SRV Records listing old DC in ACL

MISAdmin 381 Reputation points
2021-08-26T11:05:15.973+00:00

Hello. I finally replaced my 2012 DCs with 2019. One of the 2012 DCs was a VM. I'm seeing this VM's account listed in the ACL of many SRV records. These are the records in DNS-Forward Lookup Zones-[our doman name]... in the _tcp and _udp folders. How do I clean up the ACL on all these records?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,467 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,887 questions
Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,023 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426.1K Reputation points MVP
    2021-08-27T15:54:33.107+00:00

    Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


18 additional answers

Sort by: Newest
  1. Agarwal, Mayank 6 Reputation points
    2023-01-12T06:33:52.8+00:00

    check this powershell script to find dns entries for an orphaned DC and delete them

    Clean SRV Records for orphaned DC

    0 comments No comments

  2. MISAdmin 381 Reputation points
    2021-09-02T12:00:53.353+00:00

    I removed the DC from ADUC and then the SRV ACLs started showing Account Unknown for the DC. I manually removed those and now I'm waiting to see how it goes.


  3. Dave Patrick 426.1K Reputation points MVP
    2021-08-31T19:48:07.403+00:00

    I guess just removing it from ADUC is what I was wondering about... instead of having to boot it up and remove it from the domain by making it part of a workgroup

    Either way, just make sure you know the password to the local administrator group on that machine.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  4. MISAdmin 381 Reputation points
    2021-08-31T19:46:13.98+00:00

    There's no metadata left from that server aside from the permissions in the SRV records ACL. I guess just removing it from ADUC is what I was wondering about... instead of having to boot it up and remove it from the domain by making it part of a workgroup.

    0 comments No comments