Why am I not able to demote a domain controller in Active Directory due to lingering objects?
- Ensure there are no Active Directory-related services registered to the Domain Controller to be demoted
- Unjoin the Domain Controller from the Active Directory domain and reboot
- Check the Advanced group policy settings within Active Directory
- View Domain Controller security settings and ensure no lingering objects exist
- Run the Lingering Objects removal tool (LORP) to delete any detected ill-linked objects
- Reboot the machine and then try demoting it again