{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/invalidate-domain-controller-rid-pool-verify-renewal/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/",
        "slug": "invalidate-domain-controller-rid-pool-verify-renewal",
        "url": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/invalidate-domain-controller-rid-pool-verify-renewal/"
        },
        "title": "Invalidate a domain controller's RID pool and verify the renewal behavior",
        "summary": "Use AD Forest Recovery - Invalidating the RID Pool to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:14:25+00:00",
        "modified_at": "2026-08-27T12:58:58+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 611,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of AD Forest Recovery - Invalidating the RID Pool",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "AD Forest Recovery - Invalidating the RID Pool",
            "url": "https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-invaildate-rid-pool",
            "published_on": "2025-05-12",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to resolve one bounded operational decision: Invalidate a domain controller&#8217;s RID pool and verify the renewal behavior. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-invaildate-rid-pool\" target=\"_blank\" rel=\"noopener noreferrer\">AD Forest Recovery &#8211; Invalidating the RID Pool</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>Microsoft provides a PowerShell procedure that invalidates the current RID pool on one domain controller. The research record locates this support at <strong>Invalidate the current RID pool &gt; PowerShell procedure</strong>.</li>\n<li>Directory-Services-SAM event 16654 in the System log verifies completion on Windows Server 2012; Microsoft notes that earlier Windows versions do not log this event. The research record locates this support at <strong>Invalidate the current RID pool &gt; verification paragraph</strong>.</li>\n<li>After invalidation, the first security-principal creation attempt fails and requests a new RID pool; retrying succeeds after the new pool is allocated. The research record locates this support at <strong>Invalidate the current RID pool &gt; Note</strong>.</li>\n</ul>\n<p>Do not import neighboring assumptions into the source record. The supported task is a scoped comparison involving forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps and the conditions the source actually describes.</p>\n<h2>What the source does not establish</h2>\n<p>The page is a forest-recovery procedure and does not establish that every restored controller requires this action; apply it only to the controller selected by the recovery plan. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel and the environment&#8217;s recorded constraints.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Invalidate the current RID pool &gt; PowerShell procedure</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Invalidate the current RID pool &gt; verification paragraph</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 3 at <strong>Invalidate the current RID pool &gt; Note</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>What inventory proves which parts of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps are in and out of scope?</li>\n<li>Which condition in offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel must be healthy before evidence is trustworthy?</li>\n<li>What result would disprove the working assumption and return the issue to the owner?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Use a two-person review for the source interpretation and the resulting operational decision. Record the source location, examined part of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps, observed and expected states, owner, and reason for deviation.</p>\n<p>An implementation decision needs an owner, approved window, prechecks, observable outcome, stop authority, and rollback path. Validate offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel before and after the test, and store only sanitized operational evidence.</p>\n<h2>Verification and evidence</h2>\n<p>Evidence should let another reviewer reproduce this decision. Retain observations beside the traced locations <strong>Invalidate the current RID pool &gt; PowerShell procedure</strong>; <strong>Invalidate the current RID pool &gt; verification paragraph</strong>; <strong>Invalidate the current RID pool &gt; Note</strong>. Favor backup manifests, restore logs, isolation proof, recovery timing, role-transfer records, DNS validation, and exercise findings, linked to stable identifiers, time, and operator.</p>\n<p>Close the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today&#8217;s observation is not a continuing guarantee.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-invaildate-rid-pool\" target=\"_blank\" rel=\"noopener noreferrer\">AD Forest Recovery &#8211; Invalidating the RID Pool</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to resolve one bounded operational decision: Invalidate a domain controller’s RID pool and verify the renewal behavior. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official AD Forest Recovery – Invalidating the RID Pool from Microsoft supports the following bounded statements:\n\nMicrosoft provides a PowerShell procedure that invalidates the current RID pool on one domain controller. The research record locates this support at Invalidate the current RID pool > PowerShell procedure.\nDirectory-Services-SAM event 16654 in the System log verifies completion on Windows Server 2012; Microsoft notes that earlier Windows versions do not log this event. The research record locates this support at Invalidate the current RID pool > verification paragraph.\nAfter invalidation, the first security-principal creation attempt fails and requests a new RID pool; retrying succeeds after the new pool is allocated. The research record locates this support at Invalidate the current RID pool > Note.\n\nDo not import neighboring assumptions into the source record. The supported task is a scoped comparison involving forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps and the conditions the source actually describes.\nWhat the source does not establish\nThe page is a forest-recovery procedure and does not establish that every restored controller requires this action; apply it only to the controller selected by the recovery plan. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel and the environment’s recorded constraints.\nApplicability questions\n\nFor source statement 1 at Invalidate the current RID pool > PowerShell procedure, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Invalidate the current RID pool > verification paragraph, which observable configuration, record, or test can confirm applicability here?\nFor source statement 3 at Invalidate the current RID pool > Note, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps are in and out of scope?\nWhich condition in offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Use a two-person review for the source interpretation and the resulting operational decision. Record the source location, examined part of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps, observed and expected states, owner, and reason for deviation.\nAn implementation decision needs an owner, approved window, prechecks, observable outcome, stop authority, and rollback path. Validate offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel before and after the test, and store only sanitized operational evidence.\nVerification and evidence\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Invalidate the current RID pool > PowerShell procedure; Invalidate the current RID pool > verification paragraph; Invalidate the current RID pool > Note. Favor backup manifests, restore logs, isolation proof, recovery timing, role-transfer records, DNS validation, and exercise findings, linked to stable identifiers, time, and operator.\nClose the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.\nOfficial references\n\nAD Forest Recovery – Invalidating the RID Pool — Microsoft",
        "content_markdown": "Use this document to resolve one bounded operational decision: Invalidate a domain controller’s RID pool and verify the renewal behavior. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [AD Forest Recovery – Invalidating the RID Pool](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-invaildate-rid-pool) from Microsoft supports the following bounded statements:\n\n- Microsoft provides a PowerShell procedure that invalidates the current RID pool on one domain controller. The research record locates this support at Invalidate the current RID pool > PowerShell procedure.\n\n- Directory-Services-SAM event 16654 in the System log verifies completion on Windows Server 2012; Microsoft notes that earlier Windows versions do not log this event. The research record locates this support at Invalidate the current RID pool > verification paragraph.\n\n- After invalidation, the first security-principal creation attempt fails and requests a new RID pool; retrying succeeds after the new pool is allocated. The research record locates this support at Invalidate the current RID pool > Note.\n\nDo not import neighboring assumptions into the source record. The supported task is a scoped comparison involving forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps and the conditions the source actually describes.\n\n## What the source does not establish\n\nThe page is a forest-recovery procedure and does not establish that every restored controller requires this action; apply it only to the controller selected by the recovery plan. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel and the environment’s recorded constraints.\n\n## Applicability questions\n\n- For source statement 1 at Invalidate the current RID pool > PowerShell procedure, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Invalidate the current RID pool > verification paragraph, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 3 at Invalidate the current RID pool > Note, which observable configuration, record, or test can confirm applicability here?\n\n- What inventory proves which parts of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps are in and out of scope?\n\n- Which condition in offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel must be healthy before evidence is trustworthy?\n\n- What result would disprove the working assumption and return the issue to the owner?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Use a two-person review for the source interpretation and the resulting operational decision. Record the source location, examined part of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps, observed and expected states, owner, and reason for deviation.\n\nAn implementation decision needs an owner, approved window, prechecks, observable outcome, stop authority, and rollback path. Validate offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel before and after the test, and store only sanitized operational evidence.\n\n## Verification and evidence\n\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Invalidate the current RID pool > PowerShell procedure; Invalidate the current RID pool > verification paragraph; Invalidate the current RID pool > Note. Favor backup manifests, restore logs, isolation proof, recovery timing, role-transfer records, DNS validation, and exercise findings, linked to stable identifiers, time, and operator.\n\nClose the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.\n\n## Official references\n\n- [AD Forest Recovery – Invalidating the RID Pool](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-invaildate-rid-pool) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/",
                "url": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Invalidate a domain controller's RID pool and verify the renewal behavior",
                        "item": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/#article",
                "identifier": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/",
                "url": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/",
                "headline": "Invalidate a domain controller's RID pool and verify the renewal behavior",
                "description": "Use AD Forest Recovery - Invalidating the RID Pool to review this narrow operational decision without extending the source beyond its stated scope.",
                "abstract": "Use AD Forest Recovery - Invalidating the RID Pool to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to resolve one bounded operational decision: Invalidate a domain controller’s RID pool and verify the renewal behavior. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official AD Forest Recovery – Invalidating the RID Pool from Microsoft supports the following bounded statements:\n\nMicrosoft provides a PowerShell procedure that invalidates the current RID pool on one domain controller. The research record locates this support at Invalidate the current RID pool > PowerShell procedure.\nDirectory-Services-SAM event 16654 in the System log verifies completion on Windows Server 2012; Microsoft notes that earlier Windows versions do not log this event. The research record locates this support at Invalidate the current RID pool > verification paragraph.\nAfter invalidation, the first security-principal creation attempt fails and requests a new RID pool; retrying succeeds after the new pool is allocated. The research record locates this support at Invalidate the current RID pool > Note.\n\nDo not import neighboring assumptions into the source record. The supported task is a scoped comparison involving forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps and the conditions the source actually describes.\nWhat the source does not establish\nThe page is a forest-recovery procedure and does not establish that every restored controller requires this action; apply it only to the controller selected by the recovery plan. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel and the environment’s recorded constraints.\nApplicability questions\n\nFor source statement 1 at Invalidate the current RID pool > PowerShell procedure, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Invalidate the current RID pool > verification paragraph, which observable configuration, record, or test can confirm applicability here?\nFor source statement 3 at Invalidate the current RID pool > Note, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps are in and out of scope?\nWhich condition in offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Use a two-person review for the source interpretation and the resulting operational decision. Record the source location, examined part of forest recovery plans, trusted backups, isolated recovery networks, controller rebuild order, credential resets, and validation steps, observed and expected states, owner, and reason for deviation.\nAn implementation decision needs an owner, approved window, prechecks, observable outcome, stop authority, and rollback path. Validate offline credentials, Windows DNS, time, virtualization, storage, PKI, network isolation, and authorized recovery personnel before and after the test, and store only sanitized operational evidence.\nVerification and evidence\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Invalidate the current RID pool > PowerShell procedure; Invalidate the current RID pool > verification paragraph; Invalidate the current RID pool > Note. Favor backup manifests, restore logs, isolation proof, recovery timing, role-transfer records, DNS validation, and exercise findings, linked to stable identifiers, time, and operator.\nClose the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.\nOfficial references\n\nAD Forest Recovery – Invalidating the RID Pool — Microsoft",
                "datePublished": "2026-08-27T12:14:25+00:00",
                "dateModified": "2026-08-27T12:58:58+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/invalidate-domain-controller-rid-pool-verify-renewal/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Invalidate a domain controller's RID pool and verify the renewal behavior"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Briefing",
                    "Advisory priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 611,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "AD Forest Recovery - Invalidating the RID Pool",
                    "url": "https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-invaildate-rid-pool",
                    "datePublished": "2025-05-12"
                }
            }
        ]
    }
}