[ Team LiB ] |
Recipe 16.16 Searching for Deleted Objects16.16.1 ProblemYou want to search for deleted objects. 16.16.2 Solution16.16.2.1 Using a graphical user interface
16.16.2.2 Using a command-line interfaceAs of this writing, none of the standard command-line tools provide a way to search for deleted objects. 16.16.2.3 Using VBScriptIt is currently not possible to search for deleted objects with ADSI or ADO. 16.16.3 DiscussionWhen an object is deleted in Active Directory, it is not completely deleted. The original object is removed, but a tombstone (deleted) object takes its place in the Deleted Objects container within the naming context it was deleted in. See Introduction in Chapter 16 for more on tombstone objects. Both the Deleted Objects container and tombstone objects themselves are hidden by default in tools, such as Active Directory Users and Computers and ADSI Edit. To query tombstone objects you have to enable the Return Deleted Objects LDAP control, which has an OID of 1.2.840.113556.1.4.417. When that control is enabled, you can perform searches for tombstone objects by specifying a search filter that contains (isDeleted=TRUE) in it. Only members of the administrator groups can perform searches for tombstone objects. 16.16.4 See AlsoMSDN: Retrieving Deleted Objects |
[ Team LiB ] |