SRV Records listing old DC in ACL

MISAdmin 381 Reputation points
2021-08-26T11:05:15.973+00:00

Hello. I finally replaced my 2012 DCs with 2019. One of the 2012 DCs was a VM. I'm seeing this VM's account listed in the ACL of many SRV records. These are the records in DNS-Forward Lookup Zones-[our doman name]... in the _tcp and _udp folders. How do I clean up the ACL on all these records?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,467 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,888 questions
Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,023 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426.1K Reputation points MVP
    2021-08-27T15:54:33.107+00:00

    Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


18 additional answers

Sort by: Most helpful
  1. MISAdmin 381 Reputation points
    2021-08-28T15:24:40.92+00:00

    Do you mean just highlight the machine account in the ACL and click on the remove button?

    0 comments No comments

  2. Dave Patrick 426.1K Reputation points MVP
    2021-08-28T18:47:11.41+00:00

    Do you mean just highlight the machine account in the ACL and click on the remove button?

    Yes, exactly.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  3. MISAdmin 381 Reputation points
    2021-08-31T11:35:50.907+00:00

    I'll do these little-by-little... in case something breaks.


  4. Limitless Technology 39,361 Reputation points
    2021-08-31T12:45:09.823+00:00

    Hello,

    Additionally,

    Do you have old server computer account still exists in AD? If you can delete this account from AD then it should also delete ACL entries,

    I believe this ACL entries should not harm if the old server doesn't exists anymore.

    If the reply was helpful, please don’t forget to upvote or accept as answer.

    0 comments No comments