Renaming a domain controller is fully supported by Microsoft, but it’s not a simple right-click-rename like a member server. It needs to go through netdom computername so AD, DNS, and Kerberos all stay in sync. Do it the manual way and you’ll end up with orphaned SPNs and broken authentication for anything referencing the old name.
Step 1: Add the new name as an alternate
netdom computername DC01 /add:DC01-NEW.yourdomain.com
This registers the new name alongside the existing one without removing anything, letting both work simultaneously while DNS and replication catch up.
Step 2: Make the new name primary
Once you’ve confirmed DNS has replicated the new name’s records (check with nslookup from another DC), promote it to primary:
netdom computername DC01 /makeprimary:DC01-NEW.yourdomain.com
A reboot is required after this step for the primary name change to fully take effect.
Step 3: Remove the old name once everything is stable
After confirming replication, DNS, and authentication all work correctly under the new name for a few days, remove the old alternate name:
netdom computername DC01-NEW /remove:DC01.yourdomain.com
What people forget afterwards
DNS server settings on other machines and DHCP scope options that hardcode the old DC name by IP are usually fine since the IP doesn’t change, but anything referencing the DC by its old DNS name specifically. Monitoring tools, backup jobs, certificate templates bound to the old name, or a CA installed on that server. Needs manual updating. If the DC also runs an internal Certificate Authority, renaming it is significantly more involved and requires re-issuing the CA’s own certificate; plan that separately and don’t assume the netdom process alone covers it.
For official guidance, see Microsoft’s Windows Server documentation.
Gear We Recommend
A few general tech accessories worth having alongside this.
Browse our General Tech Accessories picks on AmazonAs an Amazon Associate, TechyGeeksHome earns from qualifying purchases.
Discover more from TechyGeeksHome
Subscribe to get the latest posts sent to your email.