The presence of Active Directory recycling features greatly facilitates the management of the Active Directory. Before 2008r2, every time you delete an Active Directory account, you need to go to directory Restore mode to restore it. And it's tedious. Now let me introduce you to WINDOWS2008R2 's new functional Active Directory Recycle Bin.
Method one uses Active Directory Module for Windows PowerShell to restore
1. To use the Active Directory Recycle Bin, the functional level of the domain and forest is for Windows Server 2008r2 or above
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M01/85/DD/wKioL1etFvnxhgv4AAAMYFelZok734.png-wh_500x0-wm_3 -wmp_4-s_2876138429.png "style=" Float:none; "title=" 1.png "alt=" Wkiol1etfvnxhgv4aaamyfelzok734.png-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DE/wKiom1etFvqhLdQ1AAAISxTRpTU299.png-wh_500x0-wm_3 -wmp_4-s_2953489779.png "style=" Float:none; "title=" 2.png "alt=" Wkiom1etfvqhldq1aaaisxtrptu299.png-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DD/wKioL1etFvqTqWFsAAAKmoGOIdg154.png-wh_500x0-wm_3 -wmp_4-s_191538657.png "style=" Float:none; "title=" 3.png "alt=" Wkiol1etfvqtqwfsaaakmogoidg154.png-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DD/wKioL1etFvriz5CKAAAZbtWNgMc517.png-wh_500x0-wm_3 -wmp_4-s_1884967573.png "style=" Float:none; "title=" 4.png "alt=" Wkiol1etfvriz5ckaaazbtwngmc517.png-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DE/wKiom1etFvuDwwulAAAMKAbKxt0136.png-wh_500x0-wm_3 -wmp_4-s_666385436.png "style=" Float:none; "title=" 5.png "alt=" Wkiom1etfvudwwulaaamkabkxt0136.png-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DE/wKiom1etFvvQPuu8AAAIQelfN0g639.png-wh_500x0-wm_3 -wmp_4-s_3232772202.png "style=" Float:none; "title=" 6.png "alt=" Wkiom1etfvvqpuu8aaaiqelfn0g639.png-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DD/wKioL1etFvuyy_RfAAAJj5HEqAc564.png-wh_500x0-wm_3 -wmp_4-s_291695249.png "style=" Float:none; "title=" 7.png "alt=" Wkiol1etfvuyy_rfaaajj5heqac564.png-wh_50 "/>
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M01/85/DE/wKiom1etFvyCMSRIAAAKDs7zK2k608.png-wh_500x0-wm_3 -wmp_4-s_4202850735.png "style=" Float:none; "title=" 8.png "alt=" Wkiom1etfvycmsriaaakds7zk2k608.png-wh_50 "/>
2. Enable Recycle Bin feature using active Directory Module for Windows PowerShell enabled
Open Active Directory Module for Windows PowerShell in Administrative Tools, enterEnable-ADOptionalFeature –Identity ‘CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration, DC=contoso,DC=local‘ –Scope ForestOrConfigurationSet –Target ‘contoso.local‘
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DD/wKioL1etHBPxf2Z8AADM9Gp5l3I031.jpg-wh_500x0-wm_3 -wmp_4-s_972026676.jpg "title=" 10.jpg "alt=" Wkiol1ethbpxf2z8aadm9gp5l3i031.jpg-wh_50 "/>
3. Check that the Recycle Bin function is turned on normally. Get-adoptionalfeature-filter {name-like "*"} with the following command
is that the Recycle Bin feature is enabled. the value of enabledscopes is null, which means that the feature is not enabled
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M02/85/DE/wKiom1etHGCiiZQTAAAdm7gCEXM383.png-wh_500x0-wm_3 -wmp_4-s_109108295.png "title=" 11.png "alt=" Wkiom1ethgciizqtaaadm7gcexm383.png-wh_50 "/>
4. Delete Account Test
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M01/85/DD/wKioL1etHwnBspylAAAdbesIb14139.png-wh_500x0-wm_3 -wmp_4-s_4042375620.png "style=" Float:none; "title=" 12.png "alt=" Wkiol1ethwnbspylaaadbesib14139.png-wh_50 "/>
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M00/85/DE/wKiom1etHwnCnvnlAAAmfmNLs8s177.png-wh_500x0-wm_3 -wmp_4-s_1683069229.png "style=" Float:none; "title=" 13.png "alt=" Wkiom1ethwncnvnlaaamfmnls8s177.png-wh_50 "/>
5. use get-adobject–searchscope subtree–filter {name–like "*"}–includedeletedobjects command to view deleted objects. You can see that the deleted property of 2008R2 is true, representing the deleted
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M00/85/DD/wKioL1etIMijD3JWAAAdW8766sY311.png-wh_500x0-wm_3 -wmp_4-s_3243820910.png "style=" Float:none; "title=" 14.png "alt=" Wkiol1etimijd3jwaaadw8766sy311.png-wh_50 "/>
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M02/85/DE/wKiom1etIMjRQke9AAAZ6S93C4o846.png-wh_500x0-wm_3 -wmp_4-s_1801813712.png "style=" Float:none; "title=" 15.png "alt=" Wkiom1etimjrqke9aaaz6s93c4o846.png-wh_50 "/>
6. Use the command in order to restore the deleted user,
Note: The long string of characters followed by the identity is the GUID of the OU and the user, and we restore the user by defining the GUID, which can be seen through get-adobject, if an OU that contains a user needs to be restored, the OU must be restored before the user
Restore-adobject-identity GUID
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DD/wKioL1etIVbRKituAAAb8pRtpoA040.png-wh_500x0-wm_3 -wmp_4-s_2044142111.png "style=" Float:none; "title=" 16.png "alt=" Wkiol1etivbrkituaaab8prtpoa040.png-wh_50 "/>
Restore succeeded
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DE/wKiom1etIVbTCfiSAAAa36Pke9E691.png-wh_500x0-wm_3 -wmp_4-s_3331508813.png "style=" Float:none; "title=" 17.png "alt=" Wkiom1etivbtcfisaaaa36pke9e691.png-wh_50 "/>
You can use this command to find a restore.
Get-adobject-filter {displayname-eq "user name"}-includedeletedobjects | Restore-adobject
Method Two: Use the Lap.exe mode to turn on the Recycle Bin function and restore the account
Connection
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M02/85/DF/wKiom1etN2-RivWcAABEKo2gQbE255.jpg-wh_500x0-wm_3 -wmp_4-s_3456700314.jpg "style=" Float:none; "title=" 1.jpg "alt=" Wkiom1etn2-rivwcaabeko2gqbe255.jpg-wh_50 "/>
Binding
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M02/85/DF/wKioL1etN2-BDtgJAADDGUaVeDg232.jpg-wh_500x0-wm_3 -wmp_4-s_936315806.jpg "style=" Float:none; "title=" 2.jpg "alt=" Wkiol1etn2-bdtgjaaddguavedg232.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DF/wKioL1etN3Dzn4zwAACGsvrLMV4476.jpg-wh_500x0-wm_3 -wmp_4-s_3674561370.jpg "style=" Float:none; "title=" 3.jpg "alt=" Wkiol1etn3dzn4zwaacgsvrlmv4476.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/85/DF/wKiom1etN3ChuaSkAACp_8WDGNY392.jpg-wh_500x0-wm_3 -wmp_4-s_1727409437.jpg "style=" Float:none; "title=" 4.jpg "alt=" Wkiom1etn3chuaskaacp_8wdgny392.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M00/85/DF/wKioL1etN3HRbQKfAACfrAJ5fMk470.jpg-wh_500x0-wm_3 -wmp_4-s_2524508249.jpg "style=" Float:none; "title=" 5.jpg "alt=" Wkiol1etn3hrbqkfaacfraj5fmk470.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M02/85/DF/wKiom1etN3Hy2IivAADw34z9eGE050.jpg-wh_500x0-wm_3 -wmp_4-s_1309743914.jpg "style=" Float:none; "title=" 6.jpg "alt=" Wkiom1etn3hy2iivaadw34z9ege050.jpg-wh_50 "/>
When you enable the Active Directory Recycle Bin feature using the Ldp.exe mode, you need to use the featureguid of the feature, and we use the GET command to look at the GUID of the feature.
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M00/85/DF/wKiom1etN3LQ0ybzAAChjn4gfBc833.jpg-wh_500x0-wm_3 -wmp_4-s_2835722975.jpg "style=" Float:none; "title=" 7.jpg "alt=" Wkiom1etn3lq0ybzaachjn4gfbc833.jpg-wh_50 "/>
Enable Recycle Bin Feature
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M01/85/DF/wKiom1etN3KjRyNeAADgFm4dN-E881.jpg-wh_500x0-wm_3 -wmp_4-s_3241109067.jpg "style=" Float:none; "title=" 8.jpg "alt=" Wkiom1etn3kjryneaadgfm4dn-e881.jpg-wh_50 "/>
Enable success
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/85/DF/wKiom1etN3Oi70XkAAD7OrB9Rj4503.jpg-wh_500x0-wm_3 -wmp_4-s_994256543.jpg "style=" Float:none; "title=" 9.jpg "alt=" Wkiom1etn3oi70xkaad7orb9rj4503.jpg-wh_50 "/>
Delete Account Test
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DF/wKiom1etN3TyggF4AAB14bCgEDE099.jpg-wh_500x0-wm_3 -wmp_4-s_764008952.jpg "style=" Float:none; "title=" 10.jpg "alt=" Wkiom1etn3tyggf4aab14bcgede099.jpg-wh_50 "/>
Restore your account. Open Ldp.exe Selection control
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/85/DF/wKioL1etN3SzPVMUAAA4zCgmxv8296.jpg-wh_500x0-wm_3 -wmp_4-s_1423937844.jpg "style=" Float:none; "title=" 11.jpg "alt=" Wkiol1etn3szpvmuaaa4zcgmxv8296.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M02/85/DF/wKioL1etN3TyIODqAABENbHaxIE917.jpg-wh_500x0-wm_3 -wmp_4-s_2233332347.jpg "style=" Float:none; "title=" 12.jpg "alt=" Wkiol1etn3tyiodqaabenbhaxie917.jpg-wh_50 "/>
Connection--binding
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DF/wKiom1etN3SCWDZyAAA1PT76ayo105.jpg-wh_500x0-wm_3 -wmp_4-s_3757749003.jpg "style=" Float:none; "title=" 13.jpg "alt=" Wkiom1etn3scwdzyaaa1pt76ayo105.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/85/DF/wKiom1etN3WzafSvAAEu19y8KdU096.jpg-wh_500x0-wm_3 -wmp_4-s_2892755642.jpg "style=" Float:none; "title=" 14.jpg "alt=" Wkiom1etn3wzafsvaaeu19y8kdu096.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M01/85/DF/wKiom1etN3XwZC7AAAF7seVPgt8774.jpg-wh_500x0-wm_3 -wmp_4-s_1853644733.jpg "style=" Float:none; "title=" 15.jpg "alt=" Wkiom1etn3xwzc7aaaf7sevpgt8774.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s5.51cto.com/wyfs02/M01/85/DF/wKioL1etN3bQ4M-FAAE9oNrW4zg345.jpg-wh_500x0-wm_3 -wmp_4-s_2794804608.jpg "style=" Float:none; "title=" 16.jpg "alt=" Wkiol1etn3bq4m-faae9onrw4zg345.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M00/85/DF/wKiom1etN3egxjhmAAFMlrqqSW8861.jpg-wh_500x0-wm_3 -wmp_4-s_3003627280.jpg "style=" Float:none; "title=" 17.jpg "alt=" Wkiom1etn3egxjhmaafmlrqqsw8861.jpg-wh_50 "/>
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M01/85/DF/wKioL1etN3fg8vR4AADxTiZAGCo398.jpg-wh_500x0-wm_3 -wmp_4-s_2007465248.jpg "style=" Float:none; "title=" 18.jpg "alt=" Wkiol1etn3fg8vr4aadxtizagco398.jpg-wh_50 "/>
Then change the value of the Edit entry property to "distinguishedname" and change the value to "cn=2008r2,ou=test,dc=contoso,dc=local"
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M02/85/DF/wKioL1etN3jjU1HAAAE1KuoBPsg983.jpg-wh_500x0-wm_3 -wmp_4-s_1497559628.jpg "style=" Float:none; "title=" 19.jpg "alt=" Wkiol1etn3jju1haaae1kuobpsg983.jpg-wh_50 "/>
You can see that the account has been restored
650) this.width=650; "Src=" Http://s4.51cto.com/wyfs02/M00/85/DF/wKioL1etOQ-DvEnFAABcYmm1B-M657.jpg-wh_500x0-wm_3 -wmp_4-s_703656668.jpg "title=" 20.jpg "alt=" Wkiol1etoq-dvenfaabcymm1b-m657.jpg-wh_50 "/>
This article is from the "Legend" blog, make sure to keep this source http://cyan2009.blog.51cto.com/504539/1837206
WIN2008R2 Active Directory Recycle Bin function