After struggling for quite a while to get the right commands to fix a domain controller we thought it a good idea to post the steps we had to take.
I know a lot of people would say that the best way is to dcpromo the DC out of the domain, do a meta data cleanup and then dcpromo it in again. Sometimes this method is not possible like in instance were your DC is also an Exchange server. Then you would first have to migrate the Exchange to another server before fixing the broken DC.
Always first and foremost is to make sure you have a system state backup of a healthy DC in case something goes wrong.
The first step is to allow the other domain controllers in your domain to replicate with Tombstoned DC. To do this follow the steps below:
- Click Start, click Run, type regedit, and then click OK.
- Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
- In the details pane, create or edit the registry entry as follows:
If the registry entry exists in the details pane, modify the entry as follows:
- In the details pane, right-click Allow Replication With Divergent and Corrupt Partner, and then click Modify.
- In the Value data box, type 1, and then click OK.
If the registry entry does not exist, create the entry as follows:
- Right-click Parameters, click New, and then click DWORD Value.
- Type the name Allow Replication With Divergent and Corrupt Partner, and then press ENTER.
- Double-click the entry. In the Value data box, type 1, and then click OK.