AFAIK, you can just run “Add-KdsRootKey -EffectiveImmediately” and restart Kdssvc on all the DCs to regenerate the passwords. If you don’t restart those services, it takes up to 10 hours to become effective.
Once you’ve done that, and verified the new gMSA is working, you might want to get rid of the old key: Remove or delete KDSRootKey (KDS Root Key)
--
John Wright
IT Support Specialist
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Max Coder
Sent: Tuesday, September 30, 2025 8:36 AM
To: ntsysadmin <ntsys...@googlegroups.com>
Subject: [ntsysadmin] The Get-KdsRootKey command returns a decommissioned DC.
EXTERNAL EMAIL - This email was sent by a person from outside your organization. Exercise caution when clicking links, opening attachments or taking further action, before validating its authenticity. |
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/ntsysadmin/8f393934-e0f8-4de6-89ff-b5bcc3bb1bc2n%40googlegroups.com.
On Sep 30, 2025, at 8:36 AM, Max Coder <maxc...@gmail.com> wrote:
Hi,
--