Two domain controllers, a drifting internal DNS, a directory spread across several sites.
A directory built up in successive stages, with failing replication and DNS records still pointing to a decommissioned server.
Audit of the existing setup, mapping of sites and subnets, DNS zone rebuild, cleanup of metadata left by old controllers, coherent group policy and a tested system state backup.
Replication restored, DNS zones cleaned up, password policy applied and system state backup in place.
The directory had been built up in successive stages without revisiting the original design. Replication between controllers was failing silently and DNS records still pointed to a decommissioned server.
Audit of the existing setup, mapping of sites and subnets, DNS zone rebuild, cleanup of metadata left behind by old controllers, then a coherent group policy and a tested system state backup.
Authentication became reliable again across the whole scope. A documented recovery plan was handed to the internal team, supported after go-live.