Well once, about a decade ago I did break the AD with some script I didn't even really knew what I was doing with security descriptors back then so no one could enter the root domain anymore.... deleted all the aces ;\)
Ever since I did everything on my own server (separate setup) first and lateron in vmware when that came into the picture \:\)