20 Active Directory Domain Name Local New

On an active directory domain controller each default local account is referred to as a security principal.
Active directory domain name local. Even today many active microsoft kb articles have directions to use a non public tld like a local name today. When active directory first became a thing 15 years ago there was not great direction for how to properly name your fully qualified domain name fqdn so many people just chose domain local for their active directory. The domain name local is a special use domain name reserved by the internet engineering task force ietf so that it may not be installed as a top level domain in the domain name system dns of the internet as such it is similar to the other special domain names such as localhost.
Ad domain vs dns name. From those observations you can decide which is the best solution for your future environment. Answer is yes you can but you need to aware of the issues it can occur as well.
Generic tlds like local lan corp etc are now being sold by icann so the domain you re using internally today company local could potentially become another company s property tomorrow. A security principal is a directory object that is used to secure and manage active directory services that provide access to domain controller resources. If you re still not convinced here are some more reasons why you shouldn t use local in your active directory domain name.
Use any invalid tlds root domain names or tree domain names. Few of the blog readers asked me on few occasions if they can change the ad domain name to the different domain name. For a full list see the table of reserved words section in microsoft kb article 909264 naming conventions in active directory for computers domains sites and ous.
Throughout this article we are going to discuss several points where the active directory name will impact your production environment. Ad domain names are mainly used within ad operations mostly ldap queries for ad functionality while dns is rather a network level solution for name resolution on ip level to resolve the machines or application names to ip addresses. Use any netbios domain names that are reserved by the operating system such as system and internet.
For example you may want to use domain local domain int or domain corp.