Solved

Removing a Domain Controller from a Domain with AD-integrated zone for domain

Posted on 2015-02-10
5
192 Views
Last Modified: 2015-02-11
I have 2 domain controllers (Windows 2008 and Windows 2012 R2) running at each site (3 sites total in my network), both running with AD-integrated DNS zone for the domain.  My plan is to decommission the old Windows 2008 DC by uninstall ADDS and then DNS roles from this server.  Based on my understanding, I need to run "dcpromp"  which will remove domain controller and uninstall any AD-integrated zone.

Per technet, "After AD DS is removed, the DNS server role remains installed and running if it was previously installed on the domain controller. But any Active Directory–integrated DNS zones that were installed are removed. By default, the AD DS removal process also attempts to remove the Domain Name System (DNS) delegations for the zones that point to the domain controller."

My concern is that if I have other DNS servers running for the AD-integrated zone (since they are replicated by AD), is there anything I need to worry?  The DNS service will not be affected right (since I have other servers running DNS).  

I am just trying to be a litte bit more caution.  If something goes bad, there is no way to undo it.   Can someone confirm with me please?

Thank you!
0
Comment
Question by:ModCloth_IT
5 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40602147
If you are demoting a domain controller and there is no issues while doing this process everything should be fine.

You can also check a few other things to ensure that the DC is removed.

netdom query dc

Another thing I would recommend is updating all DHCP scopes which use this DC for DNS and change it to another DC/DNS server that will be online. Also do this for any servers that have static IP's for DNS and also printers etc. This way you mitigate any issues after the demotion is successful.

Will.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 40602636
You are not deleting any zone, you are demoting domain controller

If you are delete any AD integrated zone, zone deletion will get replicated to all domain controllers and that zone got deleted from all DCs

As opposed when you demote DC, AD would just remove all AD integrated zones from that particular server by setting up flag as demoted and zones would get deleted from only that server
0
 
LVL 11

Accepted Solution

by:
Venugopal N earned 500 total points
ID: 40602862
I think you have been confused with the selection on demoting the DC "Delete the DNS delegations pointing to this server "

This option will removes any DNS delegation records for that specific server in DNS.  If that server is no longer going to run DNS, you wouldnt want any delegation records pointing to it.So we can select this, which will remove the delegation record of this server from DNS.Also the process will remove the appropriate SRV records.If the SRV records are not removed when demaoting the server, the client may be looking for this server for authentication.

None of the DNS zone will be deleted as part of the DCPROMO.

Refer the below link for more inforamtion on demoting the DC.

https://technet.microsoft.com/en-us/library/cc771844(WS.10).aspx
https://technet.microsoft.com/en-us/library/cc816644(v=ws.10).aspx
0
 

Author Comment

by:ModCloth_IT
ID: 40604545
However, I got to a different error after trying to "delete the DNS delegations pointing to this server".

"DCPromo was unable to remove DNS delegations from the parent zone: "int".  This could be because of one of the following reasons: you do not have permission to do so, the zone is hosted by a server that does not run Windows, no server hosting this zone can be contacted or the zone does not exist.  

If the zone does exist, you should delete DNS delegations in the parent zone targeting this domain controller.  To do so, contact an administrator who is responsible for the DNS zone: "int".  
The error was:

The RPC server is unavailable."

Any someone advise how to remove the DNS delegations along while trying to use "dcpromo" to remove Domain Controller please?  

Your help and patience are greatly appreciated.  Thanks in advanced.
0
 

Author Comment

by:ModCloth_IT
ID: 40604637
I went ahead to process and seem like no issue even I saw the error in the above.  After uninstall the ADDS from Server Manager and also uninstalled DNS, everythings look good and verify the domain controller is no longer show up in ADUC and the service record of this old server is no longer showing up in other DNS server.  Seem like i should not worry anymore.

Thanks everyone!
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

The password reset disk is often mentioned as the best solution to deal with the lost Windows password problem. In Windows 2008, 7, Vista and XP, a password reset disk can be easily created. But besides Windows 7/Vista/XP, Windows Server 2008 and ot…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now