Presentation is loading. Please wait.

Presentation is loading. Please wait.

Presented by Mark Minasi SESSION CODE: SIA306.

Similar presentations


Presentation on theme: "Presented by Mark Minasi SESSION CODE: SIA306."— Presentation transcript:

1 Presented by Mark Minasi help@minasi.com www.minasi.com SESSION CODE: SIA306

2

3

4

5

6

7 Deletion, Pre-AD Recycle Bin

8

9 What ADUC Shows You OU

10 OU ADUC with View /Advanced Features, ADSIEDIT or LDP ( = "new stuff")

11 What LDP (an admin tool we'll meet soon) shows, when equipped with the right "LDAP Control" OU

12

13 Now, suppose someone wants to delete Mark… Let's say that Mark has an objectGUID value of 6e2971d91 (and yes, that GUID is way too small, but it's just an example) OU

14 After deletion… New place! New name! OU

15

16

17

18

19 Next, click Connection / Connect, which lets you tell LDP which server you'd like to connect to. You can punch in a DC name but just clicking "OK" will do the job.

20 You're now connected to a particular DC, but you aren't really logged into the directory service yet, even if you're logged on as an enterprise admin. To "log onto the DS," you "bind" to the DS by clicking Connection / Bind and then probably just clicking OK. If, however, you need to proffer different credentials, choose the "Bind with credentials" option, fill in the creds and click OK

21

22 We're about to ask LDP to show us my domain bigfirm.com, but by default LDP spares us the macabre view of The Dead Things. We are, however, made of tougher stuff than that, so we'll tell it that we can handle the truth by clicking the drop-down labeled "Load Predefined" and choose "Return deleted objects," as you see in the lower right-hand part of the dialog at left. Then click "OK" to return to LDP. Just be sure that the "Active Controls" field contains 1.2.840.113556.1.4.417.

23

24 Click on "Deleted Objects," and, well, nothing happens. There's another LDP quirk – any time you want examine something in the left- hand pane, doubleclick it and it'll appear in the right-hand pane. If I do that and then double click a deleted user "mark," it looks like this:

25

26

27

28

29

30

31

32 how long before it's gone forever?

33

34

35

36

37 bringin' them back to life… both before and after ADRB

38

39

40

41

42

43

44 In the Modify dialog box, create the "delete isDeleted" command by type "isDeleted" in the "Attribute: field inside the "Edit Entry" group Click the "Delete" radio button in the "Operation" group Click Enter to queue it Check the "Extended" check box so that LDP knows to use the "let me see deleted stuff" control

45 Now, the first command's in the queue; time for the second. In "Edit Entry," change "Attribute:" to "distinguishedName" Enter a new DN in "values:" In "Operation," click "Replace" as we're not wiping out the DN, we're replacing it Then click Enter to get it queued in the "Entry List" field

46 With both commands queued in "Entry List," double-check that you remembered to check "Extended" and then click Run… … and your account's returned! (but disabled)

47

48

49

50

51

52

53

54

55

56

57

58

59

60

61

62

63

64

65

66

67

68

69 Click File / PowerPack Management…

70 Click Import…, navigate to ADRB PowerPack Click OK Click Close

71

72

73 Learn more about our solutions: http://www.microsoft.com/forefront Try our products: http://www.microsoft.com/forefront/trial

74 www.microsoft.com/teched www.microsoft.com/learning http://microsoft.com/technet http://microsoft.com/msdn

75

76 Sign up for Tech·Ed 2011 and save $500 starting June 8 – June 31 st http://northamerica.msteched.com/registration You can also register at the North America 2011 kiosk located at registration Join us in Atlanta next year

77

78


Download ppt "Presented by Mark Minasi SESSION CODE: SIA306."

Similar presentations


Ads by Google