Servers and Cloud

Windows Server Setup, Configuration and Ongoing Management

Setting up Windows Server is more than installing it and adding roles. We plan which role runs where, harden the server, and put patching and backup on a proper schedule.

CybUP TeamLast updated: 5 min read

In short

Windows Server setup covers installing the operating system on a physical or virtual server, configuring roles such as Active Directory, DNS, DHCP, file services, IIS or Hyper-V, and keeping the server secure, patched and backed up. It is for companies that run their own servers. CybUp handles version choice, installation, hardening, update management, monitoring and backup as one piece of work.

What does a Windows Server setup involve?

A Windows Server setup consists of choosing the version and installation option, installing the operating system, configuring roles, hardening, and ongoing management: updates, monitoring and backup. Most problems come from the last two steps, not the first two. We regularly come across servers that have not been patched in the two years since installation, with backups that have never been test-restored.

Say a 40-person accounting firm has bought a new server. It will host a domain controller (DC), file shares, the accounting package’s database and the print queues. Rather than piling all of that onto one operating system, splitting it into separate virtual machines on Hyper-V makes both security and maintenance downtime easier to manage. Our setup plan starts with decisions like this one.

Which Windows Server version should you install?

For a new installation today, Windows Server 2025 is the sensible choice. According to Microsoft’s release information page, Windows Server 2025 is the current Long-Term Servicing Channel (LTSC) release; mainstream support ends on 13 November 2029 and extended support on 14 November 2034. Windows Server 2022 leaves mainstream support on 13 October 2026, with extended support running until 14 October 2031.

In practice, the application vendor’s support decides the version: some accounting and ERP packages are slow to support a new release. Windows Server 2025 also lists a CPU with SSE4.2 and POPCNT support among its hardware requirements, so if an older server is being considered, we check this first. For roles that can be managed remotely, we prefer the Server Core installation option, which has no desktop interface: fewer components, fewer updates and a smaller attack surface.

“Windows Server 2025 is the current LTSC release.”

— Microsoft Learn — Windows Server release information

How do you configure Windows Server roles?

We separate roles by workload and document each one together with its settings. Active Directory Domain Services manages user and computer accounts centrally; running at least two DCs means sign-ins keep working on the day one of them is down for maintenance. We cover AD design in detail on the Active Directory and Entra ID page.

DNS and DHCP usually sit alongside the DC, and DHCP failover and scope options need to match the network design. On file servers we assign NTFS and share permissions through groups, and set up Volume Shadow Copy along with FSRM quotas and file screening. On print servers we deploy drivers centrally; on IIS we enable only the modules that are needed and configure TLS. If virtualisation is required, we plan the Hyper-V role as part of a Hyper-V setup.

  • AD DS, DNS and DHCP (with failover)
  • File server: permissions, shadow copies, FSRM quotas
  • Print server and driver deployment
  • IIS: required modules, TLS and application pools
  • WSUS and Hyper-V roles

How do you harden Windows Server?

Hardening means switching off everything the server does not need and tying the rest to a known security baseline. On Windows Server 2025, OSConfig can apply a role-based security baseline; it detects configuration drift and corrects it, and it also covers Windows LAPS for local administrator passwords.

On top of that, we confirm SMB1 is disabled, keep admin accounts separate from everyday user accounts, and allow Remote Desktop only from the management network. Microsoft’s list of removed and deprecated features is useful here too: on Windows Server 2025, TLS 1.0 and 1.1 are disabled by default and NTLMv1 has been removed. If an older application depends on either, you want to find out in a test environment before installation, not after.

How should Windows Server updates be managed?

Updates should be handled monthly and to a plan. Microsoft releases monthly security updates for Windows Server in the second week of each month (release information). We apply them to a test group first and to production servers a few days later, with reboots tied to a maintenance window.

WSUS can still be used for central distribution, but Microsoft’s WSUS page states that the role is deprecated: it gets no new features, although it remains supported. On new deployments, we talk through the alternatives for an environment of your size before installing WSUS.

“WSUS is deprecated and is no longer adding new features. However, it continues to be supported for production deployments, and receives security and quality updates as per the product lifecycle.”

— Microsoft Learn — WSUS overview

How do you set up monitoring and backup after installation?

A server should be connected to monitoring and backup on the day it goes live. We set up Zabbix monitoring for disk usage, service status, critical event log errors, certificate expiry dates and hardware health, and agree who receives alerts and how.

For backup, we define separate policies for the DC’s system state, the file server and the databases, and make sure at least one copy is immutable or kept offline. We do this with a Veeam Backup setup and hand over only after a test restore has actually worked.

What you receive

  • Setup plan covering version, installation option and role layout
  • Installed and configured Windows Server machines
  • Security baseline, LAPS and separate admin accounts
  • Monthly update schedule split into test and production groups
  • Monitoring and backup configuration with a tested restore
  • Documentation of role settings, the IP plan and where passwords are stored

How we work

  1. 1

    Discovery

    We review the applications to be hosted, the number of users, your existing servers and licensing.

  2. 2

    Planning

    We decide the version, installation option, role layout and virtual machine structure.

  3. 3

    Installation and roles

    We install the operating system, then configure the roles and connect them together.

  4. 4

    Hardening

    We apply the security baseline and switch off unneeded services and legacy protocols.

  5. 5

    Ongoing management

    We set up patching, monitoring and backup, run a restore test and hand over.

Frequently asked questions

Should we install Windows Server 2022 or 2025?

If your applications support it, we recommend 2025. Windows Server 2022 leaves mainstream support on 13 October 2026, while extended support for 2025 runs until 14 November 2034.

Can we use our existing Windows Server licences?

That depends on the version and type of licence you hold. We review your existing licences and set out in writing what the new version requires before installation.

Will there be downtime during the setup?

Installing a new server does not affect your current environment. If a migration is involved, we schedule the final step out of hours and aim to keep downtime to a matter of minutes.

Can you set up Windows Server remotely?

Yes. We handle the software side remotely anywhere in Türkiye, and in Istanbul we can also work on site when needed.

How much does a Windows Server setup cost?

We give you a written quote after reviewing the number of servers, the roles and your current environment; the review is free.

Can we still use WSUS?

Yes, WSUS is still supported, but Microsoft no longer adds features to it. Depending on the size of your environment, we recommend either WSUS or an alternative way of managing updates.

Do you offer Windows Server management after installation?

Yes. We provide ongoing management covering monthly patching, follow-up on monitoring alerts and backup checks. We agree the scope with you server by server.

What do you do about KVKK compliance?

On shares holding personal data covered by KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698), we restrict access through groups, enable access auditing and encrypt backups. We cover the details alongside a KVKK technical measures review.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.