{"id":436,"date":"2008-04-27T17:41:00","date_gmt":"2008-04-27T16:41:00","guid":{"rendered":"https:\/\/www.networknet.nl\/apps\/wp\/archives\/436"},"modified":"2008-04-27T17:48:28","modified_gmt":"2008-04-27T16:48:28","slug":"remove-active-directory-without-replication","status":"publish","type":"post","link":"https:\/\/www.networknet.nl\/apps\/wp\/archives\/436","title":{"rendered":"Remove Active Directory without replication"},"content":{"rendered":"<p>Couple minutes ago I initiated the remove of Active Directory and forced the demotion of a virtual machine domain controller. The domain controller exceed the 60day not being able to replicate and I was not able to get the replication working. It took me more than 90 minutes to troubleshoot and fix the problem. Since Windows 2003 there is option in the dcpromo tool to force the Active Directory removal.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<div id=\"gsfx_brnd_PageContainer\" style=\"height: 873px\">\n<div class=\"gsfx_brnd_TransBG gsfx_brnd_SideBorder\">\n<div id=\"contentArea\" style=\"height: 692px\">\n<blockquote>\n<div id=\"mainRow\">\n<div class=\"primaryTable\">\n<table class=\"primaryTable\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"primaryMainColumn\">\n<div id=\"mainColumn\">\n<div class=\"kb\" id=\"kb\">\n<div class=\"default\" id=\"default\">\n<div class=\"section\">\n<div class=\"sbody\">\n<table class=\"list ol\">\n<tbody>\n<tr>\n<td class=\"number\">1.<\/td>\n<td class=\"text\">By default, Windows Server 2003 domain controllers support forced demotion. Click <strong class=\"uiterm\">Start<\/strong>, click <strong class=\"uiterm\">Run<\/strong>, and then type the following command:  <\/p>\n<div class=\"indent\"><span class=\"userInput\">dcpromo \/forceremoval<\/span><\/div>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"number\">2.<\/td>\n<td class=\"text\">Click <strong class=\"uiterm\">OK<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td class=\"number\">3.<\/td>\n<td class=\"text\">At the <strong class=\"uiterm\">Welcome to the Active Directory Installation Wizard<\/strong> page, click <strong class=\"uiterm\">Next<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td class=\"number\">4.<\/td>\n<td class=\"text\">At the <strong class=\"uiterm\">Force the Removal of Active Directory<\/strong> page, click <strong class=\"uiterm\">Next<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td class=\"number\">5.<\/td>\n<td class=\"text\">In <strong class=\"uiterm\">Administrator Password<\/strong>, type the password and confirmed password that you want to assign to the Administrator account of the local SAM database, and then click <strong class=\"uiterm\">Next<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td class=\"number\">6.<\/td>\n<td class=\"text\">In <strong class=\"uiterm\">Summary<\/strong>, click <strong class=\"uiterm\">Next<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td class=\"number\">7.<\/td>\n<td class=\"text\">Perform a metadata cleanup for the demoted domain controller on a surviving domain controller in the forest. <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<\/blockquote>\n<div class=\"primaryTable\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"435\" alt=\"2008-04-27_182818\" src=\"https:\/\/www.networknet.nl\/apps\/wp\/wp-content\/uploads\/RemoveActiveDirectorywithoutreplication_10496\/20080427_182818.png\" width=\"557\" border=\"0\"> <\/div>\n<\/div>\n<\/div>\n<p>Reboot the server and cleanup the metadata with ntdsutil. I hate to use workaround like this, but there is not quick and dirty fix for me now. I am planning and testing to upgrade my Exchange 2007 server to SP1, but because the replication to the second dc did not take place for more than 60days the replication stopped.<\/p>\n<p>One of the Errors on my primary domain controller. Demote didn&#8217;t work with force removal and option 3 also did not fix the problem when using the registry fix.<\/p>\n<blockquote>\n<p>Event Type:&nbsp;&nbsp;&nbsp; Error<br \/>Event Source:&nbsp;&nbsp;&nbsp; NTDS Replication<br \/>Event Category:&nbsp;&nbsp;&nbsp; Replication <br \/>Event ID:&nbsp;&nbsp;&nbsp; 2042<br \/>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4\/27\/2008<br \/>Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5:18:39 PM<br \/>User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NT AUTHORITY\\ANONYMOUS LOGON<br \/>Computer:&nbsp;&nbsp;&nbsp; NET-DC-01<br \/>Description:<br \/>It has been too long since this machine last replicated with the named source machine. The time between replications with this source has exceeded the tombstone lifetime. Replication has been stopped with this source. <br \/>The reason that replication is not allowed to continue is that the two machine&#8217;s views of deleted objects may now be different. The source machine may still have copies of objects that have been deleted (and garbage collected) on this machine. If they were allowed to replicate, the source machine might return objects which have already been deleted. <br \/>Time of last successful replication:<br \/>2008-01-26 20:26:04 <br \/>Invocation ID of source: <br \/>01dcf6c8-f6b8-01dc-0100-000000000000 <br \/>Name of source: <br \/>e02a9b21-b7e0-4be6-9cc9-971b00325f65._msdcs.Networknet.nl <br \/>Tombstone lifetime (days): <br \/>60 <br \/>The replication operation has failed.<br \/>User Action:<br \/>Determine which of the two machines was disconnected from the forest and is now out of date. You have three options: <br \/>1. Demote or reinstall the machine(s) that were disconnected. <br \/>2. Use the &#8220;repadmin \/removelingeringobjects&#8221; tool to remove inconsistent deleted objects and then resume replication. <br \/>3. Resume replication. Inconsistent deleted objects may be introduced. You can continue replication by using the following registry key. Once the systems replicate once, it is recommended that you remove the key to reinstate the protection. <br \/> Registry Key:<br \/>HKLM\\System\\CurrentControlSet\\Services\\NTDS\\Parameters\\Allow Replication With Divergent and Corrupt Partner <\/p>\n<p>For more information, see Help and Support Center at <a href=\"http:\/\/go.microsoft.com\/fwlink\/events.asp\">http:\/\/go.microsoft.com\/fwlink\/events.asp<\/a>.<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>For more information check the knowledge base <a href=\"http:\/\/support.microsoft.com\/kb\/332199\" target=\"_blank\">article<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Couple minutes ago I initiated the remove of Active Directory and forced the demotion of a virtual machine domain controller. The domain controller exceed the 60day not being able to replicate and I was not able to get the replication working. It took me more than 90 minutes to troubleshoot and fix the problem. Since Windows 2003 there is option in the dcpromo tool to force the Active Directory removal. &nbsp; 1. By default, Windows Server 2003 domain controllers support forced demotion. Click Start, click Run, and then type the following command: dcpromo \/forceremoval 2. Click OK. 3. At the Welcome to the Active Directory Installation Wizard page, click Next. 4. At the Force the Removal of Active Directory page, click Next. 5. In Administrator Password, type the password and confirmed password that you want to assign to the Administrator account of the local SAM database, and then click Next. 6. In Summary, click Next. 7. Perform a metadata cleanup for the demoted domain controller on a surviving domain controller in the forest. Reboot the server and cleanup the metadata with ntdsutil. I hate to use workaround like this, but there is not quick and dirty fix for me now. I am planning and testing to upgrade my Exchange 2007 server to SP1, but because the replication to the second dc did not take place for more than 60days the replication stopped. One of the Errors on my primary domain controller. Demote didn&#8217;t work with force removal and option 3 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[89,307,247,360,336,361,236],"class_list":["post-436","post","type-post","status-publish","format-standard","hentry","category-windows-active-directory","tag-error","tag-fix","tag-guest","tag-kb332199","tag-machine","tag-replication","tag-virtual"],"_links":{"self":[{"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/posts\/436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/comments?post=436"}],"version-history":[{"count":0,"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/posts\/436\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/media?parent=436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/categories?post=436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.networknet.nl\/apps\/wp\/wp-json\/wp\/v2\/tags?post=436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}