Re: Lost Domain Admin Password



Thanks Al,
I agree. It is probably best to wipe and reload.
Mike

"Al Dunbar" wrote:


"Mike M" <MikeM@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:EFD997EA-DDA0-435E-8E62-B24000FC4797@xxxxxxxxxxxxxxxx
Thanks Al,
This server was removed from a defunked company and domain. We are
attempting to create a new domain without reloading the machine.

You cannot have a domain without at least one domain controller. You will
need to either make this one a DC, or create a domain by building another DC
and joining this one to the domain.

The F8 boot menu offers "Directory Services Restore Mode" (a safe mode).

That would suggest to me that it was in a domain previously, and likely a
domain controller, however, that is a bit of a guess on my part...

Booting here allows me to use the new password (Local User on this
machine)but not access to the domain.

If it was previously a DC in a domain, then the local user (local
administrator account?) might have previously been a domain administrator
account. But when you say you have no access "to the domain", what is it you
are trying to do and failing at?

It may be that this server was in a domain but not the DC.

Your guess is likely as good as mine here...

I don't have access to active directory and have no knowledge of the
previous history of this server.

It seems foolhardy to me to try to build a new domain around a computer with
such a questionable heritage as-is. You don't know, for example, whether or
not it has been compromised somehow. You don't even know if it was properly
licensed. I would strongly suggest that you protect your assets
(information) and liabilities (licensing) by wiping the current installation
and doing a completely new install.

/Al

Mike


"Al Dunbar" wrote:


"Mike M" <MikeM@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DEC31720-4F73-4139-BF10-C12E001D3D38@xxxxxxxxxxxxxxxx
Hi,
I have Server 2003 R2 sp2 and lost the domain administrator password.

Is the domain administrator the only member of the domain administrators
group? If not, use one of the other domain admin accounts to set the
password for the administrator account. If it is the only member, think
about that for next time...

I would like to clear the old domain name and start this server fresh
under
a new domain name. I was able to clear the local user admin password
with
a
boot disk,

This local user admin - what was it local to?

then restart to Active Directory Recovery safe mode but unclear as
how to continue.

Can't help you there, as I've never had to do that.

System Properties reports a computer name that I would like to change

What computer - is this your domain controller?

and
Domain as "*Unknown*" and "The Certification Authority Service" is
installed.

I fear you may be pooched if you do not have admin access to your active
directory infrastructure - especially if you have used certificates to
encrypt information with an account whose password has been changed.

Any help is greatly appreciated.

At this point I would tend to suggest starting with a completely new
install, and then taking steps to ensure you don't lock yourself out
again.

/Al






.



Relevant Pages

  • Re: New Hardware, same domain name
    ... So I built a new server and loaded up 2003 sbs using the same domain ... Logged in as the local admin account on the WS and joined the ... While the computer is still in domain A, create a local user account. ... You really need to keep your profiles miniscule, ...
    (microsoft.public.windows.server.sbs)
  • Re: Migration from NT4 to SBS 2003
    ... They purchased a server and SBS 2003. ... While the workstation is still in domain A, create a local user account. ...
    (microsoft.public.windows.server.general)
  • Re: Migration from NT4 to SBS 2003
    ... They purchased a server and SBS 2003. ... Log in as the local user account. ...
    (microsoft.public.windows.server.general)
  • Re: Lost Domain Admin Password
    ... This server was removed from a defunked company and domain. ... If it was previously a DC in a domain, then the local user (local ... administrator account?) ... I have Server 2003 R2 sp2 and lost the domain administrator password. ...
    (microsoft.public.windows.server.security)
  • Re: Cannot connect to Server 2003 Domain
    ... The useraccount that you ar eusing is it domain administrator or normal user account? ... I am trying to connect computers to a windows server 2003 domain. ... The event log appears to say success when I try to connect and then ...
    (microsoft.public.windows.server.active_directory)