In this guide, I’ll show two options on how to check the Tombstone Lifetime in Active Directory.
Option 1. Check Tombstone Lifetime using PowerShell
Use the below PowerShell command to check the Tombstone lifetime in Active Directory. You will need to update the distinguishedName to match your domain.
(get-adobject “cn=Directory Service,cn=Windows NT,cn=Services,cn=Configuration,DC=ad,DC=activedirectorypro,DC=com” -properties “tombstonelifetime”).tombstonelifetime
data:image/s3,"s3://crabby-images/20c09/20c090cc0088db5d6db57d3cbae19f15800f67af" alt="powershell check active directory tombstone lifetime"
You can see in the screenshot above my Tomestone lifetime is 180 days.
You can find your distinguishedName with this command.
Get-ADRootDSE | select defaultNamingContext
data:image/s3,"s3://crabby-images/c5772/c57727c41bdbba18d57ca794029b9fc1d86034f5" alt="powershell get root of the domain"
Update the section in red with your domains distinguishedName.
data:image/s3,"s3://crabby-images/800f7/800f73d7b8987532e5ac02e7f81bf4a2195a3d82" alt="update root domain"
Option 2. Check Tombstone Lifetime using ADSI Edit
Step 1. Open ADSI Edit
Step 2. Right on ADSEI Edit and select “Connect to”
data:image/s3,"s3://crabby-images/6be7b/6be7bdc7393cdc4eae1bfeb10216be8b32a98628" alt="adsi edit connect to"
Step 3. Select “Configuration” from the drop down and then click “OK”.
data:image/s3,"s3://crabby-images/6250e/6250e56eb33cd7a31d9b5f2613b6beaaffc37208" alt="adsi edit select configuration"
Step 4. Expand the following:
- CN=Configuration,(your domain)
- CN=Services
- CN=Windows NT
- CN=Directory Service
Then right click on CN=Directory Service and select “Properties”
data:image/s3,"s3://crabby-images/dcbce/dcbce0b400f2e59ad927f94d7b32b3ecc4698db8" alt="adsi expand containers"
Scroll down and check the value of “tombstoneLifetime”.
data:image/s3,"s3://crabby-images/2a628/2a62860b3e071e91283c7b12f15cfaa6d87236f4" alt="adsi tomestonelifetime"