Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.
--please don't forget to upvote
and Accept as answer
if the reply is helpful--
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello. I finally replaced my 2012 DCs with 2019. One of the 2012 DCs was a VM. I'm seeing this VM's account listed in the ACL of many SRV records. These are the records in DNS-Forward Lookup Zones-[our doman name]... in the _tcp and _udp folders. How do I clean up the ACL on all these records?
Ok, I don't have any machine accounts listed here so they may have been manually added. I'd probably look for and delete from the parent level.
--please don't forget to upvote
and Accept as answer
if the reply is helpful--
I removed the DC from ADUC and then the SRV ACLs started showing Account Unknown for the DC. I manually removed those and now I'm waiting to see how it goes.
check this powershell script to find dns entries for an orphaned DC and delete them