Active Directory Users/Computers Mssing

Posted on 2011-10-23
Medium Priority
Last Modified: 2012-05-12
We have been having a lot of issues with users and computer accounts just disappearing from Active Directory. My client had a Terminal Server that they didn't realize was a domain controller as well so I performed a dcpromo on that server to demote it. My client only has 1 domain controller at this point. Is there anyway that I can permenantly delete old users and computer from AD? Also I have run dcdiag and netdiag and all is well there. I don't know when the users get deleted but they show up in ADRestore but when I try to restore them I get an error that it won't enable them.
Question by:clctechs
LVL 39

Accepted Solution

Krzysztof Pytko earned 2000 total points
ID: 37014688
Please try to follow an article on that blog to clean up lingering objects within a forest at

LVL 57

Expert Comment

by:Mike Kline
ID: 37014707
You will want to enable auditing to see why objects are being deleted (and who is deleting them).  That should not be happening

Some programs that are nice to get rid of old objects

oldcmp by Joe Richards (also works for users)  http://www.joeware.net/freetools/tools/oldcmp/

ADTidy (GUI tool) http://www.cjwdev.co.uk/Software/ADTidy/Info.html

Both tools are free



Expert Comment

ID: 37016382

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question