Domain Controller

%3CLINGO-SUB%20id%3D%22lingo-sub-1206627%22%20slang%3D%22fr-FR%22%3EDomain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1206627%22%20slang%3D%22fr-FR%22%3E%3CP%3Ehello%2C%3C%2FP%3E%3CP%3Efollowing%20a%20migration%20error%2C%20demote%20the%202008%20R2%20domain%20controller%20to%20Windows%202016%2C%20unable%20to%20connect%20AD%20DC%20on%20the%20new%202016%20server.%20%3CBR%20%2F%3Ecan%20we%20recreate%20the%20domain%20controller%3F%26nbsp%3Bform%20domain%20controller%202008%20R2%20is%20deleted.%3C%2FP%3E%3CP%3EThank%20you%20in%20advance%20for%20your%20assistance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1211589%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1211589%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F573301%22%20target%3D%22_blank%22%3E%40Sambath0204%3C%2FA%3EDo%20you%20still%20have%20a%20working%20domain%3F%20Or%20have%20you%20lost%20all%20your%20domain%20controllers%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1211642%22%20slang%3D%22fr-FR%22%3ERe%3A%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1211642%22%20slang%3D%22fr-FR%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F213341%22%20target%3D%22_blank%22%3E%40Mark%20Lewis%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eold%20has%20been%20deleted%2C%20I%20have%20no%20other%20domain.%20but%20when%20I%20want%20to%20create%20again%20there%20is%20a%20message%20that%20the%20domain%20exists...%3C%2FP%3E%3CP%3EThanks%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1218396%22%20slang%3D%22pt-BR%22%3ERe%3A%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1218396%22%20slang%3D%22pt-BR%22%3EYou%20can%20try%20to%20clean%20metadata%20server.%20%3CBR%20%2F%3E%3CBR%20%2F%3EClean%20up%20server%20metadata%3CBR%20%2F%3Eusing%20the%20command%20line%20As%20an%20alternative%2C%20you%20can%20clean%20up%20metadata%20by%20using%20Ntdsutil.exe%2C%20a%20command-line%20tool%20that%20is%20automatically%20installed%20on%20all%20domain%20controllers%20and%20servers%20that%20have%20Active%20Directory%20Lightweight%20Directory%20Services%20(AD%20LDS)%20installed.%20Ntdsutil.exe%20is%20also%20available%20on%20computers%20that%20have%20RSAT%20installed.%20%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20clean%20up%20server%20metadata%3CBR%20%2F%3Eby%20using%20Ntdsutil%20Open%20a%20command%20prompt%20as%20an%20administrator%3A%20On%20the%20Start%20menu%2C%20right-click%20Command%20Prompt%2C%20and%20then%20click%20Run%20as%20administrator.%20If%20the%20User%20Account%20Control%20dialog%20box%20appears%2C%20provide%20credentials%20of%20an%20Enterprise%20Administrator%20if%20required%2C%20and%20then%20click%20Continue.%20%3CBR%20%2F%3E%3CBR%20%2F%3EAt%20the%20command%20prompt%2C%20type%20the%20following%3CBR%20%2F%3E%3CBR%20%2F%3Ecommand%2C%3CBR%20%2F%3E%3CBR%20%2F%3Eand%20then%20press%20ENTER%3A%20ntdsutil%20At%20the%20ntdsutil%3A%20prompt%2C%20type%20the%20following%20command%2C%20and%20then%20press%20ENTER%3A%3CBR%20%2F%3E%3CBR%20%2F%3Emetadata%20cleanup%3A%3CBR%20%2F%3E%3CBR%20%2F%3Eprompt%20type%20the%20following%20command%2C%20and%20then%20press%20ENTER%3A%3CBR%20%2F%3E%3CBR%20%2F%3Eremove%20selected%20server%20%3CSERVERNAME%3E%20%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20Server%20Remove%20Configuration%20Dialog%2C%20review%20the%20information%20and%20warning%2C%20and%20then%20click%20Yes%20to%20remove%20the%20server%20object%20and%20metadata.%3CBR%20%2F%3E%3CBR%20%2F%3E%20At%20this%20point%2C%20Ntdsutil%20confirms%20that%20the%20domain%20controller%20was%20successfully%20removed.%3C%2FSERVERNAME%3E%20If%20you%20receive%20an%20error%20message%20that%20indicates%20that%20the%20object%20cannot%20be%20found%2C%20the%20domain%20controller%20might%20have%20been%20removed%20earlier.%20%3CBR%20%2F%3E%3CBR%20%2F%3EAt%20the%20metadata%20cleanup%3A%20and%20ntdsutil%3A%20prompts%2C%20type%20quit%2C%20and%20then%20press%20ENTER.%20%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20confirm%20removal%20of%3CBR%20%2F%3E%3CBR%20%2F%3Ethe%20domain%20controller%3A%20Open%20Active%20Directory%20Users%20and%20Computers.%20In%20the%20domain%20of%20the%20removed%20domain%20controller%2C%20click%20Domain%20Controllers.%20In%20the%20details%20pane%2C%20an%20object%20for%20the%20domain%20controller%20that%20you%20removed%20should%20not%20appear.%20%3CBR%20%2F%3E%3CBR%20%2F%3EOpen%20Active%20Directory%20Sites%20and%20Services.%20Navigate%20to%20the%20Servers%20container%20and%20confirm%20that%20the%20server%20object%20for%20the%20domain%20controller%20that%20you%20removed%20does%20not%20contain%20an%20NTDS%20Settings%20object.%20If%20no%20child%20objects%20appear%20below%20the%20server%20object%2C%20you%20can%20delete%20the%20server%20object.%20If%20a%20child%20object%20appears%2C%20do%20not%20delete%20the%20server%20object%20because%20another%20application%20is%20using%20the%20object.%20For%20more%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-ds%2Fdeploy%2Fad-ds-metadata-cleanup%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-ds%2Fdeploy%2Fad-ds-metadata-cleanup%3C%2FA%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1219226%22%20slang%3D%22fr-FR%22%3ERe%3A%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1219226%22%20slang%3D%22fr-FR%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F69059%22%20target%3D%22_blank%22%3E%40Erick%20Garcia%20Godoy%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%20I%20will%20try....%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

hello,

following a migration error, demote the 2008 R2 domain controller to Windows 2016, unable to connect AD DC on the new 2016 server.
can we recreate the domain controller ? former domain controller 2008 R2 is deleted.

Thank you in advance for your assistance.

4 Replies
Highlighted

@Sambath0204Do you still have a working domain? Or have you lost all your domain controllers?

Highlighted

@Mark Lewis 

old has been deleted, I have no other domain. but when I want to create again there is a message that the domain exists...

Thanks in advance.

Highlighted
You can try to clean metadata server.

Clean up server metadata using the command line
As an alternative, you can clean up metadata by using Ntdsutil.exe, a command-line tool that is installed automatically on all domain controllers and servers that have Active Directory Lightweight Directory Services (AD LDS) installed. Ntdsutil.exe is also available on computers that have RSAT installed.

To clean up server metadata by using Ntdsutil
Open a command prompt as an administrator: On the Start menu, right-click Command Prompt, and then click Run as administrator. If the User Account Control dialog box appears, provide credentials of an Enterprise Administrator if required, and then click Continue.

At the command prompt, type the following command, and then press ENTER:

ntdsutil

At the ntdsutil: prompt, type the following command, and then press ENTER:

metadata cleanup

At the metadata cleanup: prompt, type the following command, and then press ENTER:

remove selected server <ServerName>

In Server Remove Configuration Dialog, review the information and warning, and then click Yes to remove the server object and metadata.

At this point, Ntdsutil confirms that the domain controller was removed successfully. If you receive an error message that indicates that the object cannot be found, the domain controller might have been removed earlier.

At the metadata cleanup: and ntdsutil: prompts, type quit, and then press ENTER.

To confirm removal of the domain controller:

Open Active Directory Users and Computers. In the domain of the removed domain controller, click Domain Controllers. In the details pane, an object for the domain controller that you removed should not appear.

Open Active Directory Sites and Services. Navigate to the Servers container and confirm that the server object for the domain controller that you removed does not contain an NTDS Settings object. If no child objects appear below the server object, you can delete the server object. If a child object appears, do not delete the server object because another application is using the object.


For more: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup
Highlighted

@Erick Garcia Godoy 

Thanks, I will try....