AD DS

Transfer or Seize FSMO Roles

Before Doing Anything

  1. Run "dcdiag" to make sure there are no major problems with the domain.
  2. Run "netdom /query fsmo" on all DCs to make sure they all agree.

Transferring FSMO roles to a new DC

Open Admin CMD

  • ntdsutil
    • roles
      • connections
        • connect to server [server name] <- the server you want to transfer the roles to
        • q
      • Transfer infrastructure master
      • Transfer naming master
      • Transfer PDC
      • Transfer RID master
      • Transfer schema master
      • q
    • q
  • exit

Seize FSMO roles to a new DC

It is preferable to transfer FSMO roles over Seizing them, however, if the old FSMO DC is no longer active/bootable, you will need to Seize. If that's the case, never reconnect the old FSMO server after roles have been seized.

The process is the same as above but replace "Transfer" with "Seize".

For a more detailed article go here:

https://support.microsoft.com/en-au/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control

Repair Trust Relationship

To repair Trust Relationship for a computer on domain:

Test-ComputerSecureChannel -Repair -Credential (get-credential)

To test:

Test-ComputerSecureChannel

dc health

Replication health

repadmin /replsummary

repadmin /showrepl *

Domain health

General summary

dcdiag

Comprehensive test suit

dcdiag /c /v

Indivual test

dcdiag /test:dns /v

Clean up old servers

Domain Controllers

  1. Open dssite.msc -> Sites -> Default-First-Site-Name -> Servers
  2. Delete old servers

Certificate Authority

  1. Open dssite.msc
  2. View -> Show Services
  3. Services -> Public Key Services
  4. Delete old server from:
    • AIA
    • CDP
    • Certificate Authorities
    • Enrollment Services
    • KRA

DNS

Run:

Get-DnsServerResourceRecord -ZoneName "_msdcs.your.domain"

Look through records to make sure no old servers are in there. Use DNS manager to remove any that shouldn't be there.

DHCP

Get-DhcpServerInDC

Get-DhcpServerv4OptionValue -ScopeId 10.1.1.0