# Leave time for NetApp Files to discover replacement domain controllers

> When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:37+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?

## Potentially affected

Use this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site's controller and subnet membership, service records, and reachability before starting the retirement clock.

## DSE recommendation

Coordinate the storage and directory change records so retirement cannot precede the discovery allowance.

## Article

## Source facts

Azure NetApp Files performs domain-controller discovery every four hours using the configured AD site’s service records. Microsoft instructs operators to wait at least four hours between deploying replacement controllers and retiring the previous ones. The service requires writable controllers and does not support RODCs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site).

## Applicability

Use this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site’s controller and subnet membership, service records, and reachability before starting the retirement clock.

## DSE recommendation

Coordinate the storage and directory change records so retirement cannot precede the discovery allowance. Keep the old supported path available while the new writable controllers are introduced and verified. Treat elapsed time as a prerequisite, not proof of successful discovery. Assign cleanup of retired-controller DNS records to the directory owner after the approved transition.

## Verification

Verify site-specific service records and connectivity to the replacement controllers, then exercise the affected authenticated file workflows after the discovery interval. Review failures before removing the old path. Preserve introduction, observation, and retirement timestamps alongside actual access results. If the new controller is not reachable from the storage network, postpone retirement even when the minimum wait has elapsed.

## Official references

[Microsoft Learn: Understand guidelines for Active Directory Domain Services site design and planning](https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site).

## Primary reference

- Name: Understand guidelines for Active Directory Domain Services site design and planning | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-netapp-files/understand-guidelines-active-directory-domain-service-site
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Leave time for NetApp Files to discover replacement domain controllers,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-319-leave-time-for-netapp-files-to-discover-replacement-domain-controllers/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
