Monday, May 25, 2015

windows server 2008 - Old domain controller still showing up in ADSS



Yesterday I demoted a domain controller, removed it from the domain and shut it down. My new Primary Domain Controller is up and running just fine (along with a secondary). Replication status is normal and doesn't show the old DC.



However, when I go into Active Directory Sites and Services -> SITE NAME -> Servers I still see the old DC. If I expand it there is nothing (unlike the other DC's which have NTDS Settings).



Is it ok to delete this server? It doesn't show up in the DOMAIN CONTROLLER organizational unit under Active Directory Users and Computers.


Answer



Yes, you can delete it right in ADS&S. See this article about manually removing domain controllers:




https://blogs.technet.microsoft.com/canitpro/2016/02/17/step-by-step-removing-a-domain-controller-server-manually/



The relevant section:




Step 2: Cleaning up the DC server instance from the Active Directory Sites and Services




  1. Go to Server manager > Tools > Active Directory Sites and Services


  2. Expand the Sites and go to the server which need to remove

  3. Right click and click Delete

  4. In next window click yes to confirm




You might want to do this too, just in case:




Step 3: Clean up metadata using ntdsutil




NOTE: Windows Server 2003 or earlier used ntdsutil and was bit of challenge but this was later simplified




  1. Right Click on Start > Command Prompt (admin)

  2. Type ntdsutil and enter

  3. Then metadata cleanup

  4. Next type remove selected server , replace with DC server to remove

  5. In warning window click yes to proceed

  6. Execute quit command twice




No comments:

Post a Comment

linux - How to SSH to ec2 instance in VPC private subnet via NAT server

I have created a VPC in aws with a public subnet and a private subnet. The private subnet does not have direct access to external network. S...