Solved

User objects missing from AD again !! - please help

Posted on 2007-11-27
6
234 Views
Last Modified: 2010-03-17
Hi all,

We had a problem yesterday where the users were missing from AD (automatically deleted)
We managed to restore the deleted users and set them back up again.
http://www.expertsexchange.com/OS/Microsoft_Operating_Systems/Server/Windows_2003_Active_Directory/Q_22982346.html

Today the user objects are missing again from ADUC.
Naturally we know how to restore them, but it looks like this is just going to keep happening.
Once the users dont logout of their PC their session remains active, but once they log out they cant log back in as they dont exist.
The only think we noticed is we have some TS user objects (that dont have an exchange mailbox) that are not getting deleted.

We have no idea why this is happening and need to find the root cause urgently.
Any help appreciated.
0
Comment
Question by:ggntt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 23

Expert Comment

by:ormerodrutter
ID: 20357657
My first thought is a Replication problem - do you  have multiple DCs in your organisation?
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 20361234
> "We managed to restore the deleted users and set them back up again. "

If you have multiple DCs in your organization, did you perform an authoritative restore?  If not, the deletion will simple re-replicate onto the DC from which you did the initial restore.  Authoritative restores are discussed here: http://technet2.microsoft.com/WindowsServer/en/library/690730c7-83ce-4475-b9b4-46f76c9c7c901033.mspx
0
 
LVL 3

Expert Comment

by:l84work
ID: 20363844
You really need to enable security auditing.

How big is your environment?  How many user objects?
How many IT staff has rights to delete user accounts?  I would start removing their rights, including service accounts.

We also use Quest software, after you restore, make sure you replicate the changes out immediately.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:ggntt
ID: 20363989
Hi All,

Very small org only 15 users, single DC (server 2003 with exchange not sbs)
The user objects are not being manually deleted we are pretty sure of that.
We installed SP2 last night in the hope that will resolve it.
Would tombstone have anything to do with it ?

Thanks
ggntt


0
 
LVL 23

Accepted Solution

by:
ormerodrutter earned 500 total points
ID: 20364115
Tombstone shouldn't be your problem if you only have one DC as there is no replication whatsoever. Providing the user account has not been manually deleted, I haven't come across this before so just like you I am waiting for the solution. :)
0
 
LVL 3

Expert Comment

by:l84work
ID: 20367509
Is there any scheduled task or automated script job running on the DC?

Enable the object level auditing in the default domain controller gpo and monitor the security logs.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Microsoft DNS on Windows Server 2012 R2 10 65
AD Account lockout 11 69
Event ID 29 KDC Win 2008 R2 DC 6 22
SYSVOL folder permission security best practice ? 14 52
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question