Re: Accidentally removed computer accounts

Tech-Archive recommends: Speed Up your PC by fixing your registry



Anton,

If you would like to prevent this from happening again, there is a
great soltuion out there called Active Administrator by ScriptLogic.
It will automatically backup AD objects down to the attribute level
including user/computer paswwords, and allow you to quickly restore
these without going into authoritative resotore mode to bring them
back. Here is a link if you care to check it out:

http://www.scriptlogic.com/products/activeadmin/

It also includes delegation enforcement, GPO lifecycle management and
assessment and change management auditing. The price points make this
solution especially attractive.

Hope this helps!

Jerry
anton.vinokurov@xxxxxxxxx wrote:
Hi All,

I have a bunch of W2K3R2 computers in W2K3 domain. Accidentally these
computer accounts were removed from the AD. Now I cannot log on to the
domain from these computers (for sure - domain contoller has no info
about it). MS suggestion is to re-join computer to the domain back, but
the local Administrator account has been disabled, so I cannot log on
to any of these computers at all.
I have all old SIDs for missing computer accounts (from DNS). The
question is: is there any way to re-create computer accounts manually
providing an old security identifiers, so the domain controller will
start to recognize these computers again?

Yours,

Anton Vinokurov
McGill University

.



Relevant Pages

  • Re: Accidentally removed computer accounts
    ... great soltuion out there called Active Administrator by ScriptLogic. ... GPO lifecycle management and ... I have a bunch of W2K3R2 computers in W2K3 domain. ... I have all old SIDs for missing computer accounts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: OU Design with single domain AD structure
    ... The two PRIMARY OU design criteria are: ... > My indentions didn't show the actual layouts I had intended...Here's> another try... ... I have a pretty good idea about almost all> the OUs, except for the ones that will contain the computer accounts. ... > Our Adminstrators - will contain admin users and computers as well as> Global groups that membership is controlled by admins. ...
    (microsoft.public.win2000.active_directory)
  • Re: OU Design with single domain AD structure
    ... except for the ones that will contain the computer accounts. ... Our Adminstrators - will contain admin users and computers as well as ... Global groups that membership is controlled by admins. ... Here's the layouts I'm ...
    (microsoft.public.win2000.active_directory)
  • RE: Delegation of duties to junior administrator
    ... That will let you see what groups have rights to that OU. ... That gives members in this group, full admin ... All Computer accounts are in a specific OU (not the default container, ... With computers being separate from servers, this only allows the members to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Accidentally removed computer accounts
    ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Why you would need SID recriation? ... I have a bunch of W2K3R2 computers in W2K3 domain. ... I have all old SIDs for missing computer accounts. ...
    (microsoft.public.windows.server.active_directory)