DNS _sites shows entries of demoted sites and DCs

Daisy Zhou 20,556 Reputation points Microsoft Vendor
2020-07-15T05:33:11.74+00:00

Hi all,
I've demoted several 2003 Servers during the last few months in our customer AD, moved subnets and succesfully deleted sites under ADSS.
So far, so good, but in DNS I can still see entries under _sites and nameserver domain properties tab.
As per the nameserver domain tab, I think they can be deleted as they are unreacheable/unresolvable records, I still got confused though by the _sites entries as some of them are not showing up and some others are still there and they has an entry under _tcp that point at a DC that has never belonged to the sites in object, but has some FSMO rules.
Some interesting points:
repadmin /replsummary doesn't shows any old DC entry
the old DCs are now member servers
I'm somewhat new to advanced DNS management, How I can safely go further from here?
Thanks

Source link:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/4350fd22-e6aa-4e3f-a6eb-4d864f32e269/dns-sites-shows-entries-of-demoted-sites-and-dcs?forum=winserverDS

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,131 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,311 Reputation points Microsoft Vendor
    2020-07-15T05:44:59.593+00:00

    Hi,
    Usually, if we demoted all the DCs successfully through DCpromo, all the DNS entries should be removed automatically.

    If old DNS entries can not be deleted on all the DCs in your AD environment, we need to delete these old DNS entries manually on one of the DCs in one domain.

    If on some DCs, these DNS entries are deleted, but on some DCs, these DNS entries are not deleted, we can wait for AD replication, after all the DCs in the domain are replicated to each other. Then we check if all these old DNS entries are deleted on all DCs in the domain.

    AD-integrated DNS can be replicated between DCs in one domain.

    If we have multiple domains, we need to check one by one.

    0 comments No comments

0 additional answers

Sort by: Most helpful