Tuesday, November 7, 2017

 

[ActiveDirectory] ntdsutil을 통한 orphaned Domain 삭제 실패시 조치사항(dcpromo /forceremoval)



ntdsutil을 통한 orphaned Domain 삭제 실패시 조치사항(dcpromo /forceremoval)




[Explanation]

더이상 사용하지 않는(orphanded) Domain을 삭제하기 위해서 우선 dcpromo를 진행하여 진행하려고 하였지만 PDC와 CDC간의 통신이 원활하지 않아서 정상적인 수행이 되지 않았다. 에러는 아래와 같이 'Logon Failure : The target account name is incorrect'

그래서 ntdsutil을 실행하여 재시도하였지만 중간에 'To properly remove the requested server from Active Directory Domain Services, please connect to a server in the domain Domain11.Contoso.com'오류가 발생하였다. 관련해서 구글링을 하여 다음 링크를 통해서 'dcpromo /forceremoval'에 대해 알 수 있었다. 
C:\Windows\system32>ntdsutil
ntdsutil: metadata cleanup
metadata cleanup: connections
server connections: connect to server pdc00
Binding to pdc00 ...
Connected to pdc00 using credentials of locally logged on user.
server connections: q
metadata cleanup: select operation target
select operation target: list domains
Found 13 domain(s)
0 - DC=Contoso,DC=com
1 - DC=Domain1,DC=Contoso,DC=com
2 - DC=Domain2,DC=Contoso,DC=com
3 - DC=Domain3,DC=Contoso,DC=com
4 - DC=Domain4,DC=Contoso,DC=com
5 - DC=Domain5,DC=Contoso,DC=com
6 - DC=Domain6,DC=Contoso,DC=com
7 - DC=Domain7,DC=Contoso,DC=com
8 - DC=Domain8,DC=Contoso,DC=com
9 - DC=Domain9,DC=Contoso,DC=com
10 - DC=Domain10,DC=Contoso,DC=com
11 - DC=Domain11,DC=Contoso,DC=com
12 - DC=Domain12,DC=Contoso,DC=com
select operation target: select domain 11
No current site
Domain - DC=Domain11,DC=Contoso,DC=com
No current server
No current Naming Context
select operation target: list site
Found 13 site(s)
0 - CN=LCN-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
1 - CN=Domain1-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
2 - CN=Domain2-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
3 - CN=GSS-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
4 - CN=Domain4-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
5 - CN=Domain5-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
6 - CN=Domain6-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
7 - CN=Domain7-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
8 - CN=Domain8-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
9 - CN=Domain9-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
10 - CN=Domain10-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
11 - CN=Domain11-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
12 - CN=Domain12-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
select operation target: select site 11
Site - CN=Domain11-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
Domain - DC=Domain11,DC=Contoso,DC=com
No current server
No current Naming Context
select operation target: list servers in site
Found 1 server(s)
0 - CN=Domain11SCCDC01V,CN=Servers,CN=Domain11-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
select operation target: select server 0
Site - CN=Domain11-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
Domain - DC=Domain11,DC=Contoso,DC=com
Server - CN=Domain11SCCDC01V,CN=Servers,CN=Domain11-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
        DSA object - CN=NTDS Settings,CN=Domain11SCCDC01V,CN=Servers,CN=Domain11-IDC,CN=Sites,CN=Configuration,DC=Contoso,DC=com
        DNS host name - Domain11SCCDC01V.Domain11.Contoso.com
        Computer object - CN=Domain11SCCDC01V,OU=Domain ControlDomain7s,DC=Domain11,DC=Contoso,DC=com
No current Naming Context
select operation target: q
metadata cleanup: remove selected server
To properly remove the requested server from Active Directory Domain Services, please connect to a server in the domain Domain11.Contoso.com; for example \\Domain11SCCDC01V.Domain11.Contoso.com.

dcpromo /forceremoval 에 대한 가이드는 링크를 통해서 확인 할 수 있지만 사용자 UI에 따른 절차는 아래와 같으니 하나하나 따라하면 된다. 하면서 이렇게 많은 경고문은 정말... 하면서도 스릴을 넘치게 한다. ㅎㅎ


















♔♔♔♔♔♔♔♔♔♔


댓글이나 의견은 언제든지 환영합니다.

Your Comments are Always Welcome!
Share:

0 comments:

Post a Comment