Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.
--please don't forget to upvote
and Accept as answer
if the reply is helpful--
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello. I finally replaced my 2012 DCs with 2019. One of the 2012 DCs was a VM. I'm seeing this VM's account listed in the ACL of many SRV records. These are the records in DNS-Forward Lookup Zones-[our doman name]... in the _tcp and _udp folders. How do I clean up the ACL on all these records?
Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.
--please don't forget to upvote
and Accept as answer
if the reply is helpful--
check this powershell script to find dns entries for an orphaned DC and delete them
I removed the DC from ADUC and then the SRV ACLs started showing Account Unknown for the DC. I manually removed those and now I'm waiting to see how it goes.
I guess just removing it from ADUC is what I was wondering about... instead of having to boot it up and remove it from the domain by making it part of a workgroup
Either way, just make sure you know the password to the local administrator group on that machine.
--please don't forget to upvote
and Accept as answer
if the reply is helpful--
There's no metadata left from that server aside from the permissions in the SRV records ACL. I guess just removing it from ADUC is what I was wondering about... instead of having to boot it up and remove it from the domain by making it part of a workgroup.