Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Regaining Control of Member Server in Domain

Reply
Thread Tools Display Modes

Re: Regaining Control of Member Server in Domain

 
 
Pegasus [MVP]
Guest
Posts: n/a

 
      01-02-2010


"W" <> said this in news item
news:O6OdnX-...
> I have a Windows 2003 member server in a domain that for whatever reason
> is
> no longer being recognized by the domain. Normally this is not a big
> deal. I login as administrator on the member server and drop the
> computer
> from the domain, then reboot and rejoin the domain and everything is
> patched. Unfortunately, this computer was configured through group
> policy
> to disable the local administrator account. I need help getting into any
> valid administrator account to regain control of the computer so I can
> drop
> from the domain and then rejoin.
>
> Here is what I have tried so far without any luck:
>
> 1) I booted with Wininternals and reset the local Administrator account
> password. This changed nothing as I get a message that the group policy
> of
> the computer prevents login with that account when I reboot and attempt a
> login.
>
> 2) I tried to boot in safe mode. Normally this always allows the local
> Administrator account to work again? Did this behavior change in
> Windows?
> Because it no longer works. I get the same error that the group policy
> forbids login.
>
> 3) I modified group policy to force that computer to allow local
> Administrator access. This does no good either: the computer itself is
> not authenticating properly to the domain, so no group policy exchange can
> ever take place.
>
> 4) I tried to boot from Wininternals and create a local administrator
> account with:
>
> net users newuser newpassword /add
> net localgroup administrators newuser /add
>
> These commands give no errors but also do nothing.
>
> 5) I tried to boot from the Windows setup disk, but unfortunately it
> appears
> that the disk controller of the computer requires me to prepare a special
> floppy and hit F6 during the bootup process.
>
> Like so many problems in Windows, solving one simple problem requires you
> into a descending chain of events that leave you in absolute hell.
>
> I am hoping that someone older, wiser, and more patient sees a way for me
> to
> regain control of this computer without spending the next six hours doing
> it.
>
> --
> W


The Group Policy Editor tells me that the Administrator account *must* be
granted a local logon right. It appears that Microsoft anticipated your
attempt at painting yourself into a corner and added a block to prevent it.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Unable to add computer to domain Nik Active Directory 5 12-18-2009 08:29 PM
Do I need to open port 137 and 138 from members server to the trusted PDC emulator ? Eric Active Directory 11 12-07-2009 03:42 PM
The local domain controller could not connect with - 2008 boe Active Directory 9 11-22-2009 01:05 AM
Re: Incorrect server name Ace Fekay [MCT] Windows Server 4 10-28-2009 02:17 PM
Slow Vista startup Jedi940 Windows Vista Performance 1 01-13-2008 08:50 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59