Separate domain from Forest

Posted on 2007-11-28
Last Modified: 2010-07-27
Separate domain from forest

In our current AD forest we have an empty root domain (UK.COM and two child domains (A.UK.COM and B.UK.COM

We need to separate one of the child domains (B.UK.COM) as it is no longer part of the business.

1.      What will happen if we just sever the link from UK.COM to B.UK.COM?
2.      How long will B.UK.COM function without access to UK.COM.
3.      Is it possible to separate B.UK.COM without migrating everything to a new domain
4.      Anything else that would be helpful in the situation?

If you need any more info please let me know


Question by:Hurel
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 3
  • +1
LVL 15

Assisted Solution

JimboEfx earned 40 total points
ID: 20365376
Consider a domain rename to move the child domain so that it becomes its own root:
LVL 10

Expert Comment

by:Walter Padrón
ID: 20365395
Hi, you can't separate a child domain from a forest.
You must setup a new forest and migrate your accounts, groups and pcs.


Author Comment

ID: 20365422
Any idea on questions one and two?

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why


Author Comment

ID: 20365563
Just read the artical in your link JimboEfx

The domain would still need to be in its own forest even it is was the root?
LVL 10

Assisted Solution

by:Walter Padrón
Walter Padrón earned 40 total points
ID: 20365567
Q1- Nothing happens, child domain will continue working (see Q2)

Q2- Is difficult to say but certainly it will stop working or you can't do certain tasks or you may get unexpected behaviours.
LVL 15

Expert Comment

ID: 20365629
The rename tool only creates a new tree-root with dependencies on the forest root still if I read this correctly...  

To be honest I think the safest path is ADMT migration into a new domain.
LVL 30

Accepted Solution

LauraEHunterMVP earned 45 total points
ID: 20365683
> "Consider a domain rename to move the child domain so that it becomes its own root"

Incorrect.  Domain rename cannot perform any kind of "prune and graft" to sever a child domain so that it becomes the root of its own forest.  This is actually referenced in the link above:

"In a Windows Server 2003 forest, you cannot:

• Change which domain is the forest root domain. Changing the DNS name or the NetBIOS name (or both) of the forest root domain is supported.
• Drop domains from the forest or add domains to the forest. The number of domains in the forest before and after the domain rename and restructuring operation must remain the same.
• Rename a domain with a name that was taken from another domain in a single domain rename and restructuring operation."

To the OP's questions:

1.      What will happen if we just sever the link from UK.COM to B.UK.COM?

B.UK.COM will no longer be able to replicate the Schema and Configuration NCs, which are replicated forest-wide.  The domain controller will throw up errors like crazy trying to replicate with its forest root.

2.      How long will B.UK.COM function without access to UK.COM.

Hard to say, since what you're describing is not recommended (and probably not supported) by Microsoft.   Off the top of my head you would be unable to perform any actions requiring Enterprise Admin or Schema admin permissions, since these security groups only exist in the forest root domain by default and will no longer be accessible to the child.

3.      Is it possible to separate B.UK.COM without migrating everything to a new domain

Not in a supported fashion; AD does not possess the kind of prune and graft functionality that you're describing without performing a migration from one domain to another.
LVL 15

Expert Comment

ID: 20365830
As I posted above before you rightly pointed my initial statement as incorrect, I re-read and this time properly. The child domain becomes tree-root not a new forest root.

Just wondering aloud - but while we have so many great minds I wonder about the feasability of:

Lets get it out of the way first - this would be not supported or recommended for that matter, I just want a discussion on it.

If you could ensure physical seperation of the child domain from the rest of the network:
-Add additional root domain dc
-Add additional Child DC
-Make sure DNS is installed and all objects replicated

Physically seperate from original network.

Clean up in orphaned network to remove all references of seperated DCs.
Seize FSMO roles.
Promote new DC in seperated forest root for resiliency.
Clear forest root of any accounts not needed.
Possible domain rename at this point?

In original network clean up references of the additional DCs now disconnected.

Some steps may be missing - but hypothetically?
LVL 30

Expert Comment

ID: 20365865
What you just outlined is actually pretty common in an organization that does a lot of acquisitions and divestitures, and is one of the only remaining scenarios in which an empty forest root domain is good design sense.  If I am the parent company and I have just sold a holding with a domain of, I hand the new owners of CHILD a root DC from company and a child DC from CHILD as you describe (obviously after scrubbing the root domain of any unnecessary accounts and changing all sensitive user account passwords), and send the new owners of CHILD on their merry way.

Author Comment

ID: 20365948
so if a get a copy of the empty root domain my child domain will continue to work OK?
Could I then rename my child to make it the root domain?
LVL 30

Expert Comment

ID: 20366098
> "so if a get a copy of the empty root domain my child domain will continue to work OK?"


> "Could I then rename my child to make it the root domain?"

No, as stated above.  If you wish to restructure the child domain so that it becomes the root domain of its own forest, a migration is necessary.

Author Closing Comment

ID: 31411403
Thanks for the answers chaps. Looks like the seperation is not going to happen now!

I've just devided thepoint between you.Hope that is OK


Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question