Solved

windows 2008 R2 Active Directory Object could not be displayed or deleted.

Posted on 2013-01-21
1
294 Views
Last Modified: 2013-01-22
Dear All,

I found some users which one I click on them I got the following error:

1

Could you please help to:
1-      List all users have the same problem using command or anything else.
2-      Delete those users, I’m not able to delete them, I got the following error.

1

Thanks
0
Comment
Question by:Rhala
1 Comment
 
LVL 42

Accepted Solution

by:
sedgwick earned 500 total points
ID: 38801094

This behavior occurs if the account that you are logged on with has only "list contents" permissions on the parent object.
http://support.microsoft.com/kb/305104
Under this scenario, you are unable to read any attributes of the object, even though you can see the object. This prevents Windows from providing information about the object based on the objectClass attribute, such as the icon attribute. You also do not have permissions to perform any operations on the object, such as a Delete command, that requires access to the objectGUID.

RESOLUTION
If you are a member of the local Administrators group on the domain controller, you may take ownership of the object and then grant yourself whatever access rights that you require.


Try this;
Logon on the DC with an account that is member of the 'Domain Admins' group
(the 'Domain Admins' group is by default a member of the Administrators group on the DC. To check this, on the DC, click Start / Run and type: CMD /k net localgroup Administrators)

- Open active directory users and computers
- Click View on the menubar
- check "Advanced Features"
- Goto the UNKNOWN object and open the properties
- on tab "Security" click on the 'Advanced' button.
- Goto tab 'Owner'
- Change Owner to the the administrator account that you are currently logged on with.
- In the Security dialog box, assign Full Control permissions to your account.
Active Directory Object could not be displayed
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question