Fix it now
Error 8340 is ERROR_DS_CANT_DELETE_DSA_OBJ: the DSA object cannot be deleted. That object is the directory’s record of a domain controller, and it has a defined removal procedure the console route invokes and a raw delete does not. If the server is genuinely gone, metadata cleanup is what removes it.
netdom query fsmo
repadmin /replsummary
- Confirm the server will never come back. Metadata cleanup is not reversible, and a server that returns afterwards will try to replicate as a controller the directory no longer knows about.
- Seize any operations master role the dead server holds onto a live controller before you remove anything. You need Enterprise Admins for the schema master or the domain naming master, and Domain Admins for the PDC emulator, RID master and infrastructure master.
- In Active Directory Users and Computers, with Advanced Features on, open the Domain Controllers organisational unit, delete the computer object, and tick “This Domain Controller is permanently offline and can no longer be demoted using the Active Directory Domain Services Installation Wizard (DCPROMO)”. You need Domain Admins to do this.
- In Active Directory Sites and Services, remove any surviving NTDS Settings object and then the server object, then clear the dead server’s records out of DNS.
If the server is only switched off rather than dead, do not do any of this. Power it on and run Uninstall-ADDSDomainController on the machine itself, which removes everything cleanly and tells its partners about it.
If the server has gone from both consoles and replication no longer names it, you are done. If the delete is still refused, the next section covers the ntdsutil route and what else has to come out.
Why it happens
A domain controller is not one object. Its computer account sits in the Domain Controllers organisational unit; its NTDS Settings object sits beneath a server object in the configuration partition, inside the site it belonged to; its name appears in the replication connection objects of its partners; and in DNS it owns a host record, an alias under the _msdcs zone and service records advertising it. Delete one part and the others carry on describing a server that is not there.
8340 is the directory protecting that structure. ERROR_DS_CANT_DELETE_DSA_OBJ says the DSA object – the directory service agent object, which is the controller’s own identity in the configuration partition – cannot be deleted. Deleting the computer account through Active Directory Users and Computers invokes the proper removal with the right flags set, which is why the console route succeeds where a raw delete in a low-level editor does not.
8419 is the other side of the same coin and normally appears afterwards, on the partners rather than on the server you are working from. ERROR_DS_CANT_FIND_DSA_OBJ means the DSA object could not be found: a partner still holding a connection to the removed controller reports it until the removal replicates round. Left alone it usually clears within a cycle or two.
Two more codes in the same range get attached to this work and neither belongs to it. 8546 is ERROR_DS_NC_STILL_HAS_DSAS – a domain could not be deleted because domain controllers still host it, which is about removing a whole domain rather than a single server. 8547 is ERROR_DS_GC_REQUIRED – the operation can only be performed on a global catalog server, which means you are bound to the wrong server, not that an object is missing.
The dead server still holds an operations master role
You have this one if netdom query fsmo names it, or the role-holder diagnostic fails pointing at the missing server.
- Seize the roles onto a live controller before removing any metadata.
- Check your rights first: Enterprise Admins for the schema master or the domain naming master, Domain Admins for the PDC emulator, RID master and infrastructure master.
- Run
netdom query fsmofrom two controllers afterwards and confirm they agree on the new holder. - Only then perform the cleanup.
Never return the old server to the network after its roles have been seized. Two claimants for one role is an argument the directory cannot settle.
The console route is unavailable or the objects are inconsistent
You have this one if The objects are visible in one console and missing from another, or the computer object delete is refused outright.
- Run ntdsutil from an elevated Command Prompt on a healthy controller.
- Bind explicitly to a live controller first, so you are not operating against a stale copy.
- Remove the named server, then exit and check Sites and Services and DNS for anything the tool left behind.
- Force replication and confirm the partners agree before you move on.
ntdsutil
metadata cleanup
connections
connect to server DC01
quit
remove selected server DC02
quit
quit
You are bound to a server that cannot perform the operation
You have this one if Error 8547, or the operation fails only from one particular controller.
- 8547 is ERROR_DS_GC_REQUIRED: the operation can only be performed on a global catalog server. Connect to one and retry.
- In ntdsutil, use the connections menu to bind to a named live controller rather than relying on whichever one the console picked.
- Confirm the controller you are bound to actually holds the partition you are trying to change.
The removal worked but the errors carry on
You have this one if The controller is gone from both consoles, yet partners still log failures naming it and clients still try to contact it.
- Look for stale DNS first, including the alias under the _msdcs zone and the service records advertising the old server.
- Clear resolver caches, and check DHCP options and hard-coded DNS entries on servers for the old address.
- Find surviving connection objects on the partners and remove them by hand if a full replication cycle has not cleared them.
- Check the site and subnet definitions, in case the removed server was the only one mapped to a site.
Full reference
The codes you will see during this work
| Code | Name | Published meaning |
|---|---|---|
| 8340 | ERROR_DS_CANT_DELETE_DSA_OBJ | The DSA object cannot be deleted |
| 8419 | ERROR_DS_CANT_FIND_DSA_OBJ | The DSA object could not be found |
| 8546 | ERROR_DS_NC_STILL_HAS_DSAS | The requested domain could not be deleted because there exist domain controllers that still host this domain |
| 8547 | ERROR_DS_GC_REQUIRED | The requested operation can be performed only on a global catalog server |
Read 8546 carefully if you meet it here, because it is about a domain rather than a server. It appears when somebody tries to remove a whole naming context while controllers still host it, which is a different operation from tidying up after one dead machine and needs those controllers dealt with first.
The documented ntdsutil sequence
ntdsutil
metadata cleanup
connections
connect to server DC01
quit
remove selected server DC02
quit
quit
DC01 is a healthy replication partner you are connecting through; DC02 is the server being removed, given as its fully qualified or NetBIOS name. Older guidance walks a select operation target menu – list domains, select domain, list sites, select site, list servers – before removing the selected server. The shorter form above is what Microsoft documents now, and it removes the opportunity to select the wrong server by index number.
Where the leftovers hide
| Location | What to remove |
|---|---|
| Active Directory Users and Computers | The computer object in the Domain Controllers organisational unit, deleted with the permanently-offline confirmation ticked |
| Active Directory Sites and Services | The NTDS Settings object first, then the server object beneath its site |
| DNS | The host record, the alias under the _msdcs zone, and the service records advertising the server |
| Replication topology | Connection objects on partners that still name the removed server |
| Operations master roles | Any role the dead server held, seized onto a live controller before the cleanup |
Metadata cleanup permanently removes a controller from the directory and must never be run against a server that is merely unreachable. If that server later comes back online it still holds a database copy, will try to replicate as a controller the directory no longer knows, and can reintroduce objects deleted while it was away. Take a system state backup of a healthy controller first, and physically confirm the dead server is dead.
Order matters
- Seize any operations master roles onto a live controller.
- Delete the computer object through Active Directory Users and Computers with the permanently-offline confirmation. On current builds this performs the cleanup for you.
- Remove the NTDS Settings object before the server object in Sites and Services – the parent cannot go while the child is there.
- Clear the DNS records, including the _msdcs alias.
- Force replication and re-check from a second controller in a different site.
- Only then decide whether you need to replace the server you have just removed.
If the delete is refused and ntdsutil will not help either
- Confirm you are a member of Domain Admins, which is what the console route requires.
- Confirm you are bound to a live, healthy controller and not to a stale replica of the configuration partition.
- Check whether the object you are trying to delete has children. The NTDS Settings object has to go before the server object.
- Check whether replication is broken between the controller you are using and the rest of the domain, because a change written here may simply not be going anywhere.
- Check for an 8547, which means the operation needs a global catalog and you are not on one.
When a licence is the actual fix
Nothing in this article costs money. Metadata cleanup, the DNS tidy-up and role seizure all use tools that ship with Windows Server, and if your remaining controllers are healthy and numerous enough you should buy nothing. The licensing question arrives afterwards, when you count what is left: a domain that has just lost a controller and is down to one has no redundancy and nothing to authenticate users if that server fails. If you decide to rebuild, Arco supplies Windows Server 2025 Standard, whose licence carries the right to run two virtual machines plus one Hyper-V host – so check whether a host you have already licensed covers the replacement before ordering anything.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
8340 |
ERROR_DS_CANT_DELETE_DSA_OBJ, 0x2094: the DSA object cannot be deleted through the path that was attempted | Microsoft Learn |
8419 |
ERROR_DS_CANT_FIND_DSA_OBJ, 0x20E3: the DSA object could not be found. Normally seen on the partners of a controller that has just been removed | Microsoft Learn |
8546 |
ERROR_DS_NC_STILL_HAS_DSAS, 0x2162: the requested domain could not be deleted because domain controllers still host it | Microsoft Learn |
8547 |
ERROR_DS_GC_REQUIRED, 0x2163: the requested operation can be performed only on a global catalog server | Microsoft Learn |
Confirm the fix worked
Get-ADDomainController -Filter *run from two controllers does not list the removed server on either.repadmin /replsummaryreports no failures naming it.- The _msdcs zone and the forward lookup zone hold no records for the old server.
netdom query fsmoreturns a live, answering server for every role, and two controllers agree on the answers.- Clients in the removed server’s site are authenticating against a controller that still exists, rather than timing out first.
Questions people ask about this
The server is only switched off, not dead. Should I still clean up?
No. If there is any realistic prospect of powering it on, do that and remove it properly. Running Uninstall-ADDSDomainController on the machine itself removes everything this article removes by hand, and tells its partners about it.
Do I have to use ntdsutil?
Not usually. Deleting the controller’s computer object in Active Directory Users and Computers, with the permanently-offline confirmation ticked, performs the cleanup. ntdsutil is the fallback for when the objects are inconsistent or the consoles cannot see them.
How long before the errors stop?
Allow a full replication cycle across every site and re-check. DNS-driven errors continue until the stale records are gone and client resolver caches have expired, which is a separate clock.
What is the difference between 8340 and 8419?
8340 is a delete being refused – the object is there and the directory will not remove it that way. 8419 is the object not being found, which is what partners report while the removal is still replicating round. Seeing 8419 after a successful cleanup is normal for a cycle or two.
Does any of this need a licence or a paid tool?
No. The cleanup is free and uses tools you already have. A licence only matters if you choose to build a replacement controller, and even then only if you do not already hold capacity for it.
