Avatar of emauch
emauch
Flag for United States of America asked on

Manually removing DC from Domain

Someone previously removed an old DC (this used to be the only DC) from my domain a while back.  I keep finding remnants of this old server in AD and DNS.  What is the best practice for cleaning up AD/DNS to remove this old server.
Active DirectoryWindows Server 2003DNS

Avatar of undefined
Last Comment
emauch

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
RickSheikh

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
RickSheikh

Also the metadata cleanup does not always remove the DC (server object) under Sites and Services. So it should be manually removed.

What are these remnants you refer to ? the _msdcs specific records ?
emauch

ASKER
Yes, there is an entry in DNS under "my domain.local" > _msdcs for the server.  The strange thing is that this is the only server listed under this section.  Should I add my 2 new DCs and remove the old one here?
RickSheikh

The other two DCs should have already register these SRV records on their. Restarting Netlogon service can accomplish that unless there is any issue from DCs standpoint i.e dynamic registration

http://support.microsoft.com/kb/241505

SRV Resource Records May Not Be Created on Domain Controller
http://support.microsoft.com/?kbid=239897

Troubleshooting Common Active Directory Setup Issues in Windows 2000
http://support.microsoft.com/?kbid=260371

How to Verify the Creation of SRV Records for a Domain Controller
http://support.microsoft.com/?kbid=241515

Frequently Asked Questions About Windows 2000 DNS and Windows Server 2003 DNS
http://support.microsoft.com/?kbid=291382

Windows 2000 DNS and Active Directory Information and Technical Resources
http://support.microsoft.com/?kbid=298448
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
RickSheikh

*The other two DCs should have already registered these SRV records on their own*.

The bunk record (old/dead DC) needs to be deleted.
emauch

ASKER
The other two servers appear to have their records in all the right places, except for the one I mentioned above.  Can I just add them manually?
RickSheikh

Well, they may not be needed, depending on where you are looking under the _msdcs node.

If you are looking under _sites than the only DC belonging to that site should have an SRV record there and it is possible that site only had the bad DC in it.

The _tcp node on the other hand should have all the live writable DCs with their _kerberos, _ldap, _kpassed etc SRV records.

See the fourth link provided.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
emauch

ASKER
Thank you for all your help.