VM2 to the domain

– Enabled RDS (grace period)

– Basic GPOs (restrictions + auto user folders)

What I need advice on:

– Best practices / methodology for this kind of project

– Proper resource allocation for VM1 and VM2 (RAM/CPU/storage)

– Backup strategy (external disk? another VM? cloud?)

– Important GPOs to apply

– Clean way to auto-launch RDP at logon

– What to do if vCenter credentials are lost (detach ESXi?)

Any guidance, advice or experience would be greatly appreciated 🙏

Thanks in advance!

windows network-programming server active-directory windows-server