Allowing a specific group to restore deleted AD objects RRS feed

Syed Hussain 1 Reputation point
2021-07-19T17:16:06.09+00:00

Repeating the same question that has not been answered: https://social.technet.microsoft.com/Forums/en-US/378572b6-5b4d-4d21-aeb4-1ea22c8f2f2e/allowing-a-specific-group-to-restore-deleted-ad-objects?forum=winserverDS

Hi

I checked this doc : https://support.microsoft.com/en-us/help/892806/how-to-let-non-administrators-view-the-active-directory-deleted-object and it did allow the group I want to view Deleted Objects. However when they try to actually restore a user/computer account they get an error reading "Insufficient access rights to perform the operation.

When I checked the output from : dsacls "CN=Deleted Objects,DC=,DC=,DC=" /g Domain\Group:LCRP I can see that the group I selected has the same rights as the default Domain\Administrators group has so I don't think the issue is here, I even went one step further and tried running the command : dsacls "CN=Deleted Objects,DC=,DC=,DC=" /g Domain\Group:GA which grants full control of the Deleted Objects container and still they receive the same error.

So I'm thinking it's a different permission they are missing. I tried restoring to several different locations in AD including some OUs where this group has full control and that didn't help either. I should add that me as a domain admin can do this with no issues.
Anyone have an idea what is missing?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2021-07-20T03:17:38.27+00:00

    Hello @Syed Hussain ,

    Thank you so much for posting here.

    Have we checked this doc: https://social.technet.microsoft.com/wiki/contents/articles/20592.how-to-delegate-the-restoration-of-objects-from-active-directory-recycle-bin.aspx

    If not, we could kindly have a check and see whether it helps.

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.