How to Rename a Domain Controller Safely

Renaming a domain controller is fully supported by Microsoft, but it’s not a simple right-click-rename like a member server. It needs to go through netdom computername so AD, DNS, and Kerberos all stay in sync. Do it the manual way and you’ll end up with orphaned SPNs and broken authentication for anything referencing the old […]

How to Rename a Domain Controller Safely

Renaming a domain controller is fully supported by Microsoft, but it’s not a simple right-click-rename like a member server. It needs to go through netdom computername so AD, DNS, and Kerberos all stay in sync. Do it the manual way and you’ll end up with orphaned SPNs and broken authentication for anything referencing the old name.

Step 1: Add the new name as an alternate

netdom computername DC01 /add:DC01-NEW.yourdomain.com

This registers the new name alongside the existing one without removing anything, letting both work simultaneously while DNS and replication catch up.

Step 2: Make the new name primary

Once you’ve confirmed DNS has replicated the new name’s records (check with nslookup from another DC), promote it to primary:

netdom computername DC01 /makeprimary:DC01-NEW.yourdomain.com

A reboot is required after this step for the primary name change to fully take effect.

Step 3: Remove the old name once everything is stable

After confirming replication, DNS, and authentication all work correctly under the new name for a few days, remove the old alternate name:

netdom computername DC01-NEW /remove:DC01.yourdomain.com

What people forget afterwards

DNS server settings on other machines and DHCP scope options that hardcode the old DC name by IP are usually fine since the IP doesn’t change, but anything referencing the DC by its old DNS name specifically. Monitoring tools, backup jobs, certificate templates bound to the old name, or a CA installed on that server. Needs manual updating. If the DC also runs an internal Certificate Authority, renaming it is significantly more involved and requires re-issuing the CA’s own certificate; plan that separately and don’t assume the netdom process alone covers it.

For official guidance, see Microsoft’s Windows Server documentation.

🛠️

Gear We Recommend

A few general tech accessories worth having alongside this.

Browse our General Tech Accessories picks on Amazon

As an Amazon Associate, TechyGeeksHome earns from qualifying purchases.


Discover more from TechyGeeksHome

Subscribe to get the latest posts sent to your email.

Andrew Armstrong

Andrew Armstrong is a UK-based IT professional with 26+ years of hands-on experience in Windows, Windows Server, SCCM/ConfigMgr, Intune, Active Directory, PowerShell and enterprise infrastructure.

He founded TechyGeeksHome in 2010 and has published 770+ practical guides to real-world IT problems. He also builds free Windows utilities, including Ultimate Settings Panel, which has been downloaded over 850,000 times.