The demotion process is really straightforward. It essentially involves verifying that you really do intend to demote the server and that you are aware of the Active Directory-related roles that the server is performing. Demoting the domain controller also requires you to provide a machine-level password.
What is demoting a domain controller?
Demoting an additional domain controller requires Domain Admin credentials. Selecting Force the removal of this domain controller demotes the domain controller without removing the domain controller object's metadata from Active Directory.
How do you decommission a domain controller?
Removing metadata via Active Directory Users and Computers
- Log in to DC server as Domain/Enterprise administrator and navigate to Server Manager > Tools > Active Directory Users and Computers.
- Expand the Domain > Domain Controllers.
- Right click on the Domain Controller you need to manually remove and click Delete.