[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now



Posted on 2009-04-24
Medium Priority
Last Modified: 2012-05-06
I'm trying to DCPromo a server 2003 Domain Controller to remove it from AD and Im receiving two error messages. One I have attached as a BMP file. I get the BMP file error first then after hitting ok I see the following

The operation failed because:
Active Directory could not transfer the remaining data in directory partition DC=msek,DC=com to domain controller MSEK-3-DC2.msek.com.
"The Active Directory cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime."

What steps should i take to remove this server from AD.
Question by:Ekuskowski
  • 2
  • 2
LVL 27

Assisted Solution

bluntTony earned 1000 total points
ID: 24224644
Did you have replication issues with this DC (well it looks like you did, for about 60 days by the sounds of it)? Were you aware of any issues? Is the other server still up and running?
How many other DCs are there on the network, and where do your FSMO roles lie? My only reservation is that if you've been making changes on this DC which haven't been replicated, then you remove this DC forcibly you're going to lose those changes.
To remove a failed DC from AD you will need to perform a metadata cleanup : http://www.petri.co.il/delete_failed_dcs_from_ad.htm, but I would first try to troubleshoot the replication issues.
LVL 18

Assisted Solution

flyingsky earned 1000 total points
ID: 24224654
has this server been offline for quite some time (more than 60 days)?
If so, you'd better shut down (disconnect from the network) it immediately and manually remove it from your AD

Author Comment

ID: 24225817
No changes would have been made on this Domain controller.
The domain controller was and is having replication problems. I see errors dating back 4 months.
The server has no FSMO roles.
We have 4 other Domain controllers at this time, but are planning on retiring/ demoting two of them.
The other servers are not having replication issues

If I forcibly remove the server, will all remnants of the DC be removed from AD ?
I'll review the two links the two of you provided.

LVL 27

Expert Comment

ID: 24226612
I think both links refer to the same process.
If you follow this link to remove the server, then all remnants will be removed from AD, but I would be careful that you haven't been making changes on this DC that will be lost. I would imagine you would have come across problems before now if this was the case (users not being able to log on etc), but I would check to be sure.

Accepted Solution

Ekuskowski earned 0 total points
ID: 24228284
We have been running some tests on the server

DCDIAG, replication tests (replmon), and funny all the tests passed. But everytime we ran dcpromo we would have the same problems.

We made no setting changes but for some reason DCPROMO worked this time. So now my DC has been removed and no longer shows up in sites and services

So my issue is now resolved , thank you all for your help

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question