Solved

Remove Stale DC

Posted on 2009-07-09
9
401 Views
Last Modified: 2012-05-07
Hi Experts,

In active directory I have a server listed as a DC that is no longer serving that role.  It appears the server at one point was reloaded, but the admin failed to demote it before proceeding.  In addition, the server was renamed exactly the same and rejoined as the member of the domain.

All roles and services are running properly on their corresponding servers, and their are no roles to seize back.

Since a replacement server has been installed on the network with exact name I am unsure if I can run the standard remove orphaned DC procedure.

Any suggestions on how to move forward?  (besides renaming the server?)

Thanks
0
Comment
Question by:gws226
  • 4
  • 3
  • 2
9 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
Comment Utility
When you go through the metadata cleanup process do you see the old  and new server listed?
http://msmvps.com/blogs/ad/archive/2008/12/17/how-to-remove-a-failed-or-offline-dc.aspx
Thanks
Mike
 
0
 
LVL 27

Expert Comment

by:bluntTony
Comment Utility
So you have two machine accounts in AD with the same name, one is a DC and one a member? Where are you seeing the DC listed?

If it's in AD Sites and Services or DNS, then you could just delete the relevant objects.
0
 
LVL 27

Expert Comment

by:bluntTony
Comment Utility
Sorry, to clarify, what I meant to say was -

If it's JUST in AD Sites and Services or DNS, and event logs/DCDIAG etc are not showing errors relating to this DC, then you could just delete the relevant objects.
0
 

Author Comment

by:gws226
Comment Utility
It shows my current DCs correctly.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:gws226
Comment Utility
you type faster then I do.  :)

I suspect that was the case.  Its OK to delete from Sites and Services then?  (its actually an exchange box so I'm really looking for some solid confirmation before proceeding.

Thanks.
0
 
LVL 27

Expert Comment

by:bluntTony
Comment Utility
If it's only showing in AD Sites and Services, and you have no errors in DCDIAG on other DCs, the machine isn't in 'Domain Controllers' in ADUC, and the other servers in AD Sites and Services do not have connection objects linking to it, then you can just delete the object. It's a leftover from the metadata cleanup.

In fact, every time I've ran a metadata cleanup in ntdsutil, I've had to manually delete the server object from AD Sites and Services.

I know Mike's already posted a link on the procedure, but this one also details some steps you have to carry out after ntdsutil, including deleting the server object from ADSS.

http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Tony


0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
Yes, I second the sites and services answer...it is ok to delete it.
Thanks
Mike
0
 

Author Comment

by:gws226
Comment Utility
[quote]
If it's only showing in AD Sites and Services, and you have no errors in DCDIAG on other DCs, the machine isn't in 'Domain Controllers' in ADUC, and the other servers in AD Sites and Services do not have connection objects linking to it, then you can just delete the object. It's a leftover from the metadata cleanup.
[/quote]

Typo on my part.

It appears in ADUC but not in Sites and Services.
0
 

Author Closing Comment

by:gws226
Comment Utility
The previous administrator also did some permission changes that prevented proper demotion of the DCs.  In addition to Mkline71's steps, I also had to change the security permissions as outlined here.

http://www.experts-exchange.com/Networking/Windows_Networking/Q_21548491.html
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Suggested Solutions

My last post dealt with using group policy preferences to set file associations, a very handy usage for a GPP. Today I am going to share another cool GPP trick, this may be a specific scenario but I run into these situations frequently in my activit…
Companies that have implemented Microsoft’s Active Directory need to ensure that the Active Directory is configured and operating properly. If there are issues found and not resolved, it eventually leads the components to fail or stop working and fi…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now