We have been having a lot of issues with users and computer accounts just disappearing from Active Directory. My client had a Terminal Server that they didn't realize was a domain controller as well so I performed a dcpromo on that server to demote it. My client only has 1 domain controller at this point. Is there anyway that I can permenantly delete old users and computer from AD? Also I have run dcdiag and netdiag and all is well there. I don't know when the users get deleted but they show up in ADRestore but when I try to restore them I get an error that it won't enable them.
Krzysztof PytkoConnect With a Mentor Senior Active Directory EngineerCommented:
Please try to follow an article on that blog to clean up lingering objects within a forest at

Mike KlineCommented:
You will want to enable auditing to see why objects are being deleted (and who is deleting them).  That should not be happening

Some programs that are nice to get rid of old objects

oldcmp by Joe Richards (also works for users)

ADTidy (GUI tool)

Both tools are free


hirenvmajithiyaManager (System Administration)Commented:
