Users Recreate ThemSelves

Jenn

Distinguished
Jul 26, 2004
254
0
18,780
Archived from groups: microsoft.public.win2000.active_directory (More info?)

We have a Windows 2000 Active Directory structure that sits under
E-Directory. We are also running Exchange 2003. We have some users that
have been verified that they were deleted, that seem to be recreated. About
1/2 of these 15+ users have Exchange mailboxes and they all must remain in
E-Directory. To maintain in E-Directory (needed due to a certain app that
does not function if they are completely removed), users are left there, but
stripped of group memberships and removed from AD.

Any ideas of what kind of replication could cause this? Is there anyway to
force a forever slumber? Another thing these accounts have in common is
again, about 1/2 have an Account Expiration date in Active Directory as
2/1/05 and if you look at the exchange mailboxes, the last time they were
modified was December 23, 24, or 26, 2004.

Any suggestions, thoughts, anything, would be greatly appreciated!
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Hello,

How many DCs you have ? are they in the same site or different sites? Also r
u using hub and spoke topology to replicate between sites, if u have multiple
sites, that is. If u have multiple sites and use hub and spoke topology, then
I suspect that when u delete a user account in a spoke site, and that info is
not replicated to a DC in the hub site, the hub site DCs have those users
still in AD and in next replication cycle, this user which u deleted from
spoke site DC, will come back to all DCs in spoke site and thus AD would be
repopulated with the deleted user account.

I would suggest you run replmon on your PDC emulator and delete a user from
AD users and computers. Then try to push replication from this PDC
cross-sites. If this info is replicated to all DCs, then we will know that AD
replication is fine. But if this fails, then there is replication problem and
we need to run MPS reports for Directory services on where u r getting back
the deleted user accounts. U can download that in www.microsoft.com and
search for MPSRPT_DIRSVC. This will generate a .cab file. Please forward me
this cab file to v_2shaib@hotmail.com. I will give u an answer as to why this
is happening...though I suspect this to be replication issue.

"Jenn" wrote:

> We have a Windows 2000 Active Directory structure that sits under
> E-Directory. We are also running Exchange 2003. We have some users that
> have been verified that they were deleted, that seem to be recreated. About
> 1/2 of these 15+ users have Exchange mailboxes and they all must remain in
> E-Directory. To maintain in E-Directory (needed due to a certain app that
> does not function if they are completely removed), users are left there, but
> stripped of group memberships and removed from AD.
>
> Any ideas of what kind of replication could cause this? Is there anyway to
> force a forever slumber? Another thing these accounts have in common is
> again, about 1/2 have an Account Expiration date in Active Directory as
> 2/1/05 and if you look at the exchange mailboxes, the last time they were
> modified was December 23, 24, or 26, 2004.
>
> Any suggestions, thoughts, anything, would be greatly appreciated!