Solved

Removing failed 2008R2 DC from ADUC after running /forceremoval

Posted on 2014-11-14
5
9 Views
Last Modified: 2016-06-23
DCDIAG reported a DC had exceeded its replication tombstone. We attempted to gracefully remove AD using DCPROMO with no luck. So we disconnected it from the network, ran /forceremoval (worked), then went into AD to remove the remnants. Took it out of ADS&S no problem, removed all DNS records no problem, but attempted to remove it from the Domain Controllers container in ADUC and got a pop-up that said:

Windows cannot delete object [server name] because:
Directory Object not found

Do I need to use ADSIUTIL now to manually clean this up? The server is permanently offline.
0
Comment
Question by:214-042308
  • 2
5 Comments
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 40443166
Did you run a metadata cleanup?

http://www.petri.com/delete_failed_dcs_from_ad.htm
0
 

Author Comment

by:214-042308
ID: 40443227
No good. Got to "list servers in site" after selecting the site it existed in and "Found 0 servers" but the artifact remains in ADUC. So, looks like using ADSIEDIT and not NTDSUTIL?
0
 
LVL 37

Assisted Solution

by:Neil Russell
Neil Russell earned 500 total points
ID: 40443390
Yes you need to find the server in ADSI Edit and expand it and delete the child objects from it first.
0
 

Accepted Solution

by:
214-042308 earned 0 total points
ID: 40443663
Apparently it's true that Windows Server 2008R2 will automatically remove metadata - the object is now gone from ADUC without my further intervention. I will still run ADSIUTIL to see if I have any vestigial metadata, but it appears AD is now clean.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

30 Experts available now in Live!

Get 1:1 Help Now