Need help recovering an orphaned AD child domain before Tech Refresh – missing Forest-level FSMO roles and Enterprise Admins

Nicholas How (Malifax SG) 0 Reputation points
2026-08-31T09:20:45.77+00:00

Hi Microsoft Community,

I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned.

Current environment

For example, the original AD structure was:

ppp.com                 ← Original parent / forest root domain
   |
   └── abc.ppp.com      ← Child domain currently in use

The original ppp.com domain has already been decommissioned and is no longer available.

However, when the child domain abc.ppp.com was separated/decommissioned from the parent environment in the past, the process was apparently not completed correctly.

The abc.ppp.com domain is still operational today. Users can authenticate and the domain is generally functioning, but the AD environment appears to retain dependencies on the previous ppp.com forest/root domain.

FSMO situation

The domain-level FSMO roles for abc.ppp.com are available, but the forest-level FSMO roles are still associated with the old environment.

The two important forest-level roles are:

  • Schema Master
  • Domain Naming Master

Microsoft documentation confirms that Schema Master and Domain Naming Master are forest-wide FSMO roles, rather than domain-specific roles.

The original ppp.com domain/DCs that previously held these roles have already been decommissioned.

Therefore, I am currently unable to perform a normal FSMO transfer.

Enterprise Admins issue

I also found that my current administrative account does not have membership in Enterprise Admins.

This is particularly problematic because Enterprise Admins is a forest-root-domain group and is normally used for forest-wide administrative operations. Microsoft documentation also states that Enterprise Admins exists in the forest root domain.

When I attempted to perform FSMO seizure/recovery, the operation was not successful because my current administrative account does not have the required Enterprise-level permissions.

The problem is that the original forest-root domain ppp.com is no longer available, so I cannot simply log on to the original forest-root domain and use the original Enterprise Admin account/group in the normal way.

My current objective

I am now planning a Tech Refresh of the Active Directory infrastructure.

I want to introduce new Windows Server domain controllers and eventually replace the existing DCs.

However, I do not want to proceed with the migration while the AD forest/domain structure is potentially inconsistent or while the forest-level FSMO roles still reference the old, decommissioned ppp.com environment.

I am therefore trying to determine whether the existing abc.ppp.com environment can be repaired and converted/recovered into a healthy, self-contained AD environment without rebuilding the domain from scratch.

My questions

  1. Is it possible to recover/fix this existing abc.ppp.com environment even though the original ppp.com forest-root domain has already been permanently decommissioned?
  2. Is there a supported Microsoft procedure for recovering the forest-level FSMO roles (Schema Master and Domain Naming Master) when the original forest-root DCs no longer exist?
  3. Since the original forest-root domain no longer exists, what is the correct way to handle the missing Enterprise Admins group/permissions?
  4. Can the existing abc.ppp.com domain be repaired so that it can continue as a healthy AD environment and support a normal DC Tech Refresh?
  5. Is there a supported way to clean up the old ppp.com forest/root-domain metadata without rebuilding abc.ppp.com?
  6. Are there any risks of corrupting the existing AD database, configuration partition, schema partition, trusts, DNS, or replication if I attempt FSMO seizure or metadata cleanup in this situation?
  7. What information/command output should I provide to determine the exact state of the forest and whether this environment is recoverable?

I would prefer to repair the existing AD environment rather than create a completely new domain, because the current abc.ppp.com domain is still actively used by production systems and users.

I would greatly appreciate advice from anyone with experience handling an orphaned child domain / decommissioned forest-root domain and recovering forest-level FSMO roles before a Windows Server Tech Refresh.

Thank you.Hi Microsoft Community,

I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned.

Current environment

For example, the original AD structure was:

ppp.com                 ← Original parent / forest root domain
   |
   └── abc.ppp.com      ← Child domain currently in use

The original ppp.com domain has already been decommissioned and is no longer available.

However, when the child domain abc.ppp.com was separated/decommissioned from the parent environment in the past, the process was apparently not completed correctly.

The abc.ppp.com domain is still operational today. Users can authenticate and the domain is generally functioning, but the AD environment appears to retain dependencies on the previous ppp.com forest/root domain.

FSMO situation

The domain-level FSMO roles for abc.ppp.com are available, but the forest-level FSMO roles are still associated with the old environment.

The two important forest-level roles are:

  • Schema Master
  • Domain Naming Master

Microsoft documentation confirms that Schema Master and Domain Naming Master are forest-wide FSMO roles, rather than domain-specific roles.

The original ppp.com domain/DCs that previously held these roles have already been decommissioned.

Therefore, I am currently unable to perform a normal FSMO transfer.

Enterprise Admins issue

I also found that my current administrative account does not have membership in Enterprise Admins.

This is particularly problematic because Enterprise Admins is a forest-root-domain group and is normally used for forest-wide administrative operations. Microsoft documentation also states that Enterprise Admins exists in the forest root domain.

When I attempted to perform FSMO seizure/recovery, the operation was not successful because my current administrative account does not have the required Enterprise-level permissions.

The problem is that the original forest-root domain ppp.com is no longer available, so I cannot simply log on to the original forest-root domain and use the original Enterprise Admin account/group in the normal way.

My current objective

I am now planning a Tech Refresh of the Active Directory infrastructure.

I want to introduce new Windows Server domain controllers and eventually replace the existing DCs.

However, I do not want to proceed with the migration while the AD forest/domain structure is potentially inconsistent or while the forest-level FSMO roles still reference the old, decommissioned ppp.com environment.

I am therefore trying to determine whether the existing abc.ppp.com environment can be repaired and converted/recovered into a healthy, self-contained AD environment without rebuilding the domain from scratch.

My questions

  1. Is it possible to recover/fix this existing abc.ppp.com environment even though the original ppp.com forest-root domain has already been permanently decommissioned?
  2. Is there a supported Microsoft procedure for recovering the forest-level FSMO roles (Schema Master and Domain Naming Master) when the original forest-root DCs no longer exist?
  3. Since the original forest-root domain no longer exists, what is the correct way to handle the missing Enterprise Admins group/permissions?
  4. Can the existing abc.ppp.com domain be repaired so that it can continue as a healthy AD environment and support a normal DC Tech Refresh?
  5. Is there a supported way to clean up the old ppp.com forest/root-domain metadata without rebuilding abc.ppp.com?
  6. Are there any risks of corrupting the existing AD database, configuration partition, schema partition, trusts, DNS, or replication if I attempt FSMO seizure or metadata cleanup in this situation?
  7. What information/command output should I provide to determine the exact state of the forest and whether this environment is recoverable?

I would prefer to repair the existing AD environment rather than create a completely new domain, because the current abc.ppp.com domain is still actively used by production systems and users.

I would greatly appreciate advice from anyone with experience handling an orphaned child domain / decommissioned forest-root domain and recovering forest-level FSMO roles before a Windows Server Tech Refresh.

Thank you.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,225 Reputation points
    2026-08-31T16:33:02.9966667+00:00

    Hello @Nicholas How (Malifax SG)

    Do not attempt to turn abc.ppp.com into a new forest root by seizing FSMO roles or deleting ppp.com metadata. You can't simply detach a child domain from its forest and convert it in place into an independent forest. Your functioning child domain still shares the forest-wide Schema and Configuration partitions with the original forest.

    Microsoft documents metadata cleanup for an orphaned domain, but that procedure assumes the domain being removed is genuinely gone, and the remaining forest is otherwise valid. Microsoft specifically warns that using ntdsutil incorrectly can cause partial or complete loss of AD functionality. In your case, deleting the original forest-root metadata is particularly risky because ppp.com was the forest root and contained Enterprise Admins, Schema Admins, and the forest-level administrative/security context you're now missing.

    Similarly, although FSMO roles can normally be seized when their former owner is permanently unavailable, the bigger issue here is authorization and forest integrity, not simply finding another DC to run ntdsutil on.

    Before making any changes, take System State backups of the surviving DCs and open a Microsoft Support case for AD DS/forest recovery. Microsoft documents System State as containing the AD database, registry, SYSVOL, and other components required for DC recovery.

    Provide Support with dcdiag /v, repadmin /showrepl, repadmin /replsummary, netdom query fsmo, Get-ADForest, Get-ADDomain, DNS configuration, Sites and Services topology, and details of any remaining ppp.com objects/DC metadata.

    The key decision is whether Microsoft can safely repair the existing forest using supported recovery procedures. If the forest-root domain is truly unrecoverable, the supported long-term solution may be to build a new forest and migrate the users, computers, and applications from abc.ppp.com, rather than attempting to promote the surviving child domain to forest root.

    References:

    Remove orphaned domains from Active Directory

    Active Directory forest recovery procedures

    Because this is a production forest, pause the DC Tech Refresh and avoid FSMO seizure/metadata cleanup until you've reviewed the forest state. This is one of those AD scenarios where an incorrect cleanup can turn a partially functioning environment into an unrecoverable one.

    Help make this community better for everyone: if this answer resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.