change time tombstone

Angel Garcia Gomez 21 Reputation points
2021-03-02T12:16:33.207+00:00

Hello,

I need to expand the tombstone to 365 days

Is it safe?

I have been able to see this URL, but I am afraid of breaking something.

https://www.windowstechno.com/how-can-i-check-the-tombstone-lifetime-of-my-active-directory-forest/

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,843 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2021-03-02T13:40:00.16+00:00

    It isn't good to be in a disconnected state for this long. Is there some compelling reason to do so?
    https://learn.microsoft.com/en-us/windows/win32/adschema/a-tombstonelifetime

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. Angel Garcia Gomez 21 Reputation points
    2021-03-02T13:50:21.683+00:00

    The reason is due to long term backups.

    0 comments No comments

  3. Dave Patrick 426.1K Reputation points MVP
    2021-03-02T13:53:21.783+00:00

    Not sure what is meant. The much simpler / safer method is to always have at least two domain controllers for high availability and disaster mitigation.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  4. Angel Garcia Gomez 21 Reputation points
    2021-03-02T14:02:39.987+00:00

    I understand you.

    By way of culture.

    What happens if, for example, I have 3 domain controllers, dc1, dc2 and dc3 and dc3 reaches 180?

    It will simply stop replication attempts and I will have to delete it manually?

    0 comments No comments

  5. Dave Patrick 426.1K Reputation points MVP
    2021-03-02T14:16:43.003+00:00

    In reality that should never happen, but in the event it did you can simply demote, reboot, promo it again. Worst case you could seize roles to a healthy one (if needed)
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds

    perform cleanup
    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup
    https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-manually-removing-a-domain-controller-server/ba-p/280564

    then rebuild it. Extending tombstone is not really a solution. Tombstone happens because of network problems.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments