Need to make my client computers get Group policy update from Different Domain controllers in the Domain

admin-ayoola 30 Reputation points
2025-03-31T15:04:16.4266667+00:00

I have four Domain controllers running Windows Server 2022.. I need to decommission one of the domain controllers, but i noticed all my client computers are getting GP update from this domain controller.

I have set a group policy to make all my client computer get group policy update from the PDC but this is not solving the solution as all client computers are still getting their group policy from the DC that need to be decommissioned.

Please i need suggestion on how to resolve the issue.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory

Answer accepted by question author
Anonymous
2025-04-01T02:40:45.0433333+00:00

Hello admin-ayoola,

Thank you for posting in Q&A forum.

Please check the information below before you demote the one DC you want.

1.Please check the Domain Controllers in your domain. You can check it by running command:

netdom query dc

For example:

User's image

nltest /dclist:domain.com

For example (domain name is the actual domain name in your environment):

User's image

You can also check it via GUI on one domain controller.

User's image

2.Make sure the SYSVOL and Netlogon folder on each DC are shared.

User's image

3.Please check the AD replication by running commands below on PDC:

repadmin /showrepl >C:\rep1.txt

repadmin /replsum >C:\rep2.txt

repadmin /showrepl * /csv >c:\repsum.csv

4.Please check the SYSVOL replication between all the DC. Make sure all the contents in the path C:\Windows\SYSVOL\domain\Policies are the same on all DCs.

User's image

5.Please make sure the DC you need to be decommissioned is not PDC. If it is PDC, please transfer the five FSMO roles to another DC.

6.You mentioned that all my client computers are getting GP update from this domain controller (you want to demote), if this DC was a DNS server, please update the DNS client configuration on all member workstations, member servers, and other DCs that might have used this DNS server for name resolution. If it is required, modify the DHCP scope to reflect the removal of the DNS server.

7.If this domain controller was a global catalog server, evaluate whether application servers that pointed to this global catalog server must be pointed to another live global catalog server.

8.If this DC was a global catalog server, evaluate whether an additional global catalog must be promoted to the address site, the domain, or the forest global catalog load.

9.If this was a DNS server, update the Forwarder settings and the Delegation settings on any other DNS servers (DC server) that might have pointed to this DC for name resolution.

I hope the information above is helpful.

If you have any questions or concerns, please feel free to let us know.

Best Regards,

Daisy Zhou

============================================

If the Answer is helpful, please click "Accept Answer" and upvote it.

Was this answer helpful?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.