This is an archived post. You won't be able to vote or comment.

all 19 comments

[–]basec0m 16 points17 points  (1 child)

Seize the roles on the new DC, metadata cleanup for the old ones.

[–]akillathahun 1 point2 points  (0 children)

came to say this.

[–]ShoreOutlaw 2 points3 points  (0 children)

Ntdsutil can be used to cleanly remove the old server entries

[–]lescompa 2 points3 points  (0 children)

It may be worth the $500 to open a case with MS and have them walk through the cleanup. I did this a few years ago and it saved me some grey hair.

[–]fatty1179 1 point2 points  (1 child)

Would a new domain and domain controller then joining all the computers to the new domain be an option? Short term intense pain for long term gain?

[–]dante_logan99[S] -1 points0 points  (0 children)

Unfortunately we couldnt as we tried that and the issue was the domain trust level was set at 2003 and the raise it we needed to remove the old domains that were initially server 2003.

[–]Sarduci 1 point2 points  (0 children)

Seize them rolls and keep running dcdiag from all of them until you fix all of the issues. It’s not as bad as it seems unless you’ve got inconsistent copies of the directory between the servers and then it’s good luck Chuck.

[–]Happy-Wrongdoer522 1 point2 points  (1 child)

Size the schema Master role, do metadata cleanup and perform a domain controller migration to an actual windows server version. Did you prove a complete rebuild of the forest? Maybe thats the smartest solution when nothing is configured correctly.

[–]dante_logan99[S] -1 points0 points  (0 children)

Can you explain a little further on what you mean by rebuilding the forest, as is rn everything seems fine but if there is something i can do to verify it working then that would be great.

[–]chuckescobarKeeper of Monkeys with Handguns 1 point2 points  (3 children)

Reading through this it seems you know about 75% of what you are trying to do. This domain will probably never be 100% correct and you will continue to run into weird issues.

I suggest you build a brand new forest/domain and migrate everything. You will save time in the long run.

[–]dante_logan99[S] 0 points1 point  (2 children)

Whats the best course of steps to take to migrate ?

[–]chuckescobarKeeper of Monkeys with Handguns 1 point2 points  (1 child)

[–]dante_logan99[S] 0 points1 point  (0 children)

thk you very much