Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

DNS Delegation on about to be decommissioned W2k3 DC

Posted on 2014-09-05
1
Medium Priority
?
405 Views
Last Modified: 2014-09-08
Hello

I have a Windows 2003 native domain with 2008 R2 PDC and Secondary DCs and a 2003 SP2 DC that is about to be decommissioned. All FSMO roles are on the PDC (my boss's decision) and all DCs are Global Catalogs.

When I DCDIAG the report says that:

           DNS delegation for the domain  _msdcs.domain.local. is operational on IP 192.168.x.xx

And:
               TEST: Delegations (Del)
                  Delegation information for the zone: domain.local.
                     Delegated domain name: _msdcs.domain.local.
                        DNS server: old_dc.domain.local. IP:192.168.x.xx [Valid]

where 192.168.x.xx is the old 2003 DC. 2003 DC was an SBS server and used to be the primary (only) DC and used to run Exchange 2003 (now uninstalled).

My questions:
* What is the DNS Delegation for (we have no child domains)?
* Do I need to take any action regarding the DNS delegation before I DCPROMO it to make it just a member server?
* If so what do I need to do?

Help much appreciated.
0
Comment
Question by:dejected
1 Comment
 
LVL 27

Accepted Solution

by:
DrDave242 earned 2000 total points
ID: 40306220
The delegation is for the _msdcs.domain.local zone, which is effectively a child domain. (It may sometimes appear as a folder named _msdcs beneath the domain.local zone rather than a separate zone.)

In the DNS console, there should be a gray folder named _msdcs inside your domain.local zone. This is the delegation record, and it should contain name server (NS) records for each DC/DNS server that hosts a copy of the zone (every DC/DNS server in the forest by default, I believe).

Check all DCs which are also DNS servers and verify that at least one of them has an _msdcs.domain.local forward lookup zone. (It's an AD-integrated zone by default, so they should all have a copy of it unless you've changed that.) Then check the delegation record and make sure the NS records match the DCs which have a copy of the zone. If you find a discrepancy, you can only make changes by right-clicking the delegation record and selecting Properties - you can't directly modify the NS records in the delegation.

You shouldn't have to change anything if the NS records in the delegation are correct; it should be handled during the demotion, but you may want to go back and check after the server is demoted to make sure its NS record was removed from the delegation.
0

Featured Post

 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question