Monday, October 05, 2026

How to Remove a Stale DHCP Server from Active Directory

When a Windows DHCP server is retired or removed improperly, its authorization can remain in Active Directory. This stale entry may continue to appear in the DHCP management console and should be cleaned up.

1. Check Authorized DHCP Servers

From an elevated PowerShell session on a domain controller or management system with the DHCP tools installed, run:

Get-DhcpServerInDC

You may see something similar to:

DnsName              IPAddress
-------              ---------
DHCP01.contoso.local 10.10.10.20
OLD-DHCP.contoso.local 10.10.10.15

Confirm that the server you intend to remove is actually retired and no longer providing DHCP services.

2. Remove the Stale Authorization

Remove the old DHCP server from Active Directory:

Remove-DhcpServerInDC -DnsName "OLD-DHCP.contoso.local" -IPAddress 10.10.10.15

Confirm the operation when prompted.

3. Verify the Removal

Run the following again:

Get-DhcpServerInDC

The retired server should no longer appear in the list of authorized DHCP servers.

Optional: Clean Up the DHCP Management Console

If the retired server still appears in the DHCP MMC console, right-click DHCP and select Manage Authorized Servers or remove the old server from the console.

Final Check

Removing a stale DHCP authorization does not delete DHCP scopes or modify another DHCP server. It removes the retired server's authorization record from Active Directory.

Before removing anything, verify the server name and IP address carefully—especially in environments where DHCP services have recently been migrated to a replacement server.