Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 138
  • Last Modified:

Do Orphaed objects in Active directory get deleted or just disabled

I know that a workstation and a Domain Controller agree on an LSA secret every 30 days. If the LSA secret is not renewed at 30 days, the Domain controller continues to communicate with the workstation to agree on an LSA secret till the 60th day.

My question: Does the machine acocunt get deleted and removed from Active Directory after 60 days and no renewal of the LSA secret so that one does not see the object in AD or does the machine acocunt just get disabled in AD and have a red X?
1 Solution
Hi Stevesdl,

the machine will be disabled not deleted, AD doesnt delete anything out of the DB in regards to computer accounts, this is where a lot of people get frustrated and have to use 3rd party cleaning tools to clear out AD


Featured Post

[Webinar On Demand] Database Backup and Recovery

Does your company store data on premises, off site, in the cloud, or a combination of these? If you answered “yes”, you need a data backup recovery plan that fits each and every platform. Watch now as as Percona teaches us how to build agile data backup recovery plan.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now