SQL Server should NOT be installed on a domain controller. It is important to segregate domain and database services for security purposes. ref. http://www.cisecurity.org/tools2/sqlserver/CIS_SQL2005_Benchmark_v1.0.pdf, pg 11. Checking whether the 'NTDS' key exists in the registry. This check will fail if the key exists.