Professional Windows Server 1002003 Security A Technical Reference [Electronic resources] نسخه متنی

اینجــــا یک کتابخانه دیجیتالی است

با بیش از 100000 منبع الکترونیکی رایگان به زبان فارسی ، عربی و انگلیسی

Professional Windows Server 1002003 Security A Technical Reference [Electronic resources] - نسخه متنی

Roberta Bragg

| نمايش فراداده ، افزودن یک نقد و بررسی
افزودن به کتابخانه شخصی
ارسال به دوستان
جستجو در متن کتاب
بیشتر
تنظیمات قلم

فونت

اندازه قلم

+ - پیش فرض

حالت نمایش

روز نیمروز شب
جستجو در لغت نامه
بیشتر
لیست موضوعات
توضیحات
افزودن یادداشت جدید







Reanimating Users from the Deleted Objects Store


In a Windows Server 2003 domain, it may be possible to recover deleted users from the Deleted Objects Store using the support tool ldp.exe. This process is called reanimating. Reanimation is not supported if a Windows Server 2003 DC has been upgraded from a Windows 2000 DC. User objects in the undeleted object stores only retain their SID, ObjectGUID, LastKnownParent, and SAMaccountName attributes, so you have to reset passwords, profiles, home directories, and group memberships after reanimating the account. The reanimated user account has the same SID. The SIDHistory attribute is not preserved.


1.

Click Start, Run, and then type ldp.exe. Click OK.

2.

Use the Connection menu to connect and bind to the Windows Server 2003 domain controller.

3.

From the Options menu, click Controls.

4.

Click the Load Predefined list Return Deleted Objects.

5.

In Control Type, click Server, and then click OK.

6.

From the View menu, select tree and enter the distinguished name path (the DN path, cn=deleted Objects,dc=domainname,dc=domainextension) of the delete object container in the domain where the deletion occurred, and then click OK.

7.

Double-click the deleted objects container.

8.

Double-click the object to be undeleted or reanimated.

9.

Right-click the object to reanimate and then click Modify.

10.

In the Edit Entry Attribute box, type isDeleted and leave the values box blank.

11.

Click the Delete Option button, and then click Enter.

12.

In the Attribute box, type distinguishedName.

13.

In the values box, type the new DN path for the reanimated object:


Cn=delteduser,ou=usersou,dc=domainname,dc=domainextension

14.

Alternatively, append the value of the deleted object's LastKnownParent attribute to tie CN value and past the full DN path in the values box.

15.

In the Operation box, click REPLACE.

16.

Click Enter.

17.

Click to select the Synchronous check box.

18.

Click to select the Extended check box.

19.

Click RUN.

20.

Click options followed by Controls, click to clear Return Deleted Objects, and then click OK.

21.

Reset user account passwords, profiles, home directories, and group memberships for the reanimated user.

22.

Enable the reanimated account in Active Directory Users and Computers.

23.

Clean up the account and reconnect it with any Active Directory integrated application. For example, if Microsoft Exchange is used for email, remove Exchange attributes and reconnect the user to his Exchange mailbox.


WARNING: Reanimation Should Not Be the Default Backup Strategy

Reanimation may or may not work. It should not be the only strategy in place to recover from deletions.


/ 194