How to let non-administrators view the Active Directory deleted objects container in Windows Server 2003 and in Windows 2000 Server (892806)
The information in this article applies to:
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Server 2003, Enterprise Edition
- Microsoft Windows Server 2003, Datacenter Edition
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server
SUMMARYWhen an Active Directory object is deleted, a small part
of the object stays in the deleted objects container for a specified time. It stays there so that other domain
controllers that are replicating changes will become aware of the deletion. By
default, only the System account and members of the Administrators group can view the contents of this container. This article describes how to modify the
permissions on the deleted objects container. You may have to modify the permissions on the deleted objects container if the following conditions are true: - You have
enterprise applications or services that bind to Active Directory with a
non-System account or a non-Administrator account.
- These enterprise applications or services poll for directory changes.
Modification Type: | Major | Last Reviewed: | 4/19/2005 |
---|
Keywords: | kbhowto KB892806 kbAudEndUser |
---|
|