Hi Microsoft Community,
I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned.
Current environment
For example, the original AD structure was:
ppp.com ← Original parent / forest root domain
|
└── abc.ppp.com ← Child domain currently in use
The original ppp.com domain has already been decommissioned and is no longer available.
However, when the child domain abc.ppp.com was separated/decommissioned from the parent environment in the past, the process was apparently not completed correctly.
The abc.ppp.com domain is still operational today. Users can authenticate and the domain is generally functioning, but the AD environment appears to retain dependencies on the previous ppp.com forest/root domain.
FSMO situation
The domain-level FSMO roles for abc.ppp.com are available, but the forest-level FSMO roles are still associated with the old environment.
The two important forest-level roles are:
- Schema Master
- Domain Naming Master
Microsoft documentation confirms that Schema Master and Domain Naming Master are forest-wide FSMO roles, rather than domain-specific roles.
The original ppp.com domain/DCs that previously held these roles have already been decommissioned.
Therefore, I am currently unable to perform a normal FSMO transfer.
Enterprise Admins issue
I also found that my current administrative account does not have membership in Enterprise Admins.
This is particularly problematic because Enterprise Admins is a forest-root-domain group and is normally used for forest-wide administrative operations. Microsoft documentation also states that Enterprise Admins exists in the forest root domain.
When I attempted to perform FSMO seizure/recovery, the operation was not successful because my current administrative account does not have the required Enterprise-level permissions.
The problem is that the original forest-root domain ppp.com is no longer available, so I cannot simply log on to the original forest-root domain and use the original Enterprise Admin account/group in the normal way.
My current objective
I am now planning a Tech Refresh of the Active Directory infrastructure.
I want to introduce new Windows Server domain controllers and eventually replace the existing DCs.
However, I do not want to proceed with the migration while the AD forest/domain structure is potentially inconsistent or while the forest-level FSMO roles still reference the old, decommissioned ppp.com environment.
I am therefore trying to determine whether the existing abc.ppp.com environment can be repaired and converted/recovered into a healthy, self-contained AD environment without rebuilding the domain from scratch.
My questions
- Is it possible to recover/fix this existing
abc.ppp.com environment even though the original ppp.com forest-root domain has already been permanently decommissioned?
- Is there a supported Microsoft procedure for recovering the forest-level FSMO roles (Schema Master and Domain Naming Master) when the original forest-root DCs no longer exist?
- Since the original forest-root domain no longer exists, what is the correct way to handle the missing Enterprise Admins group/permissions?
- Can the existing
abc.ppp.com domain be repaired so that it can continue as a healthy AD environment and support a normal DC Tech Refresh?
- Is there a supported way to clean up the old
ppp.com forest/root-domain metadata without rebuilding abc.ppp.com?
- Are there any risks of corrupting the existing AD database, configuration partition, schema partition, trusts, DNS, or replication if I attempt FSMO seizure or metadata cleanup in this situation?
- What information/command output should I provide to determine the exact state of the forest and whether this environment is recoverable?
I would prefer to repair the existing AD environment rather than create a completely new domain, because the current abc.ppp.com domain is still actively used by production systems and users.
I would greatly appreciate advice from anyone with experience handling an orphaned child domain / decommissioned forest-root domain and recovering forest-level FSMO roles before a Windows Server Tech Refresh.
Thank you.Hi Microsoft Community,
I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned.
Current environment
For example, the original AD structure was:
ppp.com ← Original parent / forest root domain
|
└── abc.ppp.com ← Child domain currently in use
The original ppp.com domain has already been decommissioned and is no longer available.
However, when the child domain abc.ppp.com was separated/decommissioned from the parent environment in the past, the process was apparently not completed correctly.
The abc.ppp.com domain is still operational today. Users can authenticate and the domain is generally functioning, but the AD environment appears to retain dependencies on the previous ppp.com forest/root domain.
FSMO situation
The domain-level FSMO roles for abc.ppp.com are available, but the forest-level FSMO roles are still associated with the old environment.
The two important forest-level roles are:
- Schema Master
- Domain Naming Master
Microsoft documentation confirms that Schema Master and Domain Naming Master are forest-wide FSMO roles, rather than domain-specific roles.
The original ppp.com domain/DCs that previously held these roles have already been decommissioned.
Therefore, I am currently unable to perform a normal FSMO transfer.
Enterprise Admins issue
I also found that my current administrative account does not have membership in Enterprise Admins.
This is particularly problematic because Enterprise Admins is a forest-root-domain group and is normally used for forest-wide administrative operations. Microsoft documentation also states that Enterprise Admins exists in the forest root domain.
When I attempted to perform FSMO seizure/recovery, the operation was not successful because my current administrative account does not have the required Enterprise-level permissions.
The problem is that the original forest-root domain ppp.com is no longer available, so I cannot simply log on to the original forest-root domain and use the original Enterprise Admin account/group in the normal way.
My current objective
I am now planning a Tech Refresh of the Active Directory infrastructure.
I want to introduce new Windows Server domain controllers and eventually replace the existing DCs.
However, I do not want to proceed with the migration while the AD forest/domain structure is potentially inconsistent or while the forest-level FSMO roles still reference the old, decommissioned ppp.com environment.
I am therefore trying to determine whether the existing abc.ppp.com environment can be repaired and converted/recovered into a healthy, self-contained AD environment without rebuilding the domain from scratch.
My questions
- Is it possible to recover/fix this existing
abc.ppp.com environment even though the original ppp.com forest-root domain has already been permanently decommissioned?
- Is there a supported Microsoft procedure for recovering the forest-level FSMO roles (Schema Master and Domain Naming Master) when the original forest-root DCs no longer exist?
- Since the original forest-root domain no longer exists, what is the correct way to handle the missing Enterprise Admins group/permissions?
- Can the existing
abc.ppp.com domain be repaired so that it can continue as a healthy AD environment and support a normal DC Tech Refresh?
- Is there a supported way to clean up the old
ppp.com forest/root-domain metadata without rebuilding abc.ppp.com?
- Are there any risks of corrupting the existing AD database, configuration partition, schema partition, trusts, DNS, or replication if I attempt FSMO seizure or metadata cleanup in this situation?
- What information/command output should I provide to determine the exact state of the forest and whether this environment is recoverable?
I would prefer to repair the existing AD environment rather than create a completely new domain, because the current abc.ppp.com domain is still actively used by production systems and users.
I would greatly appreciate advice from anyone with experience handling an orphaned child domain / decommissioned forest-root domain and recovering forest-level FSMO roles before a Windows Server Tech Refresh.
Thank you.