Federated identity management using Active Directory Federation Services
KB5082198 is not covered in the provided material, but there is directly relevant guidance for domain controllers that get stuck in a reboot/rollback loop after an OS update or in-place upgrade.
For a DC that repeatedly reboots while trying to complete an update, the supported recovery pattern is to allow the setup/servicing engine to detect the failed upgrade and roll back to the previous OS state:
- Continue rebooting the affected domain controller.
- After the permanent hang/loop is detected, reboot the server twice in succession.
- Setup should then detect the failed upgrade attempt and automatically roll back the system to the previous OS version and state.
- After rollback, the DC should return to its previous, healthy state without data loss.
If the DC remains stuck and cannot complete rollback, the documented workaround is to:
- Bring up new, healthy domain controllers (preferably on different physical or virtual machines) running the target OS version instead of trying to in-place upgrade the problematic DC.
- Once the new DCs are promoted and replicating correctly, retire or rebuild the problematic DC.
These steps avoid leaving the forest dependent on a DC that is stuck in an unstable update state and align with recommended practice for domain controller OS upgrades.
References: