Manually removing DC from Domain

Posted on 2011-03-09
Last Modified: 2012-05-11
Someone previously removed an old DC (this used to be the only DC) from my domain a while back.  I keep finding remnants of this old server in AD and DNS.  What is the best practice for cleaning up AD/DNS to remove this old server.
Question by:emauch
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
LVL 11

Accepted Solution

RickSheikh earned 500 total points
ID: 35084287
Metadata cleanup should be performed.

Let us know if you run into any issues.
LVL 11

Expert Comment

ID: 35084304
Also the metadata cleanup does not always remove the DC (server object) under Sites and Services. So it should be manually removed.

What are these remnants you refer to ? the _msdcs specific records ?

Author Comment

ID: 35084416
Yes, there is an entry in DNS under "my domain.local" > _msdcs for the server.  The strange thing is that this is the only server listed under this section.  Should I add my 2 new DCs and remove the old one here?
Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

LVL 11

Expert Comment

ID: 35084524
The other two DCs should have already register these SRV records on their. Restarting Netlogon service can accomplish that unless there is any issue from DCs standpoint i.e dynamic registration

SRV Resource Records May Not Be Created on Domain Controller

Troubleshooting Common Active Directory Setup Issues in Windows 2000

How to Verify the Creation of SRV Records for a Domain Controller

Frequently Asked Questions About Windows 2000 DNS and Windows Server 2003 DNS

Windows 2000 DNS and Active Directory Information and Technical Resources
LVL 11

Expert Comment

ID: 35084533
*The other two DCs should have already registered these SRV records on their own*.

The bunk record (old/dead DC) needs to be deleted.

Author Comment

ID: 35084549
The other two servers appear to have their records in all the right places, except for the one I mentioned above.  Can I just add them manually?
LVL 11

Expert Comment

ID: 35084681
Well, they may not be needed, depending on where you are looking under the _msdcs node.

If you are looking under _sites than the only DC belonging to that site should have an SRV record there and it is possible that site only had the bad DC in it.

The _tcp node on the other hand should have all the live writable DCs with their _kerberos, _ldap, _kpassed etc SRV records.

See the fourth link provided.

Author Closing Comment

ID: 35085313
Thank you for all your help.

Featured Post

Office 365 Training for Admins

Learn how to provision tenants, synchronize on-premise Active Directory, and implement Single Sign-On with these master level course.  Only from Platform Scholar

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question