does the DC still boot up at all in DC-mode?  with Win2k SP4 you get the
same DCPROMO /forceremoval switch as you have with Win2k3.  That would be
the preferred method to remove AD.  

Otherwise you could still clean it up manually, however with your routine,
you'd likely also kill the other apps.  How do you boot it up "normally"
without AD? There's a simple reg-key to set on the DC: set the ProductType
value under the following registry key
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions from
"LanmanNT" [DC] to "ServerNT" [member/standalone]. It will then boot
normally and you can use he DSRM pw to logon as administrator. Your apps
should behave fine (if they don't use domain credentials anywhere).  But to
cleanup AD from the box, it's best to dcpromo it again into a brand-new
"temp"-forest and then to un-promote it right afterwards and finally join it
to your real domain - you then have an "AD-cleaned" box with you apps left
on it.

Also, I wouldn't use newsid on the machine - use SysPrep instead, which you
don't need to do after performing the procedure above.

In general - don't put other Apps on your DC - treat the DCs as something
special, that you could replace separately from other parts of your
infrastructure.  I would rather argue, that you don't need a DC in a
location where you can't afford the hardware...

/Guido

-----Original Message-----
From: Tomasz Onyszko [mailto:[EMAIL PROTECTED] 
Sent: Dienstag, 24. Februar 2004 18:05
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Manual removing of domain controller

OK, I have strange problem but from some reasons it have to be done in
this way if it is possible.

I have domain controller on one of sites which fails, but on this machine
also several applications was installed. No I have on this machine also
second Windows 2000 installation on second aprtition which is ordinary
Windows 2000 Standalone server, so it looks like described below:
- partition C: - failed DC, I can log on to directory restoration mode
- partition D: - clean Windows 2000 installation.
So what I want to do if it will be possible is to manualy remove DC role
nad AD database form this system which is installed on partition C: and
preserving apps which are installed on it.

Here is an idea :
- I boot to system on partition D, I make backup of registry files from
partition C:, and then I registry files from clean system to C:

What I want to achive: boot and log on to system on C: without AD role on
it. After this I run newsid utilyty to get nesid for this machine, rename
it and then I restore my appplications to working state.

Does somobody do this?  Or maybe You have other ideas how to accomplish
this task.

I want to avoid installing this server from the sratch becouse this is in
remote location and there will be a problem with this operations.

I know this is strange but ... maybe it will work.

-- 
Tomasz Onyszko [MVP]
http://www.w2k.pl
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to