Skip to content
On-prem & HybridGuide

Domain Controller Decommission Checklist — Every Step in Order

A printable phase-by-phase checklist for decommissioning a domain controller properly. Pre-demotion, demotion, post-demotion cleanup, and final verification — every checkbox in the right order.

How to Use This Checklist

Work through each section in order. Every item must be complete before moving to the next section. Do not skip pre-demotion steps — most post-demotion cleanup headaches come from rushing this phase.

Before you startPrint this page or open it on a second screen. You need domain admin rights and access to a healthy DC to run these commands. Do not run them on the DC you're decommissioning.

Phase 1 — Pre-Demotion

FSMO Roles

# Check which FSMO roles this DC holds
netdom query fsmo
  • ☐ Schema Master — transfer if held by this DC
  • ☐ Domain Naming Master — transfer if held by this DC
  • ☐ PDC Emulator — transfer if held by this DC
  • ☐ RID Master — transfer if held by this DC
  • ☐ Infrastructure Master — transfer if held by this DC
# Transfer all roles to TARGETDC
Move-ADDirectoryServerOperationMasterRole -Identity TARGETDC `
  -OperationMasterRole SchemaMaster,DomainNamingMaster,PDCEmulator,RIDMaster,InfrastructureMaster

Global Catalog

Get-ADDomainController -Identity DCTOREMOVE | Select IsGlobalCatalog
  • ☐ If IsGlobalCatalog = True — verify another DC in the same site is a GC before proceeding
  • ☐ Confirm GC role on target DC: nltest /dsgetdc:corp.local /gc

Replication Health

repadmin /replsummary
repadmin /showrepl
dcdiag /test:Replications
  • ☐ repadmin /replsummary shows 0 failures
  • ☐ dcdiag /test:Replications passes on all DCs
  • ☐ No replication errors older than 1 hour

Force Final Sync

# Sync all changes off this DC before demotion
repadmin /syncall /AdeP
  • ☐ Sync completed with no errors

DNS

# Verify another DC is serving DNS for the domain
Resolve-DnsName corp.local -Type SOA
  • ☐ At least one other DC is configured as DNS server
  • ☐ Client DNS settings updated to point to remaining DCs

Phase 2 — Demotion

# Run on the DC being decommissioned
Uninstall-ADDSDomainController `
  -DemoteOperationMasterRole:$false `
  -RemoveApplicationPartition:$true `
  -Confirm:$false
  • ☐ Set a local administrator password when prompted
  • ☐ Server reboots automatically — let it complete
  • ☐ Server comes back as a standalone/member server (no longer a DC)
If demotion failsCheck that another DC is reachable, DNS is working, and no FSMO roles are still held by this DC. Fix the error before retrying — do not force-demote unless the DC is being decommissioned permanently and cannot be recovered.

Phase 3 — Post-Demotion Cleanup

Remove Computer Account from AD

# Run on a healthy DC
Get-ADComputer -Identity DCTOREMOVE | Remove-ADObject -Recursive -Confirm:$false
  • ☐ Computer account removed from Domain Controllers OU

Remove from AD Sites and Services

dssite.msc
# Navigate: Sites → [Site] → Servers → DCTOREMOVE
# Delete NTDS Settings first, then the server object
  • ☐ NTDS Settings object deleted
  • ☐ Server object deleted from Sites and Services

DNS Cleanup

# Remove A record from forward zone
Remove-DnsServerResourceRecord -ZoneName "corp.local" -Name "DCTOREMOVE" -RRType A -Force

# Remove from _msdcs zone
Remove-DnsServerResourceRecord -ZoneName "_msdcs.corp.local" -Name "DCTOREMOVE" -RRType A -Force -ErrorAction SilentlyContinue

# Check for orphaned SRV records
Get-DnsServerResourceRecord -ZoneName "corp.local" -RRType SRV |
  Where-Object {$_.RecordData.NameTarget -like "*DCTOREMOVE*"} |
  Remove-DnsServerResourceRecord -Force

# Re-register surviving DCs
net stop netlogon && net start netlogon
  • ☐ A record removed from forward lookup zone
  • ☐ A record removed from _msdcs zone
  • ☐ No orphaned SRV records remain
  • ☐ Netlogon restarted on surviving DCs

Phase 4 — Final Verification

# Run on a healthy DC — all should pass
dcdiag /test:Replications /e
dcdiag /test:FSMOCheck /e
dcdiag /test:DNS /e

# Replication summary — no errors, no reference to old DC
repadmin /replsummary
repadmin /showrepl | findstr /i "DCTOREMOVE"  # Should return nothing

# Confirm FSMO roles on healthy DCs
netdom query fsmo
  • ☐ dcdiag /test:Replications passes
  • ☐ dcdiag /test:FSMOCheck passes
  • ☐ dcdiag /test:DNS passes
  • ☐ repadmin /replsummary shows 0 failures
  • ☐ Old DC name does not appear in repadmin /showrepl
  • ☐ All FSMO roles held by healthy DCs
  • ☐ Server powered off (keep in hypervisor for 30 days before deleting)
DoneAll boxes checked means the decommission is complete. Keep the VM powered off but intact for 30 days as a recovery option before permanently deleting it.
// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.