SRV Records listing old DC in ACL

MISAdmin 381 Reputation points
2021-08-26T11:05:15.973+00:00

Hello. I finally replaced my 2012 DCs with 2019. One of the 2012 DCs was a VM. I'm seeing this VM's account listed in the ACL of many SRV records. These are the records in DNS-Forward Lookup Zones-[our doman name]... in the _tcp and _udp folders. How do I clean up the ACL on all these records?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,468 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,889 questions
Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,023 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426.1K Reputation points MVP
    2021-08-27T15:54:33.107+00:00

    Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


18 additional answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2021-08-26T17:55:15.463+00:00

    Just checking if there's any progress or updates?

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  2. MISAdmin 381 Reputation points
    2021-08-27T11:44:03.953+00:00

    Hello LimitlessTechnology. Thanks for this powershell method. These commands do not find anything because I don't have any records of the old dns server. What I have is records of the new dns servers but within those records in the ACL is the machine account of one of the retired DCs. It is listed (under the Security tab) as RetiredDCName$ with Write and Special permissions ticked.

    0 comments No comments

  3. Dave Patrick 426.1K Reputation points MVP
    2021-08-27T14:15:52.393+00:00

    Do you have a screenshot?

    0 comments No comments

  4. MISAdmin 381 Reputation points
    2021-08-27T15:42:00.017+00:00

    Here is an example. This is the just the _ldap properties but this DC is in the ACL of all the SRV records under the domain. The Machine account crossed off in red is one of the old DCs. A DC that was removed successfully with the Remove Roles & Features.

    127183-capture.jpg

    0 comments No comments