Active Directory forest and consistently logs Event ID 2042

Davi Gabi 20 Pontos de reputação
2026-09-24T13:05:36.4233333+00:00

We are experiencing an issue with a Domain Controller that has been offline for approximately 180 days. After bringing the server back online, it is unable to synchronize with the rest of the Active Directory forest and consistently logs Event ID 2042 related to replication.

The Domain Controller was functioning normally before being taken offline, but it now fails to resume replication with its partners. Other Domain Controllers in the environment continue to operate normally, and the issue appears to be isolated to the server that exceeded the supported replication tombstone interval.

Given the length of time the server has been disconnected, we understand that returning it to service through normal replication may no longer be supported. We would like to determine the safest approach to remove this expired Domain Controller from the environment and prevent any impact on the existing Active Directory infrastructure.

Could someone provide guidance on how to safely demote the affected Domain Controller and properly clean up its metadata from Active Directory after an extended offline period?

Windows para empresas | Windows Server | Dispositivos e implantação | Configurar grupos de aplicativos
0 comentários Sem comentários

1 resposta

Classificar por: Mais útil
  1. Domic Vo 34,490 Pontos de reputação Assistente Independente
    2026-09-24T13:36:26.88+00:00

    Hello,

    When a Domain Controller has been offline for longer than the tombstone lifetime (default 180 days in most environments), replication is permanently broken. Event ID 2042 confirms that the DC is attempting to replicate objects that have already been garbage collected in the forest. At this point, the server cannot be safely reintegrated through normal replication, and the supported approach is to remove it from the environment.

    The safest way forward is to demote the Domain Controller. If the server is still bootable, run dcpromo or use Server Manager to remove the Active Directory Domain Services role. During demotion, ensure you select the option to remove the server from the domain. If the DC cannot be cleanly demoted because replication is blocked, you will need to perform a forced demotion using dcpromo /forceremoval. This will leave orphaned metadata in Active Directory, which must then be cleaned up.

    Metadata cleanup is performed from another healthy Domain Controller using ntdsutil. Launch ntdsutil, enter metadata cleanup, connect to the domain, and remove the failed DC’s references. This process deletes the server object from the Configuration container, removes its NTDS settings, and clears lingering references in Sites and Services. After cleanup, verify that DNS records associated with the decommissioned DC are also removed, and check that no lingering replication partners remain in repadmin /showrepl.

    It is important not to attempt to reintroduce the expired DC into the forest. If you need another Domain Controller in that site, build a fresh server, promote it with dcpromo, and allow it to replicate from a healthy partner. This ensures the forest remains consistent and avoids introducing stale objects.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    DV.

    Esta resposta foi útil?

    0 comentários Sem comentários

Sua resposta

As respostas podem ser marcadas como ‘Aceitas’ pelo autor da pergunta e ‘Recomendadas’ pelos moderadores, o que ajuda os usuários a saber a resposta que resolveu o problema do autor.