Solved

Should I forcefully Demote a DC that has just passed the tombstone lifetime

Posted on 2010-08-16
6
685 Views
Last Modified: 2012-05-10
Hello guys and as always thanks for the time and expertise.  I have a windows server 2003 sp2 DC that had to be taken offline because of structural problems in a particular bldg - couldn't be helped.  The DC last successfully replicated on 6/16 and I was going to bring it back online tomorrow.  The tombstone lifetime for my forest is 60 days which puts me a day over.  I'm sure objects have been deleted during this time but I don't think there were many changed but I'm not sure as we have many sites and I'm not the only admin.  
By the way, we only have one domain.  My question is do you think I should just demote this dc, forecefully if necessary, to make sure there's no problems or should I check and remove any lingering objects with the repadmin /removelingeringobjects command.  I just want to follow best practices but I've never experienced this scenario before.  Please let me know you would recommend.
Again, the server is past tombstone only by a day.  Thanks.  
As an aside, should I increase the tombstone to 180 for the future?
0
Comment
Question by:pendal1
  • 3
  • 2
6 Comments
 
LVL 4

Assisted Solution

by:a1rh0pper
a1rh0pper earned 200 total points
ID: 33451394
What other functions does the box provide?

If it doesn't do file or print, or any applications.....I would forcefully demote it. Clean up AD, and bring it back in if the desire is to have it back online as a domain controller.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 300 total points
ID: 33451400
Man just one day over the TSL; yeah I'd just /forceremoval, metadata cleanup, add back to the domain and promote again.  It is not as bad as it sounds.

If you think there could be a chance something like happens again then increasing it to 180 would be a good safety net.

Thanks

Mike
0
 

Author Comment

by:pendal1
ID: 33453556
Thanks for the responses guys.  I think this DC also hosts a printer but only one so I can work around that. When I bring it back online, and I think I'm doing that today but I'm not a 100% sure - I will check for other functunailty.  The primary function is to be a DC and you guys seem to think it's best to demote and then bring it back online clean.  
mkline71 - that's my luck - one lousy day.  
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 57

Expert Comment

by:Mike Kline
ID: 33454521
The printers should be fine, /forceremoval will put it in a workgroup.  Then you run the metadata cleanup after that.  Then you add it back to the domain and promote again.
Give the domain time to fully replicate between the steps.
Thanks
Mike
0
 

Author Comment

by:pendal1
ID: 33460792
Thanks guys.  I  took your advice and forefully demoted the DC.  I also renamed the domain controller when readdming it back to the domain just in case there were any lingering references.  Process went smoothy.  There was only one printer installed on this server and I'll change that reference in GP.  Thanks again for your time and valuable info.
0
 

Author Closing Comment

by:pendal1
ID: 33460797
Thank you very much for your prompt attention and expert advice.  Greatly appreciated.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question