Remove old DCs from AD

Awhile back we upgraded out domain from 2003R2 to 2012R2.
The old DCs were demoted using DCpromo.
However, they are still listed in AD Computers.
When I try to manually delete them, I get the message;
==============
 The object SRV2003 contains other objects. Do you want to remove the object SRV2003 and all the objects it contains?
    If you cancel the removal in process any objects removed are not restored.

    WARNING: If you check the box "Use server control for removal of subtrees" all objects in the subtree are removed, including objects which are protected against removal, and the removal cannot be undone.
=============

I turned on the view computers as containers, but see nothing inside of them. Is it safe to delete these objects while checking the box "Use server control for removal of subtrees" or could this have an adverse effect on my current Domain/DCs?
keamalsaSystem AdministratorAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hypercat (Deb)Commented:
It's safe to delete those objects.  I've seen that message many times in the past; not sure exactly what causes the message to appear, but I've never seen any adverse effects of deleting the objects.  If you want to be extra certain, you can use adsiedit.msc instead of ADUC to check the objects and make sure there are no subcontainers with any objects in them.
1

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
FOXActive Directory/Exchange EngineerCommented:
If you have already successfully demoted it, it is not talking to any of the domain controllers
Make sure any traces of the 2003 DC are  deleted from AD, AD Sites and Services, DNS(forward and reverse lookups)
0
keamalsaSystem AdministratorAuthor Commented:
So, to be clear, It's OK to delete it while checking the box "Use server control for removal of subtrees" ?
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

FOXActive Directory/Exchange EngineerCommented:
AS hypercat suggested, open ASiedit and see if there are any valuable objects below it.  I doubt it.  If you see nothing delete away.
0
keamalsaSystem AdministratorAuthor Commented:
Opened ADSi Edit, and there are folders under the DC object folder named CN=IASIdentity, but nothing inside of those folders.
0
Hypercat (Deb)Commented:
Yes, that's OK to delete. It looks like Microsoft Internet Authentication Service was once in use. I'm assuming that's not longer the case and/or that server particularly isn't being used for that purpose.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.