How to Use This Checklist
Work through each section in order. Every item must be complete before moving to the next section. Do not skip pre-demotion steps — most post-demotion cleanup headaches come from rushing this phase.
Phase 1 — Pre-Demotion
FSMO Roles
# Check which FSMO roles this DC holds netdom query fsmo
- ☐ Schema Master — transfer if held by this DC
- ☐ Domain Naming Master — transfer if held by this DC
- ☐ PDC Emulator — transfer if held by this DC
- ☐ RID Master — transfer if held by this DC
- ☐ Infrastructure Master — transfer if held by this DC
# Transfer all roles to TARGETDC Move-ADDirectoryServerOperationMasterRole -Identity TARGETDC ` -OperationMasterRole SchemaMaster,DomainNamingMaster,PDCEmulator,RIDMaster,InfrastructureMaster
Global Catalog
Get-ADDomainController -Identity DCTOREMOVE | Select IsGlobalCatalog
- ☐ If IsGlobalCatalog = True — verify another DC in the same site is a GC before proceeding
- ☐ Confirm GC role on target DC:
nltest /dsgetdc:corp.local /gc
Replication Health
repadmin /replsummary repadmin /showrepl dcdiag /test:Replications
- ☐ repadmin /replsummary shows 0 failures
- ☐ dcdiag /test:Replications passes on all DCs
- ☐ No replication errors older than 1 hour
Force Final Sync
# Sync all changes off this DC before demotion repadmin /syncall /AdeP
- ☐ Sync completed with no errors
DNS
# Verify another DC is serving DNS for the domain Resolve-DnsName corp.local -Type SOA
- ☐ At least one other DC is configured as DNS server
- ☐ Client DNS settings updated to point to remaining DCs
Phase 2 — Demotion
# Run on the DC being decommissioned Uninstall-ADDSDomainController ` -DemoteOperationMasterRole:$false ` -RemoveApplicationPartition:$true ` -Confirm:$false
- ☐ Set a local administrator password when prompted
- ☐ Server reboots automatically — let it complete
- ☐ Server comes back as a standalone/member server (no longer a DC)
Phase 3 — Post-Demotion Cleanup
Remove Computer Account from AD
# Run on a healthy DC Get-ADComputer -Identity DCTOREMOVE | Remove-ADObject -Recursive -Confirm:$false
- ☐ Computer account removed from Domain Controllers OU
Remove from AD Sites and Services
dssite.msc # Navigate: Sites → [Site] → Servers → DCTOREMOVE # Delete NTDS Settings first, then the server object
- ☐ NTDS Settings object deleted
- ☐ Server object deleted from Sites and Services
DNS Cleanup
# Remove A record from forward zone
Remove-DnsServerResourceRecord -ZoneName "corp.local" -Name "DCTOREMOVE" -RRType A -Force
# Remove from _msdcs zone
Remove-DnsServerResourceRecord -ZoneName "_msdcs.corp.local" -Name "DCTOREMOVE" -RRType A -Force -ErrorAction SilentlyContinue
# Check for orphaned SRV records
Get-DnsServerResourceRecord -ZoneName "corp.local" -RRType SRV |
Where-Object {$_.RecordData.NameTarget -like "*DCTOREMOVE*"} |
Remove-DnsServerResourceRecord -Force
# Re-register surviving DCs
net stop netlogon && net start netlogon
- ☐ A record removed from forward lookup zone
- ☐ A record removed from _msdcs zone
- ☐ No orphaned SRV records remain
- ☐ Netlogon restarted on surviving DCs
Phase 4 — Final Verification
# Run on a healthy DC — all should pass dcdiag /test:Replications /e dcdiag /test:FSMOCheck /e dcdiag /test:DNS /e # Replication summary — no errors, no reference to old DC repadmin /replsummary repadmin /showrepl | findstr /i "DCTOREMOVE" # Should return nothing # Confirm FSMO roles on healthy DCs netdom query fsmo
- ☐ dcdiag /test:Replications passes
- ☐ dcdiag /test:FSMOCheck passes
- ☐ dcdiag /test:DNS passes
- ☐ repadmin /replsummary shows 0 failures
- ☐ Old DC name does not appear in repadmin /showrepl
- ☐ All FSMO roles held by healthy DCs
- ☐ Server powered off (keep in hypervisor for 30 days before deleting)