Jump to content

Recommended Posts

Posted

Hi Guys,

 

i will give you the story, we was running windows updates on our physical hyper-v server over the half term, did some reboots and such, came back up fine. shut the server down as you do and cleaned all the dust out as it was caked in it.

plugged it all in, switched it on, everything was still fine. logged in did a quick check as you do. made sure the Domain Controller VM was back up and it was fine.

 

this week Monday we had a phone call saying the all the teachers cannot login, OK. so i logged into the DC VM gone into AD and the teacher OU was there but all the teacher user accounts had gone? no one has been on the server apart from myself to run updates and reboots. i am an honest person and if i had done this i would own up.

 

we cannot work out why this might of happened, i sure windows updates would not cause this nor doing a shutdown.

 

any ideas, has anyone had anything like this happen before?

 

we would like to know why this might of happened.

 

today - two of their desktops on the Domain have stopped working, they do not want to pick up any Group Polices. the user can login but they are missing all the essential GP's

I've tried everything and to no avail, this has only happened since the teacher user accounts went missing on Monday.

 

when i did a gpresult /r - i got a message saying the user has does not have RSOP data

tired logging in as other people on that machine, same thing.

logged in as Domain admin, same thing

 

i got the user to logon else where and his user profile was fine.

 

I've taken the machine off the domain, deleted it from AD re-joined it back, tried/checked DNS, DHCP, gave it a static IP nothing

 

only thing i haven't tried is

 

- changing the computer name

- move the desktop somewhere else and try?

 

Again any idea's guys before i go mad!

Posted

I am guessing you don't have Audit account management enabled? Might be worth doing for any potential future reoccurrences like this

https://blogs.technet.microsoft.com/abizerh/2010/05/27/tracing-down-user-and-computer-account-deletion-in-active-directory/

 

But for the here and now, with only one DC I assume you are not replicating the AD anywhere (if you are then check for corruption on one or both ends).

 

Check the server logs for those times, see if any automatic windows updates/reboots happened between you doing the work and the Monday.

 

Apart from that does anyone else have access to the server that could you gone in without you knowing?

 

In future it might be good practice to enable those OU's and objects protection from accidental deletion.

 

Could be worth running the Active Directory best practices analyser. Just to see if it kicks anything up.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...