PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Noms de domaine > ms.public.win.server.dns > Removing Domain Machine Account
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
Removing Domain Machine Account

Réponse
 
LinkBack Outils de la discussion
Vieux 30/08/2006, 13h13   #1
neeraj kashyap
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Removing Domain Machine Account

hi all

I have deleted one of our DC purposly through ntdsutil. Now I want to know
that is it safer to delete all dns records like gc,ldap,kerberos & other in
dns for deleted DC manully.

If there is other way? Pls. tell me


Thanks in advance
  Réponse avec citation
Vieux 30/08/2006, 13h51   #2
Jorge Silva
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Removing Domain Machine Account

Hi
Hi

Assuming that this Dc is an Aditional Dc for an existent domain:

- Disconnect the Dc from network and run dcpromo /forceremoval. If this
Fails and you're running

- Windows 2000, make sure that you install SP4 then try again, if it fails
again then:

Navigate to:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\ProductOptions]
Change "ProductType"="LanmanNT" to "ProductType"="ServerNT"
Follow

Domain controllers do not demote gracefully when you use the Active
Directory Installation Wizard to force demotion in Windows Server 2003 and
in Windows 2000 Server

http://support.microsoft.com/kb/332199/en-us

- Then remove all references to that Dc on AD database (Metadata cleanup).

- Remove any Dns references to the Dc. - nltest /dsderegdns:<dns host name>

- Verify that FRS member objects (FRS and DFS) are removed, and remove them
if they are present.

- If necessary seize any left Op Master roles that were hosted by that Dc.

*Note: The domain controller that seizes the role must be fully up-to-date
with the updates performed on the previous role owner. Because of
replication latency, it is possible that the domain controller might not be
up-to-date. To check the status of updates for a domain controller, use the
Repadmin.exe /Showutdvec switch.

*C:\> repadmin/showutdvec server2. mydomain.com dc= mydomain,dc=com

*C:\> repadmin/showutdvec server3. mydomain.com dc= mydomain,dc=com

- If some discrepancies Use the Repadmin /Syncall switch to make the
replication happen immediately.

- If the domain controller that you are demoting is a DNS server or global
catalog server, you must create a new GC or DNS server to satisfy load
balancing, fault tolerance, and configuration settings in the forest, don't
forget that you need at least one GC per Forest..

-Dont forget to export the *EFS* certificate. If one of these two dcs is
the first dc that was installed in your domain then the EFS certificate
resides locally on that dc. When you remove the dc before you export the
efs certificate you will loose it. Without this certificate you are not
able to recover efs encrypted files.
http://support.microsoft.com/?scid=k...41201&x=5&y=13

- When you use the remove selected server command in NTDSUTIL, the NTDSDSA
object, the parent object for incoming connections to the domain controller
that you forcibly demoted is removed. The command does not remove the parent
server objects that appear in the Sites and Services snap-in. Use the Active
Directory Sites and Services MMC snap-in to remove the server object if the
domain controller will not be promoted into the forest with the same
computer name

Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller

http://support.microsoft.com/kb/255504/

Overview of Active Directory Objects That Are Used by FRS

http://support.microsoft.com/kb/296183/

Wizard to force demotion in Windows Server 2003 and in Windows 2000 Server
http://support.microsoft.com/kb/332199
How to remove data in Active Directory after an unsuccessful domain
controller demotion

http://support.microsoft.com/?kbid=216498

How To Remove Orphaned Domains from Active Directory

http://support.microsoft.com/default...b;en-us;230306

Clean up server metadata

http://technet2.microsoft.com/Window....mspx?mfr=true


--
I hope that the information above s you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"neeraj kashyap" <neerajkashyap@discussions.microsoft.com> wrote in message
news:78E04881-2F31-4B85-9631-021998773807@microsoft.com...
> hi all
>
> I have deleted one of our DC purposly through ntdsutil. Now I want to know
> that is it safer to delete all dns records like gc,ldap,kerberos & other
> in
> dns for deleted DC manully.
>
> If there is other way? Pls. tell me
>
>
> Thanks in advance



  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 12h56.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,09210 seconds with 10 queries