
Explanation:

Reference:
The Administering Windows Server Hybrid Core Infrastructure guidance for deploying Azure Active Directory Domain Services (Azure AD DS) in a new subscription is explicit about the required sequence.
First, you prepare networking: "Before you enable Azure AD DS, create or select an Azure virtual network and subnet that will host the managed domain." Next, you provi sion the managed domain: "Enable Azure AD DS into the chosen virtual network/subnet; the service deploys managed domain controllers and exposes domain IP addresses." Finally, you update DNS for the VNet so VMs can locate the domain: "After the managed domain i s provisioned, configure the virtual network DNS servers to the IP addresses of the Azure AD DS domain controllers so that virtual machines can resolve the domain and join it." The course also clarifies what you do not do with Azure AD DS: "Azure AD DS is a managed domain; you do not install the AD DS role or run the AD DS installation wizard on your own VMs." And: "Azure AD Connect is only required when synchronizing identities from an on-premises AD; it isn't required for a cloud- only deployment of Azure AD DS." Therefore, the correct sequence to ensure VMs can be deployed and joined to Azure AD DS is:
Create an Azure virtual network,
Create an Azure AD DS instance (into that VNet/subnet),
Modify the VNet DNS settings to point to the managed domain IPs.