When I was working with Linux based kiosks and PoS systems I had a good share of issues with the Microsoft MVP signature use of .local on their forests. Back then their training material recommended .local for Active Directory services.
When I was working with Linux based kiosks and PoS systems I had a good share of issues with the Microsoft MVP signature use of .local on their forests. Back then their training material recommended .local for Active Directory services.
Pretty sure MS's official documentation always strongly suggested using a real domain you own for AD.
Specifically, either a registered name or a subdomain of a registered name reserved for this purpose, because the A records for the apex should or must — I don't remember which, but it's definitely the default configuration — point to the domain controllers, and you probably don't want to host your public web site on the same addresses as your DCs (or for that matter, your internal and public records necessarily hosted on the same server).
Historically (20+ years ago), some Microsoft documentation suggested .local as an example of an unregistered domain that could be used for this purpose, which was problematic when .local was subsequently reserved for multicast DNS.