Administration > Single Sign On > Configuration > Active Directory Domain > Leave AD, the node fails to leave the domain.Idm client exception: Error trying to leave AD, error code [11], user [domain\user]
/opt/likewise/bin/domainjoin-cli leave command via ssh session fails with errorroot@vcsa[~]# /opt/likewise/bin/domainjoin-cli leaveLeaving AD Domain:<domain name>Error: ERROR MEMBER NOT IN GROUP [code 0x00000529]
/opt/likewise/bin/domainjoin-cli query may give below output:Error: LW_ERROR_KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN [code 0x0000a309]Client not found in Kerberos database
This issue occurs when stale or orphaned registry entries in the Likewise identity service prevent the standard unjoin workflow from validating group membership
Below steps will make changes in Likewise registry, Hence ensure to take a snapshot of the appliance. Refer to VMware vCenter in Enhanced Linked Mode pre-changes snapshot (online or offline) best practice
Note: The below steps would require a planned downtime as reboot of the appliance is necessary post domain unjoin operation
/opt/likewise/bin/lwregshell list_values "HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoin"
Sample Output:+ "Default" REG_SZ "<Domain Name>"
delete commands/opt/likewise/bin/lwregshell delete_tree "HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoin"
/opt/likewise/bin/lwsm restart lwreg
domainjoin-cli query command that the PSC/vCenter node no longer references the Active Directory Domain:/opt/likewise/bin/domainjoin-cli query
Name = vcsaDomain =