Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Should I forcefully Demote a DC that has just passed the tombstone lifetime

Posted on 2010-08-16
6
686 Views
Last Modified: 2012-05-10
Hello guys and as always thanks for the time and expertise.  I have a windows server 2003 sp2 DC that had to be taken offline because of structural problems in a particular bldg - couldn't be helped.  The DC last successfully replicated on 6/16 and I was going to bring it back online tomorrow.  The tombstone lifetime for my forest is 60 days which puts me a day over.  I'm sure objects have been deleted during this time but I don't think there were many changed but I'm not sure as we have many sites and I'm not the only admin.  
By the way, we only have one domain.  My question is do you think I should just demote this dc, forecefully if necessary, to make sure there's no problems or should I check and remove any lingering objects with the repadmin /removelingeringobjects command.  I just want to follow best practices but I've never experienced this scenario before.  Please let me know you would recommend.
Again, the server is past tombstone only by a day.  Thanks.  
As an aside, should I increase the tombstone to 180 for the future?
0
Comment
Question by:pendal1
  • 3
  • 2
6 Comments
 
LVL 4

Assisted Solution

by:a1rh0pper
a1rh0pper earned 200 total points
ID: 33451394
What other functions does the box provide?

If it doesn't do file or print, or any applications.....I would forcefully demote it. Clean up AD, and bring it back in if the desire is to have it back online as a domain controller.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 300 total points
ID: 33451400
Man just one day over the TSL; yeah I'd just /forceremoval, metadata cleanup, add back to the domain and promote again.  It is not as bad as it sounds.

If you think there could be a chance something like happens again then increasing it to 180 would be a good safety net.

Thanks

Mike
0
 

Author Comment

by:pendal1
ID: 33453556
Thanks for the responses guys.  I think this DC also hosts a printer but only one so I can work around that. When I bring it back online, and I think I'm doing that today but I'm not a 100% sure - I will check for other functunailty.  The primary function is to be a DC and you guys seem to think it's best to demote and then bring it back online clean.  
mkline71 - that's my luck - one lousy day.  
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 57

Expert Comment

by:Mike Kline
ID: 33454521
The printers should be fine, /forceremoval will put it in a workgroup.  Then you run the metadata cleanup after that.  Then you add it back to the domain and promote again.
Give the domain time to fully replicate between the steps.
Thanks
Mike
0
 

Author Comment

by:pendal1
ID: 33460792
Thanks guys.  I  took your advice and forefully demoted the DC.  I also renamed the domain controller when readdming it back to the domain just in case there were any lingering references.  Process went smoothy.  There was only one printer installed on this server and I'll change that reference in GP.  Thanks again for your time and valuable info.
0
 

Author Closing Comment

by:pendal1
ID: 33460797
Thank you very much for your prompt attention and expert advice.  Greatly appreciated.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question