RE: force removal of Domain controllers from AD

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Yup, done all that. Unfortunately a collegue of mine previously removed site
the that contained the offending DC, so it is cannot possibly be listed when
I run ntdsutil.

"johnsanz" wrote:

Have you executed the "ntdsutil metadata cleanup" commands?

If you execute the following commands, do you see the Domain Controller in
question listed?

C:\ntdsutil
ntdsutil: m c
metadata cleanup: c
server connections: connect to server <your_DC>

server connections: q
metadata cleanup: s o t
select operation target: list sites

select operation target: select site <# of site DC existed in>

select operation target: list servers in site
Found X server(s)
0 - CN=....
1 - CN=....
...

Do you see the DC in question in the list above?


John


"jprstokato" wrote:

Hi john,

Thanks for your link.
I had actually read thru it before but didn't go thru the dns steps.
Thats what was blocking deletion.
I have another couple of DCs that are still causing problems with a msg:

"The object <servername> (or some of the objects it contains) cannot be
deleted because: Acces is denied."

Tried changing permissions (and am logged in with all necessary rights), but
still will not delete...any ideas?

"johnsanz" wrote:

Follow the steps outlined in the following MS KB article:

How to remove data in Active Directory after an unsuccessful domain
controller demotion
http://support.microsoft.com/kb/216498/en-us


Best Regards,

John M. Sanz

"Dragos CAMARA" wrote:

hi,
delete from ou=domain controllers, delete from site and services (be aware
to delete from depth of structure until including server name).
run ntdsutil metadata cleanup
chech the fsmo roles and reseize what is necessary (fsmo roles on deleted DC).

--
Dragos CAMARA
MCSA Windows 2003 server


"jprstokato" wrote:

Hi,

We have introduced a DC into our AD for testing purposes.
It has since been removed from the production domain and had FSMO roles
seized separatley so as to implement a completely separate test environment.
As such it is no longer part of the domain nor can it now be reintroduced
(so as to demote in the normal way as necessary).

We need to remove the DC form our production AD, so that it no longer
appears in either dssite.msc or dsa.msc.

All material I have found relates to using dcpromo which is not possible in
our situation.

(I have tried using ntdsuitl (metadata cleanup), which clears it off sites
and services, but DC still remains in dsa.)

Can someone please help and tell me how this can otherwise be done.
Thanks,

John.
MCSE, CCNA.
.



Relevant Pages

  • RE: force removal of Domain controllers from AD
    ... metadata cleanup: s o t ... select operation target: list sites ... to delete from depth of structure until including server name). ... chech the fsmo roles and reseize what is necessary. ...
    (microsoft.public.windows.server.active_directory)
  • Re: FSMO - can I turn on a DC after its PDCe role has been seized?
    ... remove the member server from the domain and then rejoin. ... do a metadata cleanup. ... another domain controller so DHCP could be installed and authorized on ... Do I have to seize the rest of the FSMO roles to the box the PDCe was ...
    (microsoft.public.windows.server.active_directory)
  • Re: domain.local dns forward lookup zone has a red x
    ... When I put the server in place I ... You'll need to first seize the FSMO roles over to the existing DC. ... Cleanup (Metadata Cleanup) the AD database from the crashed DC - How to ...
    (microsoft.public.windows.server.dns)
  • RE: Raising domain level
    ... I would run a DCDiag to look for lost FSMO roles and replication partners ... Remove any DNS records pointing to the old DC -- including the SRV ... Perform a metadata cleanup to remove traces of the old DC from the AD. ... Is there anyway i can raise the current domain level from 2000 server to a ...
    (microsoft.public.windows.server.active_directory)
  • Re: Removing a child domain from the parent
    ... I successfully removed the server with the ... I am trying to run the metadata cleanup. ... server connections: connect to server app1 ... metadata cleanup: select operation target ...
    (microsoft.public.windows.server.setup)