Hi,
I updated from 8.2.1 to 8.5 a couple of days ago and the update went fine but since then no one, not even the AR admins, can delete computer objects. I thought it was the msFVE-RecoveryInformation objects they couldn't delete, but it worked before the update. I' followed the instructions in this link but it didn't help. Unable to delete computer objects with BitLocker subtree/leaf object (4226632)
Delegates have full control of computer objects and delete child objects access to the OUs they're in, but even the AR admins like me can't delete computers. The initial message that comes up when we try to delete one is for the recovery info and that comes up with an error Administrative Policy returned an error, object reference not set to an instance of an object. If I say no to deleting the recovery info I then get to the message about deleting the computer itself, but trying to delete that comes up with a message saying You do not have sufficient privileges to delete......this object is protected from accidental deletion. The directory service can perform the requested operation only on a leaf object. I've checked the the computers are NOT protected from deletion (we can delete the same object directly in AD) and enabling the protection then removing it didn't make any difference. I even ran native AD as the service account and could delete a computer with that, so it['s only via Active Roles itself it doesn't work. Very confusing!
Any ideas? Has anyone else come across this?
Thanks