Solved

Should I forcefully Demote a DC that has just passed the tombstone lifetime

Posted on 2010-08-16
6
690 Views
Last Modified: 2012-05-10
Hello guys and as always thanks for the time and expertise.  I have a windows server 2003 sp2 DC that had to be taken offline because of structural problems in a particular bldg - couldn't be helped.  The DC last successfully replicated on 6/16 and I was going to bring it back online tomorrow.  The tombstone lifetime for my forest is 60 days which puts me a day over.  I'm sure objects have been deleted during this time but I don't think there were many changed but I'm not sure as we have many sites and I'm not the only admin.  
By the way, we only have one domain.  My question is do you think I should just demote this dc, forecefully if necessary, to make sure there's no problems or should I check and remove any lingering objects with the repadmin /removelingeringobjects command.  I just want to follow best practices but I've never experienced this scenario before.  Please let me know you would recommend.
Again, the server is past tombstone only by a day.  Thanks.  
As an aside, should I increase the tombstone to 180 for the future?
0
Comment
Question by:pendal1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 4

Assisted Solution

by:a1rh0pper
a1rh0pper earned 200 total points
ID: 33451394
What other functions does the box provide?

If it doesn't do file or print, or any applications.....I would forcefully demote it. Clean up AD, and bring it back in if the desire is to have it back online as a domain controller.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 300 total points
ID: 33451400
Man just one day over the TSL; yeah I'd just /forceremoval, metadata cleanup, add back to the domain and promote again.  It is not as bad as it sounds.

If you think there could be a chance something like happens again then increasing it to 180 would be a good safety net.

Thanks

Mike
0
 

Author Comment

by:pendal1
ID: 33453556
Thanks for the responses guys.  I think this DC also hosts a printer but only one so I can work around that. When I bring it back online, and I think I'm doing that today but I'm not a 100% sure - I will check for other functunailty.  The primary function is to be a DC and you guys seem to think it's best to demote and then bring it back online clean.  
mkline71 - that's my luck - one lousy day.  
0
Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

 
LVL 57

Expert Comment

by:Mike Kline
ID: 33454521
The printers should be fine, /forceremoval will put it in a workgroup.  Then you run the metadata cleanup after that.  Then you add it back to the domain and promote again.
Give the domain time to fully replicate between the steps.
Thanks
Mike
0
 

Author Comment

by:pendal1
ID: 33460792
Thanks guys.  I  took your advice and forefully demoted the DC.  I also renamed the domain controller when readdming it back to the domain just in case there were any lingering references.  Process went smoothy.  There was only one printer installed on this server and I'll change that reference in GP.  Thanks again for your time and valuable info.
0
 

Author Closing Comment

by:pendal1
ID: 33460797
Thank you very much for your prompt attention and expert advice.  Greatly appreciated.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question