Forcing the removal of a Domain Controller

Source: Internet
Author: User

forcing the removal of a Domain Controller



Reference Link

Https://technet.microsoft.com/en-us/library/cc781245%28v=ws.10%29.aspx


Forced removal of a domain controller from Active Directory are intended to being used as a last resort to avoid have to Rei Nstall the operating system on a domain controller, which has failed and cannot is recovered. When a domain controller can be no longer function in a domain (so is, it's offline), you cannot remove Active Directory I n the normal, which requires connectivity to the domain. Forced removal is not intended to replace the normal Active Directory removal procedure on any. It is virtually equivalent to permanently disconnecting the domain controller.

Active Directory stores a considerable amount of metadata about a domain controller. During the normal process of uninstalling active Directory on a domain controller, this metadata was removed from active Di Rectory through a connection to another domain controller in the domain. A forced removal assumes that there are no connectivity to the domain; Therefore, it does not attempt any metadata removal (cleanup).

Consequently, forced removal of Active Directory from a domain controller should always being followed by the metadata Cleanu P procedure, which removes all references to the domain controller from the domain and forest.

Forced demotion should not being performed on the last domain controller in a domain.

Task Requirements

The following tools is required to perform the procedures for this task:

    • Active Directory Sites and Services

    • Dcpromo.exe

    • Ntdsutil.exe


To clean up server metadata
    1. Open a command prompt.

    2. Type the following command, and then press ENTER:

      ntdsutil

    3. At the ntdsutil: prompt, type:

      metadata Cleanup

    4. Perform metadata cleanup as follows:

      At this point, Active Directory confirms the domain controller was removed successfully. If you receive a error message that indicates this object cannot be found, Active Directory might has already remove d the domain controller.

  • If you were performing metadata cleanup by using the version of the Ntdsutil.exe that's included with Windows Server 2003 SP1, At the metadata cleanup: prompt, type:

    Remove selected server ServerName

    Or

    Remove selected server ServerName1 on ServerName2

    Value Definition

    ServerName, ServerName1

    The distinguished name of the domain controller whose metadata you want to remove, in the form cn=ServerName, Cn=s ervers,cn=SiteName, cn=sites,cn=configuration,dc=forestrootdomain

    ServerName2

    The DNS name of the domain controller to which your want to connect and from which you want to remove server metadata

  • If you were performing metadata cleanup by using the version of Ntdsutil.exe, that is included with Windows Server 2003 with No service pack, perform metadata cleanup as follows:

  1. At the metadata cleanup: prompt, type:

    Connection

  2. At the server connections: prompt, type:

    Connect to Server Server

  3. At the server connections: prompt, type:

    Quit

  4. At the metadata cleanup: prompt, type:

    Select operation Target

  5. At the select operation target: prompt, type:

    List Sites

    A numbered list of sites appears.

  6. At the select operation target: prompt, type:

    Select Site Sitenumber

  7. At the select operation target: prompt, type:

    List domains in site

    A numbered list of domains in the selected site appears.

  8. At the select operation target: prompt, type:

    Select Domain Domainnumber

  9. At the select operation target: prompt, type:

    List servers in site

    A numbered list of servers in a domain and site appears.

  10. At the select operation target: prompt, type:

    Select Server Servernumber

  11. At the select operation target: prompt, type:

    Quit

  12. At the metadata cleanup: prompt, type:

    Remove selected server

    value description

    Server

    The DNS name of a domain controller that you want to connect to

    sitenumber

    The number associated with the Site of the server so you want to clean up that appears in the list

To verify this server was removed, type list servers on site, and then press ENTER. Ensure that the domain controller so you wanted to be removed are no longer displayed in the command output. At the metadata Cleanup:and ntdsutil:prompts, type quit.


Forcing the removal of a Domain Controller

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.