# Change Domain Controller IP Address Safely

Source: https://srvscripts.com/guides/change-domain-controller-ip-address/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

In short: Transfer FSMO roles off the DC if it holds any, change the address with New-NetIPAddress, set its DNS client to a partner DC first and itself second, then run ipconfig /registerdns, Restart-Service Netlogon and dnscmd /config…

Changing a domain controller’s IP address is routine during a subnet migration or a move to a new VLAN, and it goes wrong for one reason: something still points at the old address. That something is usually DNS, either the DC’s own client settings, the other DCs, or clients handed the old value by DHCP. A DC whose records are stale stops replicating, stops serving Group Policy and, if it is the only one at a site, takes logons down with it. The sequence below applies to Windows Server 2019, 2022 and 2025 and takes about half an hour of careful work.

**Short answer:** Transfer FSMO roles off the DC if it holds any, change the address with `New-NetIPAddress`, set its DNS client to a partner DC first and itself second, then run `ipconfig /registerdns`, `Restart-Service Netlogon` and `dnscmd /config /localnetprioritynetmask 0` if needed, update the DHCP scope options and the site subnet in Active Directory Sites and Services, delete any leftover old-address A, NS and SRV records, and confirm with `repadmin /replsummary`, `dcdiag /test:dns` and `nltest /dsgetdc`.

## Prepare before touching the network settings

Record the current state and reduce the blast radius:

```
ipconfig /all
netdom query fsmo
Get-DnsClientServerAddress -InterfaceAlias Ethernet
repadmin /replsummary
Get-DhcpServerv4OptionValue -OptionId 6
```

If the DC holds FSMO roles or is the only DNS server clients use, do the change out of hours, or move the roles first with [transfer and seize FSMO roles](/guides/transfer-fsmo-roles-powershell/). Check every place the old address is hard-coded: DHCP option 6 (DNS servers) on every scope, DNS forwarders and conditional forwarders on other DNS servers, the NTP configuration of any non-Windows device, firewall rules, VPN split-DNS settings, and any application config with an LDAP or Kerberos server address.

Clients pointing at the old IP for DNS will lose name resolution the moment you change it, so plan to update DHCP and force a renew, or keep the old address bound as a secondary IP for a day.

## Change the address and fix the DC’s own DNS client

On the DC, in an elevated PowerShell:

```
New-NetIPAddress -InterfaceAlias Ethernet -IPAddress 10.20.0.11 -PrefixLength 24 -DefaultGateway 10.20.0.1
Remove-NetIPAddress -InterfaceAlias Ethernet -IPAddress 10.10.0.11 -Confirm:$false
Set-DnsClientServerAddress -InterfaceAlias Ethernet -ServerAddresses 10.20.0.12,127.0.0.1
```

Point at a partner DC first and loopback second; a DC that only lists itself can fail to start AD DS cleanly after a reboot if its zones have not loaded. Then re-register everything the DC publishes:

```
ipconfig /flushdns
ipconfig /registerdns
Restart-Service Netlogon
dcdiag /fix
```

Netlogon rewrites the SRV records under `_msdcs`, `_sites`, `_tcp` and `_udp` from `C:\Windows\System32\config\netlogon.dns`; you can open that file to see exactly which records should now show the new address. `dcdiag /fix` re-registers the DC’s GUID CNAME as well.

## Clean up DNS, DHCP and sites

Open the DNS console on another DC and check the forward zone for the domain: the A record for the DC name, the “same as parent” A record at the zone root, the NS record and the SRV records in `_msdcs` must show the new address. Delete any that still show the old one; Netlogon adds records but does not always remove the old ones if scavenging is off. Also check the reverse zone for the old subnet and remove the PTR. Then:

```
Set-DhcpServerv4OptionValue -ScopeId 10.20.0.0 -DnsServer 10.20.0.11,10.20.0.12
Get-ADReplicationSubnet -Filter * | Select-Object Name, Site
New-ADReplicationSubnet -Name "10.20.0.0/24" -Site "HQ"
```

The site subnet is the one people forget. If the new address is in a subnet not mapped to a site, clients at that site will pick a DC elsewhere and the DC itself will log Event ID 5778 warnings. If other DNS servers had the DC as a forwarder or a secondary zone master, update those too, and if the DC ran DHCP, its own scope and any DHCP failover partner relationship must be re-created against the new address, as covered in [configure DHCP failover](/guides/windows-dhcp-failover/).

## Verify

Give replication a few minutes, then confirm from a different DC and from a client:

```
repadmin /replsummary
repadmin /showrepl DC01
dcdiag /s:DC01 /test:dns /test:advertising /test:netlogons
nslookup -type=SRV _ldap._tcp.dc._msdcs.corp.example.com
nltest /dsgetdc:corp.example.com /site:HQ
```

Every SRV answer must list the new IP, replication must show zero failures, and a client at the site should receive the re-addressed DC. If other DCs still show the old address in `/showrepl` errors, flush DNS on them and re-run; if 1722 errors persist, follow [fix AD replication errors 8453 and 1722](/guides/ad-replication-error-1722-8453/). A common pitfall is leaving the old address in the DC’s own DNS client list as the primary entry, which makes every lookup wait for a timeout and slows logons across the site.

## Change domain controller IP address at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Fix AD replication errors 8453 and 1722 “The RPC server is unavailable”](https://srvscripts.com/guides/ad-replication-error-1722-8453/) · [Fix “The trust relationship between this workstation and the primary domain failed”](https://srvscripts.com/guides/trust-relationship-failed-fix/) · [Raise the AD forest and domain functional level safely](https://srvscripts.com/guides/raise-ad-functional-level/).

## Frequently asked questions

### Does changing a domain controller’s IP address require a reboot?

No; the address change, DNS re-registration and Netlogon restart take effect live, though a reboot afterwards is a cheap way to confirm AD DS and DNS start cleanly with the new settings.

### How long does it take for clients to pick up the new DC address?

DNS records replicate to other DCs within the normal AD replication interval and clients honour the SRV record TTL of 600 seconds by default, so most clients find the new address within 15 to 30 minutes; DHCP clients need a renew to receive updated DNS server options.

### Can I undo the change if replication breaks?

Yes; set the old address back, re-run `ipconfig /registerdns` and restart Netlogon, and DNS records revert within minutes, which is why keeping the old address free for a day is worthwhile.
