Active Directory preserved attributes in TombStone


When an Active Directory object is deleted, by default, the object goes in “TombStone” for 180 days. It looses a lot of its data, only a subset of attributes are preserved, you can find them with that PowerShell example :

#Preserved Attributes in TombStone
$dse = [adsi]“LDAP://RootDSE”
$TombStoneAttSearcher.FindAll() | Select-Object -ExpandProperty Path | % {($_ -split ",")[0]} | % {($_ -split "=")[1]} | Sort-Object



Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.