How to Restore Deleted Active Directory Objects in Windows Server 2003, 2008 and 2008 R2 Domains

In this blog post we will be learning on how to restore deleted objects which was deleted accidentally.

In the past we have to restore system state backup by either performing Authoritative or Non Authoritative Restore.

For more Information on Authoritative and Non-Authoritative Restore please check the TechNet article here.

Before we begin

The account with we are going to perform this steps should be a member of Domain Admins and Enterprise Admins Group.

We will walk you through the steps involved in restoring AD User Object with scenarios.

The tool with which we are going to perform this action is called as AD Restore. Amazing tool and must to have handy with all system administrators. The tool is available on Mark Russinovich site.

Best Practices

Always ensure that AD System state backup has been taken at least once in a week and have them tested.

Scenario

We will be working on Windows Server 2003, 2008 and 2008 R2 Domain and Forest Functional Level.

For testing purpose I have created three different forest with same domain name with different functional levels on a different subnets.

image

Figure 1 : Windows Server 2003 Domain Controller.

image

Figure 1.1 : Windows Server 2008 Domain Controller.

image

Figure 1.2 : Windows Server 2008 R2 Domain Controller.

We will be deleting the entire OU along with users and other objects in the container.

Download the tool AdRestore.exe and place in the root of system drive.

Post which open command prompt and type the below command.

image

Figure 2.1 : Command with /r

Now “r” stands for restore.

This command will first try to restore user objects and other objects in the OU=All Company Users. Which wont help us initially. To avoid that we have to first select “N” for all other objects in the OU. For doing that please follow the below command.

image

Figure 2.2 : Showing the option what we have to select for restoring the OU=All Company Users.

In the above command we have still not selected Y to restore the OU first.

image

Figure 2.3 : Restored OU successfully.

image

Figure 3.1 : The OU is restored with no objects in it.

image

Figure 4.1 : All Users and Distribution Group Restored.

After restoring the account you have to reset password and enable the account.

image

Figure : 5.1 : All Users and Groups are restored.

The above tool is very old and it is really helpful for all Administrator who want to save their precious time.

Note :- The tool will work only if the deleted objects have not crossed the default tombstone limit of 60 Days. Also the display name and logon name field will show empty. You might have to add them manually.

In the next part series we will learn how to configure Active Directory Recycle Bin in Windows Server 2008 R2 Domain and Forest Functional Level.

Happy Learning

Sunder

MSEXCHANGETEAM | Ideas That Clicks

Tagged , . Bookmark the permalink.

5 Responses to How to Restore Deleted Active Directory Objects in Windows Server 2003, 2008 and 2008 R2 Domains

  1. Shyam seegu says:

    Nice one…

  2. Shyam says:

    Really,The same issue we faced yesterday and we recovered the user object with the help of ADRestore Version 1.1, It seems it will provide you all the deleted objects alphabhetically and we have to wait until that user object is visible….Once it is visible we can restore the object,after restoring we need to manually assign display name, Alias,and windows 2000 domain Logon account this feilds value will be blank and we need to assign it manually. and in object tab if you will see it will show you the creation time when the user object has been created in my case it was created in the year 2008.After this we have run repadmin /syncall and replmon to get synchronise with other ADC.

    The same in office 365 we do have the mailbox for the account which was deleted.In office 365 on cloud the mailbox will be their up to 30 Days as per the retention set by the Microsoft and it will recognised only that account which was deleted and automatically the mailbox will get sync with the user object which was restore.

    Its a amazing tool, which reduces your downtime of your Active Directory.

  3. Sunder says:

    Good that the tool helped. Say thanks to Mark http://sysinternal.com

  4. jiju says:

    Hi Sunder,

    Its great.