Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

how can i convert a SID value of a deleted group to a common name?

Posted on 2013-06-18
9
Medium Priority
?
568 Views
Last Modified: 2013-06-18
we have an urgent need to restore 2 deleted security groups, however we only have the SID ID's of the groups. is there a script that can convert this to a common name so that we know which groups to restore from our backup?

many thanks!

S.
0
Comment
Question by:siber1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 3
9 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39257154
How long ago where they deleted?
0
 
LVL 40

Expert Comment

by:Subsun
ID: 39257160
0
 

Author Comment

by:siber1
ID: 39257179
thanks Subsun, i will try that in a bit and let you know
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 1000 total points
ID: 39257219
I also like adfind for this sort of thing

http://www.joeware.net/freetools/tools/adfind/

so if you know the SID

adfind -default -binenc -showdel -f  "(objectsid={{sid:YOURSID}})"

screenshot from my lab below

deletedsid
Want to find all deleted groups

adfind -default -showdel -f  "&(objectclass=group)(isdeleted=TRUE)" samaccountname

Thanks

Mike
0
 
LVL 40

Accepted Solution

by:
Subsun earned 1000 total points
ID: 39257254
With PowerShell you can use Get-QADObject cmdlet with parameter -Tombstone
For example..
Get-QADObject -Tombstone | ?{$_.sid -eq "S-1-5-21-617003201-2970812123-1821496560-1145"}

or 

Get-QADObject -Tombstone | ?{$_.sid -like "S-1-5-21-617003201-*"}

Open in new window

You can also use Get-ADObject to find the deleted objects..
0
 

Author Comment

by:siber1
ID: 39257295
thx MK and Subsun, both are excellent approaches, i get zero results when i try to query. perhaps these have passed the tombstone life then.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39257301
yeah if they are past the TSL then you won't find them.
0
 
LVL 40

Expert Comment

by:Subsun
ID: 39257337
Probably.. I think default tombstone lifetime is 180 days, is it deleted before that?
0
 

Author Closing Comment

by:siber1
ID: 39257583
thanks again. looks like this was past the tombstone life, not much we can do here.
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
A walk-through example of how to obtain and apply new DID phone numbers to your cloud PBX enabled users that are configured in Office 365. Whether you have 1, 10 or 100+ users in your tenant, it's quite easy to get them phone-enabled and making/rece…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question