Leave time for NetApp Files to discover replacement domain controllers

When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

When can an old AD domain controller be retired after its replacement is introduced for NetApp Files?

Potentially affected

Use this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site's controller and subnet membership, service records, and reachability before starting the retirement clock.

DSE recommendation

Coordinate the storage and directory change records so retirement cannot precede the discovery allowance.

Source facts

Azure NetApp Files performs domain-controller discovery every four hours using the configured AD site’s service records. Microsoft instructs operators to wait at least four hours between deploying replacement controllers and retiring the previous ones. The service requires writable controllers and does not support RODCs. Microsoft Learn.

Applicability

Use this timing boundary during planned replacement of controllers in the site selected by the NetApp AD connection. Confirm the site’s controller and subnet membership, service records, and reachability before starting the retirement clock.

DSE recommendation

Coordinate the storage and directory change records so retirement cannot precede the discovery allowance. Keep the old supported path available while the new writable controllers are introduced and verified. Treat elapsed time as a prerequisite, not proof of successful discovery. Assign cleanup of retired-controller DNS records to the directory owner after the approved transition.

Verification

Verify site-specific service records and connectivity to the replacement controllers, then exercise the affected authenticated file workflows after the discovery interval. Review failures before removing the old path. Preserve introduction, observation, and retirement timestamps alongside actual access results. If the new controller is not reachable from the storage network, postpone retirement even when the minimum wait has elapsed.

Official references

Microsoft Learn: Understand guidelines for Active Directory Domain Services site design and planning.

Primary reference

Review the official source

Understand guidelines for Active Directory Domain Services site design and planning | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE