Reanimating Users from the Deleted Objects Store

In a Windows Server 2003 domain, it may be possible to recover deleted users from the Deleted Objects Store using the support tool ldp.exe. This process is called reanimating. Reanimation is not supported if a Windows Server 2003 DC has been upgraded from a Windows 2000 DC. User objects in the undeleted object stores only retain their SID, ObjectGUID, LastKnownParent, and SAMaccountName attributes, so you have to reset passwords, profiles, home directories, and group memberships after reanimating the account. The reanimated user account has the same SID. The SIDHistory attribute is not preserved.

1.
Click Start, Run, and then type ldp.exe. Click OK.
2.
Use the Connection menu to connect and bind ...

Get Windows Server 2003 Security: A Technical Reference now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.