AD DS
Transfer or Seize FSMO Roles
Before Doing Anything
- Run "dcdiag" to make sure there are no major problems with the domain.
- Run "netdom /query fsmo" on all DCs to make sure they all agree.
Transferring FSMO roles to a new DC
Open Admin CMD
- ntdsutil
- roles
- connections
- connect to server [server name] <- the server you want to transfer the roles to
- q
- Transfer infrastructure master
- Transfer naming master
- Transfer PDC
- Transfer RID master
- Transfer schema master
- q
- connections
- q
- roles
- exit
Seize FSMO roles to a new DC
It is preferable to transfer FSMO roles over Seizing them, however, if the old FSMO DC is no longer active/bootable, you will need to Seize. If that's the case, never reconnect the old FSMO server after roles have been seized.
The process is the same as above but replace "Transfer" with "Seize".
For a more detailed article go here:
Repair Trust Relationship
To repair Trust Relationship for a computer on domain:
Test-ComputerSecureChannel -Repair -Credential (get-credential)
To test:
Test-ComputerSecureChannel
dc health
Replication health
repadmin /replsummary
repadmin /showrepl *
Domain health
General summary
dcdiag
Comprehensive test suit
dcdiag /c /v
Indivual test
dcdiag /test:dns /v
Clean up old servers
Domain Controllers
- Open dssite.msc -> Sites -> Default-First-Site-Name -> Servers
- Delete old servers
Certificate Authority
- Open dssite.msc
- View -> Show Services
- Services -> Public Key Services
- Delete old server from:
- AIA
- CDP
- Certificate Authorities
- Enrollment Services
- KRA
DNS
Run:
Get-DnsServerResourceRecord -ZoneName "_msdcs.your.domain"
Look through records to make sure no old servers are in there. Use DNS manager to remove any that shouldn't be there.
DHCP
Get-DhcpServerInDC
Get-DhcpServerv4OptionValue -ScopeId 10.1.1.0