"W" <> said this in news item
news:O6OdnX-...
> I have a Windows 2003 member server in a domain that for whatever reason
> is
> no longer being recognized by the domain. Normally this is not a big
> deal. I login as administrator on the member server and drop the
> computer
> from the domain, then reboot and rejoin the domain and everything is
> patched. Unfortunately, this computer was configured through group
> policy
> to disable the local administrator account. I need help getting into any
> valid administrator account to regain control of the computer so I can
> drop
> from the domain and then rejoin.
>
> Here is what I have tried so far without any luck:
>
> 1) I booted with Wininternals and reset the local Administrator account
> password. This changed nothing as I get a message that the group policy
> of
> the computer prevents login with that account when I reboot and attempt a
> login.
>
> 2) I tried to boot in safe mode. Normally this always allows the local
> Administrator account to work again? Did this behavior change in
> Windows?
> Because it no longer works. I get the same error that the group policy
> forbids login.
>
> 3) I modified group policy to force that computer to allow local
> Administrator access. This does no good either: the computer itself is
> not authenticating properly to the domain, so no group policy exchange can
> ever take place.
>
> 4) I tried to boot from Wininternals and create a local administrator
> account with:
>
> net users newuser newpassword /add
> net localgroup administrators newuser /add
>
> These commands give no errors but also do nothing.
>
> 5) I tried to boot from the Windows setup disk, but unfortunately it
> appears
> that the disk controller of the computer requires me to prepare a special
> floppy and hit F6 during the bootup process.
>
> Like so many problems in Windows, solving one simple problem requires you
> into a descending chain of events that leave you in absolute hell.
>
> I am hoping that someone older, wiser, and more patient sees a way for me
> to
> regain control of this computer without spending the next six hours doing
> it.
>
> --
> W
The Group Policy Editor tells me that the Administrator account *must* be
granted a local logon right. It appears that Microsoft anticipated your
attempt at painting yourself into a corner and added a block to prevent it.
|