Domain Admin Accoutn locke dout with group Policy

Discussion in 'Active Directory' started by BJ, Feb 6, 2008.

  1. BJ

    BJ Guest

    Our domain admin account got locked. out (AD server 2003, 3 DCs). We forgot
    to deny the domain and enterprise administrators n the GPO from locking it
    out. Now, we have 3 doman controllers and no one can login as the
    administrator accont. What can we do? Is there a way to reboot the servers
    and get the account unlocked? We set it against the default domain policy
    and put a maximum of 4 tries. Apparently something is causing it to lockout
    that we cant see. So...how do we:

    1. Get logged back in as administrator to the domain?
    2. DO we just reboot all domain controllers?

    BJ
     
    BJ, Feb 6, 2008
    #1
    1. Advertisements

  2. it is not possible to lock the administrator account permanently like other
    accounts. It will get locked, but as soon as the correct password had been
    entered it is unlocked right away

    see:
    http://blogs.dirteam.com/blogs/jorg...dministrator-account-is-locked_21003F00_.aspx

    --

    Cheers,
    (HOPEFULLY THIS INFORMATION HELPS YOU!)

    # Jorge de Almeida Pinto # MVP Windows Server - Directory Services

    BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
    BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
     
    Jorge de Almeida Pinto [MVP - DS], Feb 7, 2008
    #2
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.