How to do it...

To render the read-only domain controller useless to an attacker or thief, perform these steps:

  1. Open Active Directory Users and Computers (dsa.msc).
  2. In the left navigation pane, expand the domain name.
  3. In the left navigation pane, expand the Domain Controllers OU.
  4. Right-click the compromised read-only domain controller and select Delete.
  5. On the Deleting Active Directory Domain Controller screen, select the Reset all passwords for user accounts that were cached on this read-only domain controller option.
  6. Since the persons associated with the user accounts will be forced to have their passwords reset by service desk personnel, it's recommended practice to also check Export the list of accounts that were cached on this read-only domain controller to this file: and to specify a file. This way, the service desk may proactively approach affected colleagues.
  7. Click Delete.