Findout previous deleted domain controller computer name frome SID

Hi
I recently suspicious that some one in my company join new additional domain controller  to my primary DC and after replication and get the domain controller partitions ,he disjoint the new additional dc .
I got the his event in my dns log :
The DNS server was unable to create a resource record for  d630907c-e2f4-41cf-a2c6-adc087f25f46._msdcs.metro.com. in zone metro.com. The Active Directory definition of this resource record is corrupt or contains an invalid DNS name. The event
data contains the error.
I want to translate the DNS alias sid :d630907c-e2f4-41cf-a2c6-adc087f25f46
to computer name in order to find who did this?
is there a way to find out previous DC computer name after hey disconnected or DC computer account deleted?
I wonder to know ho did this?
Regards

The guid you're referring to corresponds to the NTDS Settings object for the "lost" DC. You can do this in Powershell to get the DirectoryEntry for that guid:
[adsi]"LDAP://<GUID=d630907c-e2f4-41cf-a2c6-adc087f25f46>"
However, if the object has been deleted, you need to perform another query (in Powershell as well):
$guid = ([guid]"d630907c-e2f4-41cf-a2c6-adc087f25f46")
Get-ADObject -SearchBase "DC=metro,DC=com" -IncludeDeletedObjects -Filter { objectGuid -eq $guid }
Note that by default you need to be a member of Domain Admins or Administrators to be able to query AD for deleted objects.
Best Regards,
Carl S
All code is provided as-is with no guarantees. Always try it out in a test environment before applying it in a production environment.

Similar Messages

  • Disabled domain controller computer object

    on one of our DC's DC01 (RID/PDC) the computer account was disabled this was showing as disabled on all DC's in the domain. I have managed to fix it by changing the
    User account control attribute on that object to 532480 in adsiedit on all DC's. I then had to reset the secure password for DC01 using netdom resetpwd as it had got out of sync. Everything now seems fine replication/authentication/DCdiag/netdiag
    Why did this occur ? it looks like you cant disable a Domain controller computer account from the GUI ? am i likely to get any further issues

    I have seen similar situations on the net but I have not found an explanation to this behavior (assuming here that this is a bug in the system). You can see references here:
    http://www.kenmanohar.com/blog/tag/domain-controller-computer-account-disabled/
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/9fb5084e-b27d-48c8-92e7-8818fc769a90/disabled-domain-controller-computer-account
    You might check if any of the administrators have mistakenly changed the value of UserAccountControl attribute. By using ADUC, you would not be able to disable the computer account of a DC.
    Please also enable the auditing in AD so that you can get more details about what happened in the future: http://technet.microsoft.com/en-us/library/cc731607(v=ws.10).aspx
    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Get Active Directory User Last Logon
    Create an Active Directory test domain similar to the production one
    Management of test accounts in an Active Directory production domain - Part I
    Management of test accounts in an Active Directory production domain - Part II
    Management of test accounts in an Active Directory production domain - Part III
    Reset Active Directory user password

  • How to delete previously deleted files off iphone PERMANENTLY from database

    Someone I happen to know hacked my iPhone 4s. They took my iPhone when I left it out. They plugged it into their Macbook and used software I beleive called Wondershare Data Recovery, to raid my phone and go through confidential files I had previously deleted on my phone. They went through text messages, photos and files that were personally confidential to myself. They made it aware they did this because they personal told me they would continue "tracking" what I do on my phone because my files will be backed up onto their computer. I was also made aware that after I decided to put a password on my phone, the person told me "It doesnt matter if you put a password on the phone since my phone is now ENCRYPTED with the laptop".
    My first question is how do I go about this situation. Is there a program i can use to fully erase all the "deleted" files i thought were deleted previously on my phone? Is there a data base i can PERMANENTLY delete my files from so they can never be acessed in a data base in the future?
    How do I make sure i dont continue to get stalked by this "close friend" in the future?

    If you have permanently deleted iPhone file thoroughly, No one can get you personal information and data from iPhone,after you sell, donate or give it away.
    To permanently delete photo,video and other files on iPhone,you can use a iPhone data eraser,there are some iPhone data eraser software in the market, but few can be completely and permanently delete the data on iPhone, even if data has been cleared, some professional iPhone data recovery software can recover them later.
    Please read this use guide about how to Permanently Erase iPhone Data Before Selling your iPhone.So
    <Link Edited By Host>

  • Delete job number & Job name from standard table

    Dear Experts,
    i want to delete Job Number & job description from table when my job is finished.
    thanx

    hi use the function module..HR_JOB_DELETE
    regards,
    venkat

  • Get Network Computer name from IP address

    On a windows machine I want to be able to get the computer name if I know the IP. I have a VI that will return the MAC Address which is useful since my wireless access point does not have a static IP, I can search for the MAC Address to find it and then access it, but would like to add the feature of returning the computer name.. How can I do this?
    Thanks
    Jeff
    Jeff D.
    OS: Win 7 Ultimate
    LabVIEW Version: 2011,2010,2009 installed
    Certified LabVIEW Architect

    Attached screenshot shows how to find the name of the network adapters
    on your computer... the STR IP function has Multiple Outputs enabled to
    produce an array. 
    If you wanted to find the computer name of another computer you could
    feed the IP address string "x.x.x.x" to the STR IP function.
    Attachments:
    Screenshot.jpg ‏66 KB

  • Change Computer name from previous ower's

    My computer still is named Matt's Computer from the previous owner. How do I change it?

    You'll need admin privileges; go to System Preferences, click on the 'Sharing' preference pane. The computer's name is displayed at the top. Just click on it and change to whatever you want.
    eMac   Mac OS X (10.4.4)  

  • Delete large number of names from address book

    By mistake I imported a large database of names and addresses into Address book a while ago.
    I now find the Address book is too bulky and wish to remove 80% of the names.
    How can I do this easily? Or is is simple to start a new address book from scratch?
    Thanks

    Thanks, rkaufmann87, I've tried that many times thinking I can sneak up on it (funny when we're to the point to try ANYTHING)----AB not cooperating on that one, either. The group will delete, but the names/cards are still on the main list and won't delete from the main Address Book. If you "select all" it goes back to the Address Book main list, not the group which is wanting to be deleted.

  • How does one flush old computer names from network finder?

    Whenever I select Network from the Go->Networks Finder menu item, the list of networked computers that appear in the finder includes names of computers that no longer exist on my network. I have tried reinitializing the com.apple.finder.plist and com.apple.recentitems.plist without success. I am running Yosemite and this problem appears on all 3 of my Macs (iMac, mini, and MB Pro). Does anyone know how to clear this list?

    Welcome  
    You may also need to delete the Safari Forms AutoFill keychain.

  • How to delete old email source name from emails I send?

    I used to work at company and sent email from that email address. I do not work there now but when I send new or replies to anyone, that old email address is plunked into the from email.

    No....Did not work....I followed your instructions numerous times.
    Problem....Remains....
    When I compose an new email the FROM email address list alphabetically as AAAA, BBBB, CCCC. If I don't select CCCC it automatically sends the email from AAAA which no longer exist. Recipients of the email who reply to the AAAA email address are informed no such address exist.
    I agree....
    My question is How do I delete BOTH AAAA and BBBB email addresses from being used? Is there a simple table I can access?
    Thank you, WRELAM

  • Delete of my account - skype name from skype direc...

    Hello.
    I am wish to delete my account (Skype Name from the Skype directory)
    I have already taken all steps described in: 'Can I delete my Skype account?' ...deleted all personal information (name, e-mail, etc...)
    I also tried to contact the customer support with my request ...tried all the steps there as well but it took me all around back here.
    Is there any direct e-mail contact option? Can someone assist me?
    Thanks.

    I think that the instructions on how to contact customer service is clear enough and easy to follow.  Yet, if that one is not working for you (though contacting via webform usually results to faster responses), you can also try to send an email to [email protected] .
    IF YOU FOUND OUR POST USEFUL THEN PLEASE GIVE "KUDOS". IF IT HELPED TO FIX YOUR ISSUE PLEASE MARK IT AS A "SOLUTION" TO HELP OTHERS. THANKS!
    ALTERNATIVE SKYPE DOWNLOAD LINKS | HOW TO RECORD SKYPE VIDEO CALLS | HOW TO HANDLE SUSPICIOS CALLS AND MESSAGES

  • Use old domain controller AD user profile with new domain (profile changed)

    Dear All,
    I have built Win Server 2012 for Domain migration from Windows Server 2003 to Windows Server 2012. I have tested all thing on VMware including user creation and tested Domain join using power shell for Win 7 and .VBs batch file for Win XP computers all thing
    are working fine.
    Let 1st I introduce my current environment. I have existing Win Server 2003 domain controller (abc.com) with 130 client computers and 200 users I am going to plan migrate my current environment to Win server 2012 Domain (xyz.com) Keep in mind that Domain
    name is changed but Domain Controller (Server) names are same i.e MY-PDC . I have tested domain join on multiple computers using existing clone of client computers and create all existing users using .csv file and power shell with required
    credentials and OU.I am facing the user profile issue when I join domain and login with existing user which was previously the user of same computer the required profile does not login and computer creates new user profile in Document and Settings section
    of Win XP.
    I need your expert opinions because copy old profile data and create new outlook profile for each user is a big headache for any one. Hope you people can understand and help me in this issue.
    Please provide best answer and result on priority I will be thankful to all of you.
    Regards,
    Arsalan

    Hi Arsalan,
    Please check if USMT can help you to achieve this target.
    User State Migration Tool 4.0 User's
    Guide
    Meanwhile, please also refer to following articles and check if can help you.
    How
    to Migrate Windows User Profile to New Account
    Keeping user old domain profile
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft
    does not guarantee the accuracy of this information.
    If anything I misunderstand or any update, please don’t hesitate to let us know.
    Hope this helps.
    Best regards,
    Justin Gu

  • Reimaged Win 7 PC still cannot ping either domain controller by IP Address, but sees other PCs fine.

    OK so this is weird one: I have a Window 7 box that when I went to use it, I discovered that it no longer had access to the internet, but it did see the other PCs on the network. After trying completely different network ports then removing/reading the NIC
    and using system restore, I decided to reimage it from scratch and deleted the PC's name from the domain. Here's where it gets strange: Even after a completely wiped and reloaded PC from a known good template, it DOES get an IP address from DHCP/DC/DNS server
    (same machine) it can view the other workstations on the domain, but it cannot even get a ping reply back from either of our 2 domain controllers, much less join the domain and it still does not see the internet. This one really has me kerfuffled! It is the
    only PC with this problem and I've already scorched the HD.

    Hi,
    According to your description, the Windows 7 PC has joined the domain before going wrong. And after a series of operations the Windows 7 still can’t access Internet and it can’t ping DC by IP address.
    Have you checked the Windows Firewall to see if the firewall blocked the ICMP packet?
    Due to the Windows PC can get an IP address from DHCP server as mentioned above, so what IP address the Windows 7 PC get? And what is the IP address of the Windows 7’s DNS server? We can use
    ipconfig /all command to print out the TCP/IP configuration. Because we can’t ping DC by IP address, maybe the Windows 7 PC can’t connect to DHCP server. If a DHCP client can’t connect the DHCP server, it can assign a private IP address of
    169.254.0.0/16 network to itself. Then the DHCP client will attempt to find an available DHCP server every five minutes. Obviously, computer with a private IP address can’t access Internet.
    Best Regards,
    Tina

  • Moving domain controller vm between Hyper-V 2012 R2 hosts

    Hello,
    I have one stand alone Hyper-V host - hvserver01 (Hyper-V Server 2012 R2) and 3 VM's running on it. One Virtual machine is our company's additional Domain controller.
    I'm planning to install an additional hyper-v host - hvserver02 (Hyper-V Server 2012 R2) as well.
    I have the following task to perform: I need to move domain controller virtual machine from hvserver01 to hvserver02.
    So, for this operation which tool do i need - move, export/import or something else... ? or it will be necessary to install a new DC and then demote the old one.. ?
    Is there a some special requirements when moving DC from one virtual host to another.. ?
    And also, - MS Hyper-V Server 2012 R2 is installed on both Hyper-V hosts.
    Do you have some advices ?
    Thanks in advance,

    There's no difference between a VM acting as your DC and any other VM as far as live-migration is concerned.
    You should use live-migration. The VM will remain up and running during the entire process. Both Hyper-V hosts should be domain members. They should have vSwitches with the same exact name. They should have same CPU type, or configure CPU compatibility on
    the VM. Configure Live-migration setting on each host. You can use Hyper-V Manager for live-migration..
    Sam Boutros, Senior Consultant, Software Logic, KOP, PA http://superwidgets.wordpress.com (Please take a moment to Vote as Helpful and/or Mark as Answer, where applicable) _________________________________________________________________________________
    Powershell: Learn it before it's an emergency http://technet.microsoft.com/en-us/scriptcenter/powershell.aspx http://technet.microsoft.com/en-us/scriptcenter/dd793612.aspx

  • Make a Mac's Computer Name the Same as it's OD  Computer Record Name?

    I heard someone mention that its possible (at least in 10.5 server) to make a Mac's Computer name become exactly as its OD Computer Record name is (at the time of binding). I assume this would be a setting in Server Admin/OD or in WGM perhaps. I cant find the setting. Can you locate it for me?
    Im running a test Leopard OD master in Advanced mode on an Xserve Xeon.

    OK, let me give you a similar scenario regarding computer record names.
    I had previously setup OD to set computer names based the computer record name once the Macs were bound to OD.
    I decided later that that naming scheme will not work (I need the computer (host) name and the OD computer record name to be different for logisitical reasons - long story). I unbound my OD clients and trash all LDAP settings to start over from scratch. One problem:
    I cant for the life of me find that checkbox on my OD server to disable that setting. I have looked everywhere. I check WGM and Server Admin too. The post you made earlier doesn't look like the steps I took to setup the option to force the computer name from the record name. I simply checked a box. I also did enable authenticated binding either.
    I have a test OD lab right now. None of the servers and clients are in production, so I have the luxury of experimenting a little before we go live in Q1 2008.

  • FolderShare Computer name wrong and will not Change

    Last night I got my new Quad, and used the Firewire transfer method from my powerbook to the Quad to set up everything. It worked very well with an exception with FolderShare.
    In the transfer, the computer name from the Powerbook was copied over to the new computer. Hence, in prefernces on Foldershare, it shows the same comuter name for the PB and the Quad.
    I tried the following without success:
    First, I changed the name of my Quad in System Preferences/Sharing and rebooted, but Foldershare keeps reverting back to my old PB name.
    Next, I deleted Foldershare and the preference file and reinstalled. But in FolderShare Settings/My Account is still shows the old PB computer name.
    I tried logging out and chaning it, but it keep defaulting to the old PB computer name.
    Any ideas what to try next??? FolderShare must either store the computer name some where else or else there is another place in OS X that the computer name is stored when I first copied all my files over.

    Before you can successfully rename the computer, you must ensure file sharing is turned off.
    Once file sharing is off, rename the machine and/or folders.
    The change should be immediate (and should not require a reboot)

Maybe you are looking for

  • Error while running a trusted application in OC4J

    I have created a trusted application to access the CDB and I can directly run this application in the Embedded OC4J and get the right result. The login code is : public ManagersFactory loginCDB(){ FdkCredential credential = new S2SFdkCredential( "orc

  • Is it possible to sort photos by the date imported?

    The majority of my photos were taken without the date being set in the camera. In previous versions of iphoto it appeared as though each time I imported images (now called an event) the events were put in the order that they were imported. I would li

  • No photos in Photostream, but 3rd party apps show that the photos are there

    I am having a problem, not sure where to post it. Here is what is happening: 1. Take a photo with iPhone 4 2. Syncs to great up until last night 3. Last night I brought a photo into Nik's Snapseed app on my iPad (import from Photostream) 4. Now, my s

  • HT1277 How do I sync Google Apps mail account with Apple Mail 5.2?

    How do I sync Google Apps mail account with Apple Mail 5.2?

  • Wired guest

    Respected members of this community... :) I need help. The last couple of days i spend implementing unified wireless at a customers site. We used the latest versions of the controller and WCS software. This new software offers a new feature, wired gu