robsonma Posted December 13, 2015 Posted December 13, 2015 Hi All, Think i'm in the Crap, but anyway. Over the week-end I have been doing some work on our DC Running Server 2012R2 I have been deleting some GPO's that I didn't think where needed. On a re-boot of the server I can no longer log-in, I Have deleted the domainadmin user from active directory and that's the only admin on the domain, so I cant now log-in. I'm going in early to morrow to try and sort out! + I also dont know the local admin password so cant access that way. I am hoping With a windows Server 2012r2 USB to boot up to System Repair run cmd and do a restore of Active directory from backup. Any one anything that I could try? or should this work, do I still need the local password?? Roll on 7am
dblight Posted December 13, 2015 Posted December 13, 2015 Are you sure there is not another user in the Domain Admins group at all you could use? When the server is made a Domain Controller the local users are not available. Do you have a valid system state backup that you could do an authoritative ad restore from?
FN-GM Posted December 13, 2015 Posted December 13, 2015 A domain controller doesn't have a local admin account. The only way you are going to sort this out is by restoring from a backup.
Steve21 Posted December 13, 2015 Posted December 13, 2015 Over the week-end I have been doing some work on our DC Running Server 2012R2 I have been deleting some GPO's that I didn't think where needed. On a re-boot of the server I can no longer log-in, So did you deffo delete the admin account? As obviously deleting a GPO might affect "your" domain admin account, but it wouldn't make a difference to "The" domain admin account. If all you've done is delete a GPO or two, worst you could do is drop your own permissions lower, and you'd need to login with the real domain admin account Steve
robsonma Posted December 13, 2015 Author Posted December 13, 2015 No there was just domainadmin and me in the OU which we where both administrators which was deleted, I have Full daily Backups so as long as I can boot from my USB/DVD i should be ok to do a authoritative ad restore?
robsonma Posted December 13, 2015 Author Posted December 13, 2015 (edited) Could i not do a Nonauthoritative Restore ? Yes I had a OU Called ICT with Me and domainadmin in I was using GPO and I deleted the OU in there, I closed GPO and Active directory tried to re-open and it said I dont have permissions, could not access Active Directory or GPO logged out and tried to log-back in it now says unsername and password are incorrect. Edited December 13, 2015 by robsonma
DJ-1701 Posted December 13, 2015 Posted December 13, 2015 In Active Directory there is always a critical system object called Administrator, you can rename it but you won't be able to delete it. For it to be able to be deleted would be counter productive. Someone must have the password to that account. 1
dblight Posted December 13, 2015 Posted December 13, 2015 Doing a non-authoritative restore will not replicate the restored backup to other DC's you would effectively restore and then it would be over written by another DC, assuming of course you must have more than 1 DC? I was also sure you couldn't delete the Administrator account too!
Jamo Posted December 13, 2015 Posted December 13, 2015 Could i not do a Nonauthoritative Restore ? Yes I had a OU Called ICT with Me and domainadmin in I was using GPO and I deleted the OU in there, I closed GPO and Active directory tried to re-open and it said I dont have permissions, could not access Active Directory or GPO logged out and tried to log-back in it now says unsername and password are incorrect. Deleting an OU is quite different from deleting a GPO. It will trash any users or computers which were also resident in that location. Deleting an OU from GPMC is the same as deleting the OU from ADUC. Sounds like you have basically deleted your user - and any others under that OU. You can't do anything really without an admin account. Backup is your only option I would have said, that's if you can log on to the backup server to actually get to any backups that is. Even if you can get to the backups without an account to actually make any changes to the AD you can't do anything with a backup unless you can restore the entire server and basically recreate the last good domain state. - This may require extra work if it is a multi DC setup. I would be surprised if there wasn't another admin account, usually in the Users container (not an OU) and by default called Administrator. - Try that with some known passwords (bearing in mind the normal lockout policy may only let you choose a few before it locks you out for a period of time)
robsonma Posted December 13, 2015 Author Posted December 13, 2015 Thanks all, No its the Only DC on that domain, Its a Primary School, Ill keep trying with Administrator.
Jamo Posted December 13, 2015 Posted December 13, 2015 If its the only DC it may make restore a viable option - is it a VM and when was the last good backup?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now