Solved

Cannot create a group in Active Directory, 'The specified group already exists'.

Posted on 2010-08-17
8
2,580 Views
Last Modified: 2012-08-13
I am trying to create a group on our Active Directory (Windows 2003 SBS based) but when I do, it says it can't create the object because it already exists...it doesn't.  Some background:

This server is going to be retired as a DC, so I'm stripping out all the roles it used to carry out for us.  The last one I removed was the Sophos Enterprise console, which is where the problem lies.  The Sophos EC has been moved to another machine and is running well, but any server which is either a DC or a PDC needs to look to an Active Directory group called Sophos Administrators for it to run.  These groups were removed when Sophos was uninstalled, but when I try to re-add one it says it already exists!!  I have had a good look through AD users and computers and it's nowhere to be found.  
0
Comment
Question by:-Juddy-
  • 4
  • 3
8 Comments
 
LVL 24

Accepted Solution

by:
Mike Thomas earned 500 total points
ID: 33452223
The old (deleted) group will be tombstoned and un usable, your probably better off restoring that group.

See if ad restore can get the group back for you.

http://technet.microsoft.com/en-us/sysinternals/bb963906.aspx
0
 
LVL 3

Author Comment

by:-Juddy-
ID: 33452242
What a fantastic app!!  It's brought back the AD objects, but they are called (example) myrestoredgroupTmpRn.........why the TmpRn suffix?
0
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33452277
Not sure but maybe so you can identify them and so they won't cause conflicts? just rename them back.
0
 
LVL 3

Author Comment

by:-Juddy-
ID: 33452281
Sorry, I'm being dim.....I suppose it's just to highlight the fact that it's been restored by the tool.  There's a GUI version too: http://www.windowsreference.com/free-utilities/adrestorenet-the-gui-version-of-adrestore/
0
Save on storage to protect fatherhood memories

You're the dad who has everything. This Father's Day, make sure your family memories are protected. My Passport Ultra has automatic backup and password protection to keep your cherished photos and videos safe. With up to 3TB, you have plenty of room to hold the adventures ahead.

 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33452288
BTW there is a very nice gui tool linked from this page call ADRestore.net
http://www.petri.co.il/recovering-deleted-items-active-directory.htm

Direct Link to Download
http://www.petri.co.il/downloads/ADRestore.NET.zip
0
 
LVL 3

Author Comment

by:-Juddy-
ID: 33452311
Point coming your way, top man!!
0
 
LVL 3

Author Closing Comment

by:-Juddy-
ID: 33452316
Just great!
0
 
LVL 17

Expert Comment

by:Premkumar Yogeswaran
ID: 33452939
Can you check this in AD

open command prompt and copy paste the comment below

dsquery group -name *Sophos*

also check this

dsquery user -name *Sophos*

Check this query and let us know if you find any thing...

Cheers,
Prem
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now