Solved

Restore AD Objects from Recycle Bin

Posted on 2014-07-23
5
450 Views
Last Modified: 2014-07-23
We are running Windows Server 2012 and I'm almost certain that the AD recycle bin was enabled during deployment.

Yesterday, one of the technicians deleted an OU along with all of the group objects that are contained within the object and we're trying to restore it.

I can't seem to find the "Deleted Objects" container when opening Active Directory Administrative Center like my research has led me to believe it would have so I have resorted to the CLI in trying to restore the objects.

In the attached screenshot, you will see that I ran the Get-ADObject command and successfully found the folder I want to restore. I then piped the command into the "Restore-ADObject -whatif" command which didn't error out. When I removed the "-whatif" option, it started to error.

Any reason why this is giving me so many issues?
Screenshot.png
0
Comment
Question by:Adeste
  • 3
  • 2
5 Comments
 
LVL 19

Accepted Solution

by:
Miguel Angel Perez Muñoz earned 500 total points
ID: 40214209
You can not use * to recover bulk items without add recover name:
Get-ADObject -IncludeDeletedObjects -filter {cn -like "*name*"} | Restore-ADObject -NewName "<newname>"

I think you must use one by one to recover all lists or uses any GUI tool to do this: http://technet.microsoft.com/en-us/library/dd392261(v=ws.10).aspx
0
 

Author Comment

by:Adeste
ID: 40214269
Thank you! You are a gentleman and a scholar!

I was able to recover the OU itself and one AD group (so far). Is there a way to restore the AD groups with the original group membership?
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 40214316
Thanks!.

IMHO restored groups are same before deleting. Have you checked membership of this? ensure you recover all deleted groups (forgetting one group causes no appears on membership). On this link you can review entire process: http://blogs.msdn.com/b/dsadsi/archive/2009/08/26/restoring-object-from-the-active-directory-recycle-bin-using-ad-powershell.aspx

The other way is doing a authoritative restore of deleted objects.
0
 

Author Comment

by:Adeste
ID: 40214382
I've tried going through the outline of that link you sent but the group membership still comes out blank.

In that article, It used the command to restore AD objects:
$deletedOU | Restore-ADObject

Open in new window


This command didn't work because as you mentioned above, I need to use the "NewName" parameter. Why do all of the articles online never make mention that this is a requirement?
0
 

Author Comment

by:Adeste
ID: 40214496
I just realized that AD recycle bin was actually not enabled and this is the reason why it wasn't restoring the object's group membership

Reference: http://social.technet.microsoft.com/Forums/windowsserver/en-US/8c774486-3d30-4c4d-821a-6de3c2a95f9f/whats-wrong-with-this-command
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I thought I'd write this up for anyone who has a request to create an anonymous whistle-blower-type submission form created using SharePoint 2010 (this would probably work the same for 2013). It's not 100% fool-proof but it's as close as you can get…
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now