Using the Ntdsutil utility to remove the only (tombstoned) DC along with an orphaned child domain

Hello experts,
before working on a server consolidation project for a new customer the situation was:
Headquarter (I will not mention file and application servers)
==================================================
- One physical server running Windows Server 2003 R2 Standard Edition acting as a Domain Controller and Global
Catalog, holding the Five FSMO roles and running Microsoft Exchange Server 2003.
==================================================
Branch office (connected to the corporate office by using a persistent site-to-site VPN)
==================================================
- One physical server running Windows Server 2003 R2 Standard Edition acting as a file server and a Domain Controller
in a child domain. Before we started work on the server consolidation project, this Domain controller at the remote site already was tombstoned.
==================================================
After working on the server consolidation project the situation is:
Headquarter
==================================================
- We have added a new VM running Windows Server 2003 R2 Standard Edition acting as a Domain Controller.
- We have added a new VM running Windows Server 2008 R2 Standard Edition running Exchange 2007 Service Pack 3
and successfully migrated Exchange 2003 to 2007. We are ready to remove Exchange 2003 from the old physical server running Windows Server 2003 R2 Standard Edition.
==================================================
Branch office
==================================================
- We have added a new VM running Windows Server 2003 R2 and promoted it to be a new Domain Controller in a new
forest.
- We have turned off the tombstoned Domain Controller after migrating the applications and users to the new domain.
We haven't tried to demote it gracefully because it is totally screwed up
==================================================
In order to decommission the two remaining physical servers (the one acting as a Domain Controller and Global
Catalog, holding the Five FSMO roles and running Microsoft Exchange Server 2003 in the Headquarter and the tombstoned Domain Controller in the Branch office) our plan is to:
==================================================
1. Use the Ntdsutil.exe utility to manually remove the tombstoned Domain Controller in the Branch office.
2. After manually removing the tombstoned Domain Controller in the Branch office (step above), use the Ntdsutil.exe utility
to manually remove the orphaned child domain from Active Directory.
3. Transfer the role of the global catalog and all FSMO roles to the new VM we have added in the Headquarter (It is already
acting as a Domain Controller).
4. Remove Exchange 2003 from and gracefully demote the old physical server running in the Headquarter. ==================================================
Does our plan above make sense to you ? Can someone please explain or provide instructions for step 1 & 2 above ?
I would be very grateful if someone could kindly share some thoughts.
Any help/information will be greatly appreciated.
Regards,
Massimiliano

To remove an orphaned child domain: http://support.microsoft.com/en-us/kb/230306
To do a metadata cleanup: https://technet.microsoft.com/en-us/library/cc816907%28v=ws.10%29.aspx
Your plan is okay. Just make sure that your DCs are in healthy state and AD replication is fine using
dcdiag and repadmin commands before proceeding with demoting. Also, take system state backups before proceeding.
This posting is provided AS IS with no warranties or guarantees , and confers no rights.
Ahmed MALEK
My Website Link
My Linkedin Profile
My MVP Profile
Hello Ahmed,
thank you for your reply to my question.
I have analyzed the replication status for all domain controllers in the Active Directory forest using the Active
Directory Replication Status Tool (ADREPLSTATUS). All DCs are in healthy state and AD replication is fine.
The only replication errors shown in the Active Directory Replication Status Tool are those involving the tombstoned
Domain Controller in the Branch office, so I think it should be safe to go ahead.
It is my understanding that before removing the orphaned child domain I should remove the tombstoned Domain Controller
in the Branch office. Can I refer to the instructions on the following webpage:
==================================================
http://www.petri.com/delete_failed_dcs_from_ad.htm ==================================================
Thank you,
Massimiliano

Similar Messages

  • If I suspend wireless connectivity can I then use the camera connection kit along with the usb ethernet adapter to connect to the internet?

    If I suspend wireless connectivity on my Ipad2, can I then use the camera connection kit alond with the Apple USB Ethernet cable to connect to the internet?

    No, you can't.

  • How to use the database change notification event with an AppModule Child ?

    hi,
    I try to do the same stuff that this "How To" : [http://niallcblogs.blogspot.com/2009/06/auto-refreshing-adf-chart-objects-in.html].
    This example works fine, but I want an Application Module Root which contains the Application Module which contains the VO where there is the method processDatabaseChangeNotification.
    I have trying all the configuration possible of AppModuleRoot and AppModuleChild: Shared/Local, Local/Shared and even Local/Local ... but nothing works ...
    Can you tell me if possible, and if so ... how?
    thanks !
    (I use jdev11g)

    I don't find my reponse in the documentation....
    I have an AM Child in an AM Root like that :
    <AppModuleUsage
    Name="AppModuleChild"
    FullName="model.AppModuleChild"
    ConfigurationName="model.AppModuleChildShared"
    SharedScope="2" />
    My AM Root is Shared in the file "DataBinding.cpx" :
    <BC4JDataControl id="AppModuleRootDataControl" Package="model"
    FactoryClass="oracle.adf.model.bc4j.DataControlFactoryImpl"
    SupportsTransactions="true" SupportsFindMode="true"
    SupportsRangesize="true" SupportsResetState="true"
    SupportsSortCollection="true"
    Configuration="AppModuleRootShared" syncMode="Immediate"
    xmlns="http://xmlns.oracle.com/adfm/datacontrol"/>
    ... and the database change event notification don't work... I don't understand !

  • How can I transfer photos from an IPhone 5 to an IPad 2 using a cable.  I have tried using the lightning to firewire adapter with my current lead but this only seems to allow a download from the Ipad to the Iphone and not the other way around.

    How can I transfer photos from an IPhone 5 to an IPad 2 using a cable.  I have tried using the lightning to firewire adapter with my current lead but this only seems to allow a download from the IPad to the IPhone and not the other way around.

    The devices are not designed for transfer of that kind.  Use Photo Stream as suggested by another poster, or transfer photos to your computer (a good idea anyway since they will be lost if your device needs to be reset), then use iTunes to sync them to the other devices.

  • With my i phone 4 , the Push notifications doesn't work for apps like (fb viber , whatsapp etc ) it only works for the official apps like message  even when im using the phone, has  this probleme with the iOs 6.0.1 and also with the iOs 6.1

    With my i phone 4 , the Push notifications doesn't work for apps like (fb viber , whatsapp etc ) it only works for the official apps like message  even when im using the phone, has  this probleme with the iOs 6.0.1 and also with the iOs 6.1

    This isn't an issue. Notice the screen prior to the one that shows usage has an iCloud section and a Manage Storage button. For this button to activate ios needs to download a few kb from icloud. Switching back to this screen forces ios to download those few kb.

  • I purchase Adobe Elements Photoshop 12 & Premiere 12 together from a camera shop in town.  When I tried to use the Premiere, it splashed "created with the trial verson" over all of the photos. How can this unsightly watermark be removed. It has severely h

    I purchased  Adobe Elements Photoshop 12 & Premiere 12 together from a camera shop in town.  When I tried to use the Premiere, it splashed "created with the trial version" over all of the photos. How can this unsightly watermark be removed. It has severely hampered my timeline to start and finish this project. Why would a purchase software product purport to be a "trial" version?

    This indicator will appear when you have not registered your product or typed in the serial number for the product.
    Once you've added the serial number, any future products will not display this indicator.
    To remove this this indicator from videos created before you added the serial number, you'll need to delete the rendered files.

  • Trying to update iPhoto, tells me to use the account I bought it with.  I only have one account!

    How do I update iPhoto when I get a message saying I must use the account I bought it with.  I only have one account, which I bought it with!!!  How do I sort this out?

    Did you actually buy the app or did it Come free on your Mac when you bought it? Kf it camefree on your Mac, did you sign into your account look on the Purchases pane and except the iLife apps?

  • TS1702 Renewed my subscription with the Sun app, was charged £0.69 but app won't load seem that I am not the only one having issue with this app. How can I claim my money back?

    Renewed my subscription with the Sun app, was charged £0.69 but app won't load seem that I am not the only one having issue with this app. How can I claim my money back?

    It sounds like you may have multiple problems, but none of them are likely to be caused by malware.
    First, the internet-related issues may be related to adware or a network compromise. I tend to lean more towards the latter, based on your description of the problem. See:
    http://www.adwaremedic.com/kb/baddns.php
    http://www.adwaremedic.com/kb/hackedrouter.php
    If investigation shows that this is not a network-specific issue, then it's probably adware. See my Adware Removal Guide for help finding and removing it. Note that you mention AdBlock as if it should have prevented this, but it's important to understand that ad blockers do not protect you against adware in any way. Neither would any kind of anti-virus software, which often doesn't detect adware.
    As for the other issues, it sounds like you've got some serious corruption. I would be inclined to say it sounds like a failing drive, except it sounds like you just got it replaced. How did you get all your files back after the new drive was installed?
    (Fair disclosure: I may receive compensation from links to my sites, TheSafeMac.com and AdwareMedic.com, in the form of buttons allowing for donations. Donations are not required to use my site or software.)

  • How to sync 2 different Mac users using the same Apple ID and with out mixing each other info?

    How to sync 2 different Mac users using the same Apple ID and with out mixing each other info?
    We are two people using three difrent Macs, 1 Iphone and 1 Ipad with separate USERS  on each Mac but sharing the same Apple ID: xxxxxx
    I set up the first user to iCloud and it was OK but when I set up the second user to use iCoud the first users's info gets mixed with the second user's info?
    Do we have to set up a diffrent Apple ID for each other?
    Sometime ago I added my friends E mail (yyyyy) to the main Apple ID (xxxx) as for using his E mail account (to separate our e mail accounts, and it's working ok) but now when I try to create a new apple ID whith the same friend's e mail (yyyyyy)  it says that his mail (yyyyy) is already an apple ID when the Apple ID is really my E mail (xxxxx)... any clue?
    Thanks

    I believe because you migrated from a Nokia to an iPhone you need to register the Bn phone number with your Apple ID so it can be used for iMessage. The Pn number seems to be the only one registered
    Go here > https://appleid.apple.com/cgi-bin/WebObjects/MyAppleId.woa/
    Manage your Apple ID and see if that does the trick
    Hope that helps

  • The first time I connected my new My Passport portable hard drive to my Mac, the message asking if I want to use the drive to back up with Time Machine did not appear.  What is the next step?

    The first time I connected my new My Passport portable hard drive to my MacBook Pro, the message asking if I want to use the drive to back up with Time Machine did not appear.  I would like to set it up to do this.  What would my next step be?

    Drive Partition and Format
    1. Open Disk Utility in your Utilities folder.
    2. After DU loads select your hard drive (this is the entry with the mfgr.'s ID and size) from the left side list. Click on the Partition tab in the DU main window.
    3. Under the Volume Scheme heading set the number of partitions from the drop down menu to one. Click on the Options button, set the partition scheme to GUID then click on the OK button. Set the format type to Mac OS Extended (Journaled.) Click on the Apply button and wait until the process has completed.
    4. Select the volume you just created (this is the sub-entry under the drive entry) from the left side list. Click on the Erase tab in the DU main window.
    5. Set the format type to Mac OS Extended (Journaled.) Click on the Security button, check the button for Zero Data and click on OK to return to the Erase window.
    6. Click on the Erase button. The format process can take up to several hours depending upon the drive size.
    Open Time Machine preferences to select this drive for use as the backup drive. Turn on Time Machine.

  • Why my safari browser is not opening pdf files?I'm currently using the lat 2013 macbook pro with os mavericks and all my software is uptodate?

    Why my safari browser is not opening pdf files?I'm currently using the lat 2013 macbook pro with os mavericks and all my software is uptodate? 

    Back up all data.
    If Adobe Reader or Acrobat is installed, there should be a setting in its preferences such as Display PDF in Browser. I don't use those applications myself, so I can't be more precise. Deselect that setting, if it's selected. Otherwise do as follows.
    Triple-click anywhere in the line of text below on this page to select it, the copy the selected text to the Clipboard by pressing the key combination command-C:
    /Library/Internet Plug-ins
    In the Finder, select
    Go ▹ Go to Folder
    from the menu bar, or press the key combination shift-command-G. Paste into the text box that opens (command-V), then press return.
    From the folder that opens, move to the Trash any items that have "Adobe" or “PDF” in the name. You may be prompted for your login password. Then quit and relaunch Safari, and test.
    The "Silverlight" web plugin distributed by Microsoft can also interfere with PDF display in Safari, so you may need to remove it as well, if it's present. The same goes for a plugin called "iGetter," and perhaps others — I don't have a complete list.
    If you still have the issue, repeat with this line:
    ~/Library/Internet Plug-ins
    If you don’t like the results of this procedure, restore the items from the backup you made before you started. Relaunch Safari again.

  • I have iWork '06 on my Mac (running OS 10.6.8). Will I be able to use the Keynote files it produces with the Keynote iPad app?

    Hi,
    I have iWork '06 on my Mac (running OS 10.6.8). Will I be able to use the Keynote files it produces with the Keynote iPad app?
    Thanks,
    Mark

    You probably can open the Keynote '06 files with Keynote for iOS but not the other way around. Files created by the iOS iWork apps can only be opened by iWork '09 apps on the Mac.

  • Can I use the backups that I made with Leopard ?

    Hi,
    Can I use the backups that I made with Leopard or do I have to re-configure Time Machine again, like it never happened when SL is installed ?
    Sincerely.

    You should only have to worry about doing this, if you choose to erase and install Snow Leopard.
    Snow Leopard by default upgrades your system, and thus a restore would only be necessary in an emergency.

  • 10.5.2: You cannot use the application "System preferences.app" with...

    Hello
    after (successfully) updating from 10.5.1 to 10.5.2, the System Preferences.app cannot be started. Either the application does not start (a silent error) or there is a message "You cannot use the application "System preferences.app" with this version of MacOS X." The version is 10.5.2, according to "About this Mac", while the application version is 3.5. The same happens when I attempt to open "Time machine preferences" using the new menu/icon on the bar.
    Any help is appreciated.
    Thanks in advance,
    Marinho.

    Thanks, I did that, but it didn't solve the problem.
    By the way, the application version (of System preferences.app) remained the same (old one). Then I removed the application to Trash (meaning to restore it later if required) and applied the update again (and a third time), but then a new System preferences.app was not installed and the older one has disappeared from the trash! What a mess this update turns out to be...
    Marinho.

  • Is there a way to use the iMac's display mode with a Mac mini with out logging in first on the Mac mini

    Is there a way to use the iMac's display mode with a Mac mini with out logging in first on the Mac mini (late2014)
    im currently useing my Mac mini as a portable computer, I take it to the university and use the iMacs there as a monitor but before I can do that I have to log in to my Mac mini first which means doing it blind
    is there a way to put the IMacs into display mode with out logging into my Mac mini first
    or is there a portable monitor that I can use that will not require me to login first

    This
    Target Display Mode: Frequently Asked Questions (FAQ) - Apple Support
    says:
    How do I enable TDM?
    Make sure both computers are turned on and awake. 
    Connect a male-to-male Mini DisplayPort or ThunderBolt cable to each computer.
    Press Command-F2 on the keyboard of the iMac being used as a display to enable TDM.
    Note: In Keyboard System Preferences, if the checkbox is enabled for "Use all F1, F2, etc. keys as standard functions keys," the key combination changes to Command-Fn-F2.
    How do I exit TDM?
    To leave TDM, press Command-F2 on the keyboard of the iMac that is in TDM. You can also exit TDM if you shutdown or sleep either computer or detach the cable.
    Can I use a third-party keyboard or older Apple keyboard to enable TDM?
    Some older Apple keyboards and keyboards not made by Apple may not allow Command-F2 to toggle display modes. You should use an aluminum wired or wireless Apple keyboard to toggle TDM on and

Maybe you are looking for

  • ITunes freezes when selecting "Add file to library" or "Add folder....

    Not had a problem before and everything worked fine. But this morning if I select "Add file to library" or "Add folder to library" nothing happens and itunes just freezes. I can play music already in the library. Any ideas?

  • Environment Variables (Urgent)

    Hi everyone, Does any body know how to use environment variable in any application. I am using Oracle 8.1.6 on Windows NT. And I want to use the value of an environment variable in my procedure. Any sooner help will be highly appreciated. Thanks Must

  • Audio distortion caused by 10.6.7 update

    Since updating my 21.5" iMac I get slight distortions whenever moving files, or a web page is loading, basically most any more active actions on the desktop. It occurs with CDs, DVDs, streaming audio, everything. I first noticed it on downloads of ra

  • HT1600 Why do I get update not successful every time I attempt to update?

    Every time I try to update my apple tv, i get the error message at the end that says Update not successful, try again... I am using it on a cable off my router and works perfectly. IE streams Netflix just fine etc.

  • WDS service never starts once DP PXE is enabled

    Hi , I am facing issues with deploying OS through PXE. WDS stop working (not able to start the services) once I enable PXE point on distribution point. I have observed that RemoteTool\SMSBoot\x64 and x86 folders are empty. Its config manager 2012 R2.