Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

February 28, 2006 12:00 AM

A Free and Easy Way to Reset Directory Service Restore Mode Passwords

Windows IT Pro
InstantDoc ID #49162
Rating: (6)

When a Windows Server 2003 or Windows 2000 machine is promoted to a domain controller (DC), its local user database (i.e., its SAM) is reset and a new local Administrator account is created. During the promotion process, you're required to set the password for this new account. This password will be used in two rare, but extremely useful cases: when Active Directory (AD) isn't working and you must use the local Administrator account in the recovery console or in Directory Services Restore Mode. If you forget the local Administrator password, you can't use the recovery console nor restore the AD database. (The AD database is a part of the system state, and the system state in DCs can only be restored in Directory Services Restore Mode.)

In Windows 2003, the Ntdsutil utility has a nice solution to a forgotten local Administrator password: the Set DSRM Password command. However, the Ntdsutil utility in Windows 2000 doesn't offer this command. As a result, the system state backup in Windows 2000 might be rendered useless if you forget the local Administrator password.

One solution to this problem in Windows 2000 is to use a third-party utility, such as the Locksmith utility in Winternals Software's ERD Commander 2005. However, although this utility is good, it isn't free.

A free and simple solution is to verify that you've backed up the system state, then demote the DC. In the demotion process, the local user database is reset once again and you're asked to set the password of the new local Administrator account. After the demotion, you can log on to the machine using this password. Then, without going to Directory Service Restore Mode, you can restore the system state backup. (For standalone servers and member servers, you don't need to switch to the Directory Service Restore Mode when the system state backup will be restored.) That's all you need to do.

Related Content:

ARTICLE TOOLS

Comments
  • Murat
    6 years ago
    Mar 26, 2006

    jsean, you are right, I missed setpwd command because I wasn't aware of this command. The article you mentioned says that this command comes with SP2. Our method can still be used with Windows 2000 DCs without SP2 (tough I cannot imagine such an installation).
    Second thing: Microsoft in general, and the article in particular fail to explain the dsrm password. And they fail also what is happening during the DC promotion process; that is the SAM database and Active Directory database relation which we thought we explained clearly in our article.

    Murat Yildirimoglu

  • james
    6 years ago
    Mar 15, 2006

    Demoting a DC to change the DSRM password is not the "easy" way - far from it. The real easy way is to run setpwd from a command prompt.

    http://support.microsoft.com/kb/239803/en-us

    This article missed by a lot. Wow.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.