View Categories

Why am I not able to demote a domain controller in Active Directory due to lingering objects?

< 1 min read

Why am I not able to demote a domain controller in Active Directory due to lingering objects?

  1. Ensure there are no Active Directory-related services registered to the Domain Controller to be demoted
  2. Unjoin the Domain Controller from the Active Directory domain and reboot
  3. Check the Advanced group policy settings within Active Directory
  4. View Domain Controller security settings and ensure no lingering objects exist
  5. Run the Lingering Objects removal tool (LORP) to delete any detected ill-linked objects
  6. Reboot the machine and then try demoting it again

Powered by BetterDocs