Jump to content

Recommended Posts

Posted

Hi All,

Think i'm in the Crap,

but anyway.

Over the week-end I have been doing some work on our DC Running Server 2012R2 I have been deleting some GPO's that I didn't think where needed.

On a re-boot of the server I can no longer log-in,

I Have deleted the domainadmin user from active directory and that's the only admin on the domain, so I cant now log-in.

 

I'm going in early to morrow to try and sort out! + I also dont know the local admin password so cant access that way.

I am hoping With a windows Server 2012r2 USB to boot up to System Repair run cmd and do a restore of Active directory from backup.

Any one anything that I could try? or should this work, do I still need the local password??

 

Roll on 7am :sick: :(:behindsofa:

Posted

Are you sure there is not another user in the Domain Admins group at all you could use? When the server is made a Domain Controller the local users are not available.

 

Do you have a valid system state backup that you could do an authoritative ad restore from?

Posted

A domain controller doesn't have a local admin account.

 

The only way you are going to sort this out is by restoring from a backup.

Posted
Over the week-end I have been doing some work on our DC Running Server 2012R2 I have been deleting some GPO's that I didn't think where needed.

On a re-boot of the server I can no longer log-in,

 

So did you deffo delete the admin account? As obviously deleting a GPO might affect "your" domain admin account, but it wouldn't make a difference to "The" domain admin account.

 

If all you've done is delete a GPO or two, worst you could do is drop your own permissions lower, and you'd need to login with the real domain admin account

 

Steve

Posted
No there was just domainadmin and me in the OU which we where both administrators which was deleted, I have Full daily Backups so as long as I can boot from my USB/DVD i should be ok to do a authoritative ad restore?
Posted (edited)

Could i not do a Nonauthoritative Restore ?

 

Yes I had a OU Called ICT with Me and domainadmin in I was using GPO and I deleted the OU in there, I closed GPO and Active directory tried to re-open and it said I dont have permissions, could not access Active Directory or GPO logged out and tried to log-back in it now says unsername and password are incorrect.

Edited by robsonma
Posted
In Active Directory there is always a critical system object called Administrator, you can rename it but you won't be able to delete it. For it to be able to be deleted would be counter productive. Someone must have the password to that account.
  • Thanks 1
Posted

Doing a non-authoritative restore will not replicate the restored backup to other DC's you would effectively restore and then it would be over written by another DC, assuming of course you must have more than 1 DC?

 

I was also sure you couldn't delete the Administrator account too!

Posted
Could i not do a Nonauthoritative Restore ?

 

Yes I had a OU Called ICT with Me and domainadmin in I was using GPO and I deleted the OU in there, I closed GPO and Active directory tried to re-open and it said I dont have permissions, could not access Active Directory or GPO logged out and tried to log-back in it now says unsername and password are incorrect.

 

Deleting an OU is quite different from deleting a GPO. It will trash any users or computers which were also resident in that location. Deleting an OU from GPMC is the same as deleting the OU from ADUC. Sounds like you have basically deleted your user - and any others under that OU.

 

You can't do anything really without an admin account. Backup is your only option I would have said, that's if you can log on to the backup server to actually get to any backups that is. Even if you can get to the backups without an account to actually make any changes to the AD you can't do anything with a backup unless you can restore the entire server and basically recreate the last good domain state. - This may require extra work if it is a multi DC setup.

 

I would be surprised if there wasn't another admin account, usually in the Users container (not an OU) and by default called Administrator. - Try that with some known passwords (bearing in mind the normal lockout policy may only let you choose a few before it locks you out for a period of time)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...