{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
        "slug": "dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/"
        },
        "title": "Leave time for NetApp Files to discover replacement domain controllers",
        "summary": "When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:37+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 213,
        "potentially_affected": "Use this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site's controller and subnet membership, service records, and reachability before starting the retirement clock.",
        "dse_recommendation": "Coordinate the storage and directory change records so retirement cannot precede the discovery allowance.",
        "primary_source": {
            "name": "Understand guidelines for Active Directory Domain Services site design and planning | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure NetApp Files performs domain-controller discovery every four hours using the configured AD site&#8217;s service records. Microsoft instructs operators to wait at least four hours between deploying replacement controllers and retiring the previous ones. The service requires writable controllers and does not support RODCs. <a href=\"https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site&#8217;s controller and subnet membership, service records, and reachability before starting the retirement clock.</p>\n<h2>DSE recommendation</h2>\n<p>Coordinate the storage and directory change records so retirement cannot precede the discovery allowance. Keep the old supported path available while the new writable controllers are introduced and verified. Treat elapsed time as a prerequisite, not proof of successful discovery. Assign cleanup of retired-controller DNS records to the directory owner after the approved transition.</p>\n<h2>Verification</h2>\n<p>Verify site-specific service records and connectivity to the replacement controllers, then exercise the affected authenticated file workflows after the discovery interval. Review failures before removing the old path. Preserve introduction, observation, and retirement timestamps alongside actual access results. If the new controller is not reachable from the storage network, postpone retirement even when the minimum wait has elapsed.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Understand guidelines for Active Directory Domain Services site design and planning</a>.</p>",
        "content_text": "Source facts\nAzure NetApp Files performs domain-controller discovery every four hours using the configured AD site’s service records. Microsoft instructs operators to wait at least four hours between deploying replacement controllers and retiring the previous ones. The service requires writable controllers and does not support RODCs. Microsoft Learn.\nApplicability\nUse this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site’s controller and subnet membership, service records, and reachability before starting the retirement clock.\nDSE recommendation\nCoordinate the storage and directory change records so retirement cannot precede the discovery allowance. Keep the old supported path available while the new writable controllers are introduced and verified. Treat elapsed time as a prerequisite, not proof of successful discovery. Assign cleanup of retired-controller DNS records to the directory owner after the approved transition.\nVerification\nVerify site-specific service records and connectivity to the replacement controllers, then exercise the affected authenticated file workflows after the discovery interval. Review failures before removing the old path. Preserve introduction, observation, and retirement timestamps alongside actual access results. If the new controller is not reachable from the storage network, postpone retirement even when the minimum wait has elapsed.\nOfficial references\nMicrosoft Learn: Understand guidelines for Active Directory Domain Services site design and planning.",
        "content_markdown": "## Source facts\n\nAzure NetApp Files performs domain-controller discovery every four hours using the configured AD site’s service records. Microsoft instructs operators to wait at least four hours between deploying replacement controllers and retiring the previous ones. The service requires writable controllers and does not support RODCs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site).\n\n## Applicability\n\nUse this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site’s controller and subnet membership, service records, and reachability before starting the retirement clock.\n\n## DSE recommendation\n\nCoordinate the storage and directory change records so retirement cannot precede the discovery allowance. Keep the old supported path available while the new writable controllers are introduced and verified. Treat elapsed time as a prerequisite, not proof of successful discovery. Assign cleanup of retired-controller DNS records to the directory owner after the approved transition.\n\n## Verification\n\nVerify site-specific service records and connectivity to the replacement controllers, then exercise the affected authenticated file workflows after the discovery interval. Review failures before removing the old path. Preserve introduction, observation, and retirement timestamps alongside actual access results. If the new controller is not reachable from the storage network, postpone retirement even when the minimum wait has elapsed.\n\n## Official references\n\n[Microsoft Learn: Understand guidelines for Active Directory Domain Services site design and planning](https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Leave time for NetApp Files to discover replacement domain controllers",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/",
                "headline": "Leave time for NetApp Files to discover replacement domain controllers",
                "description": "When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?",
                "abstract": "When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?",
                "articleBody": "Source facts\nAzure NetApp Files performs domain-controller discovery every four hours using the configured AD site’s service records. Microsoft instructs operators to wait at least four hours between deploying replacement controllers and retiring the previous ones. The service requires writable controllers and does not support RODCs. Microsoft Learn.\nApplicability\nUse this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site’s controller and subnet membership, service records, and reachability before starting the retirement clock.\nDSE recommendation\nCoordinate the storage and directory change records so retirement cannot precede the discovery allowance. Keep the old supported path available while the new writable controllers are introduced and verified. Treat elapsed time as a prerequisite, not proof of successful discovery. Assign cleanup of retired-controller DNS records to the directory owner after the approved transition.\nVerification\nVerify site-specific service records and connectivity to the replacement controllers, then exercise the affected authenticated file workflows after the discovery interval. Review failures before removing the old path. Preserve introduction, observation, and retirement timestamps alongside actual access results. If the new controller is not reachable from the storage network, postpone retirement even when the minimum wait has elapsed.\nOfficial references\nMicrosoft Learn: Understand guidelines for Active Directory Domain Services site design and planning.",
                "datePublished": "2026-09-10T00:26:37+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Leave time for NetApp Files to discover replacement domain controllers"
                },
                "articleSection": [
                    "Business Continuity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Business Continuity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 213,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Understand guidelines for Active Directory Domain Services site design and planning | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site"
                }
            }
        ]
    }
}