How to remove protection on OU in Windows Server 2012 R2 from accidental deletetion

You have created OU in [easyazon_link identifier=”0735626480″ locale=”US” tag=”wn0d5-20″] Active Directory [/easyazon_link] and for some reason such as you make a mistake or you do not need anymore this OU, you would like to delete this OU from your [easyazon_link identifier=”B00X6FS6F2″ locale=”US” tag=”wn0d5-20″] Active Directory [/easyazon_link]. You right-clik on OU and try delete. Instead of deletion you are getting this message:

You do not have sufficient privileges to delete OU, or this object is protected from accidental deletion.

 OU-message

This is default behavior and protection so you do not delete OU by accident when you are working in [easyazon_link identifier=”1782175997″ locale=”US” tag=”wn0d5-20″] Active Directory [/easyazon_link] console. If you would like to delete this OU from [easyazon_link identifier=”1449320023″ locale=”US” tag=”wn0d5-20″] Active Directory [/easyazon_link] you have to follow few steps bellow and remove the protection. Once done, you will be able to delete the OU from AD.

 Protect-ou

To remove protection that prevents an OU from accidental deletion [KB – cc736842]

  1. Log on to the computer as a member of the Domain Admins group.
  2. Open Active Directory Users and Computers.
  3. Click View, and then click Advanced Features.
  4. First, clear permissions on the OU for which you want to remove protection. To do this, right-click the OU, and then click Properties.
  5. In OU Properties, click the Security tab, and then click Advanced.
  6. In Permission Entries, select the Deny entry for the Everyone group, and then click Remove.
  7. Click OK to close the Advanced Security Settings, and then click OK to close OU Properties.
  8. Second, clear permissions on the parent container of the OU for which you want to remove protection. To do this, right-click the parent container, and then click Properties.
  9. In ContainerProperties, click the Security tab.
  10. In Group or user names, select the Everyone group, and then clear the Deny check box for Delete All Child Objects, and then click OK to close Container Properties.

Membership in the Domain Admins group, or equivalent, is required to complete this procedure.

[easyazon_image align=”none” height=”160″ identifier=”0735682674″ locale=”US” src=”http://blog.technotesdesk.com/wp-content/uploads/2015/07/51PTov2ZEPL._SL160_.jpg” tag=”wn0d5-20″ width=”131″]

2 Replies to “How to remove protection on OU in Windows Server 2012 R2 from accidental deletetion”

  1. Thanks a million. I’m new at a company and was making an ou but forgot to click inside the window and the ou ended up in the wrong place. Didn’t want to ask for help so this was great.

Leave a Reply