Avatar of AblSysadmin
AblSysadmin
 asked on

Group Policy was applied from deleted domain controller

We have an issue with domain policies not being applied. After running a gpresult we have found that the policy is trying to update from a DC that was deleted about 3 years ago...

How can I find this ghost object and remove it?
Active Directory

Avatar of undefined
Last Comment
snusgubben

8/22/2022 - Mon
Miguel Angel Perez Muñoz

AblSysadmin

ASKER
Server being listed in gpresult not listed. these DC's were removed without any issues a bout 3years ago but still being ref by gpo
snusgubben

A "dcdiag /v /e /f:dcdiag.txt" might tell you why.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
AblSysadmin

ASKER
found this in the result between all the current prod DC's

* SPN found :LDAP/a6a54aea-9b1c-4f94-ac33-8d4f99e96664._msdcs.domain.name
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/a6a54aea-9b1c-4f94-ac33-8d4f99e96664/domain.name

how can i removed this if i don't find it in DNS?
snusgubben

Where did you find it?

E3514235-4B06-11D1-AB04-00C04FC2DCD2 is the AD replication SPN
a6a54aea-9b1c-4f94-ac33-8d4f99e96664 is the DC GUID

This entry should only be registered on the DC with that GUID.

To see spn's:

setspn -l <name of DC>

To remove a spn:

setspn -d <SPN> <name of DC>
arifkayaca

Try abandon your domain with one of your domain account and join domain again (I suppose you have a another dc ) and check your dns settings to clients resolve your new dc (on client side, in command prompt write ipconfig /flushdns)

good luck.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
AblSysadmin

ASKER
removed pc from domain and readded it. no issues. with the setspn cmd:
FindDomainForAccount: DsGetDcNameWithAccountW failed!
arifkayaca

Try, open OU that your computer belongs to, right click computer name select reset computer account (be careful, all GPOs,certificates are affected at this time).

If it doesn't work try move your client to another OU.


good luck
AblSysadmin

ASKER
How do i remove the old DC from the domain if the computer account does not exist anymore?
Your help has saved me hundreds of hours of internet surfing.
fblack61
ASKER CERTIFIED SOLUTION
snusgubben

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question