JSI Tip 6166. You cannot manually remove a domain from the forest?

Jerold Schulman

January 1, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

In tip 4984, Microsoft detailed how to remove data in the Active Directory after an unsuccessful domain controller demotion.

In tip 3425, I described how to remove an orphaned domain from Active Directory without demoting the domain controllers.

If you attempt to use adsiedit.msc or ldp.exe to manually remove a domain from the forest, you receive:

Using ADSI Edit:

A referral was returned from the server.

Using ldp.exe:

Error 10: Referral deleted zero entries.

These errors will occur if a domain controller retains the schema master or the domain naming master Flexible Single Master Operation (FSMO) roles.

To fix the problem:

1. On each domain controller for the deleted domain, open a CMD prompt.

2. Type Dcdiag /test:KnowsOfRoleHolders /v and press Enter.

3. Seize any FSMO roles that are still held by the domain controller for the deleted domain.

4. To verify FSMO role holders in the forest, type Dcdiag /test:KnowsOfRoleHolders /v and press Enter.

NOTE: See Using Ntdsutil to remove a non-existant domain generates 'DsRemoveDsDomainW error'?



Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like