|
|
|
date: Mon, 2 Jun 2008 17:42:28 -0400,
group: microsoft.public.platformsdk.active.directory
back
Re: DS Restore mode password - is it perhaps replicated?
In news:uIhZD2RxIHA.5520@TK2MSFTNGP06.phx.gbl,
Herb Martin typed:
> <-> wrote in message news:%235diPmPxIHA.2384@TK2MSFTNGP02.phx.gbl...
> The Local Administrator or more formally the "Directory Restore Mode
> Administrative Password" is not replicated but it totally local that
> single DC.
>
> There is essentially a local SAM database, a la NT4 server's accounts
> database (outside of a domain.)
>
> It is specific to that one DC.
And more specifically for the original poster, it's the password that was
set by the administrator while running DCPROMO on that machine to make it a
DC.
--
Regards,
Ace
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
MVP Microsoft MVP - Directory Services
Microsoft Certified Trainer
For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.
Infinite Diversities in Infinite Combinations
date: Mon, 2 Jun 2008 22:47:09 -0400
author: Ace Fekay [MVP]
Re: DS Restore mode password - is it perhaps replicated?
And it can be reset using a number of tools.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
* http://sl.mvps.org * http://msmvps.com/blogs/sp *
"Ace Fekay [MVP]" wrote in message
news:uUg02QSxIHA.4376@TK2MSFTNGP06.phx.gbl...
> In news:uIhZD2RxIHA.5520@TK2MSFTNGP06.phx.gbl,
> Herb Martin typed:
>> <-> wrote in message news:%235diPmPxIHA.2384@TK2MSFTNGP02.phx.gbl...
>
>> The Local Administrator or more formally the "Directory Restore Mode
>> Administrative Password" is not replicated but it totally local that
>> single DC.
>>
>> There is essentially a local SAM database, a la NT4 server's accounts
>> database (outside of a domain.)
>>
>> It is specific to that one DC.
>
> And more specifically for the original poster, it's the password that was
> set by the administrator while running DCPROMO on that machine to make it
> a DC.
>
> --
> Regards,
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
> MVP Microsoft MVP - Directory Services
> Microsoft Certified Trainer
>
> For urgent issues, you may want to contact Microsoft PSS directly. Please
> check http://support.microsoft.com for regional support phone numbers.
>
> Infinite Diversities in Infinite Combinations
>
>
date: Tue, 10 Jun 2008 18:08:39 +1000
author: S. Pidgorny MVP
Re: DS Restore mode password - is it perhaps replicated?
Dean Wells (An AD MVP) has a tool to change the dsrm password on all dc's.
Script is based on SETPWD available from here that will reset all DSRM
passwords within a supplied forest.
ftp://falcon.msetechnology.com/scripts/dsrmreset.cmd.txt
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
"S. Pidgorny <MVP>" wrote in message
news:eBX%230EtyIHA.4168@TK2MSFTNGP06.phx.gbl...
> And it can be reset using a number of tools.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
> "Ace Fekay [MVP]" wrote in message
> news:uUg02QSxIHA.4376@TK2MSFTNGP06.phx.gbl...
>> In news:uIhZD2RxIHA.5520@TK2MSFTNGP06.phx.gbl,
>> Herb Martin typed:
>>> <-> wrote in message news:%235diPmPxIHA.2384@TK2MSFTNGP02.phx.gbl...
>>
>>> The Local Administrator or more formally the "Directory Restore Mode
>>> Administrative Password" is not replicated but it totally local that
>>> single DC.
>>>
>>> There is essentially a local SAM database, a la NT4 server's accounts
>>> database (outside of a domain.)
>>>
>>> It is specific to that one DC.
>>
>> And more specifically for the original poster, it's the password that was
>> set by the administrator while running DCPROMO on that machine to make it
>> a DC.
>>
>> --
>> Regards,
>> Ace
>>
>> This posting is provided "AS-IS" with no warranties or guarantees and
>> confers no rights.
>>
>> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
>> MVP Microsoft MVP - Directory Services
>> Microsoft Certified Trainer
>>
>> For urgent issues, you may want to contact Microsoft PSS directly. Please
>> check http://support.microsoft.com for regional support phone numbers.
>>
>> Infinite Diversities in Infinite Combinations
>>
>>
>
>
date: Tue, 10 Jun 2008 08:12:42 -0500
author: Paul Bergson [MVP-DS]
Re: DS Restore mode password - is it perhaps replicated?
Sure, plus you can already set the DSRM password by running setpwd from a
command prompt.
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
"Herb Martin" wrote in message
news:eWNhd0wyIHA.3680@TK2MSFTNGP05.phx.gbl...
>
> "Paul Bergson [MVP-DS]" wrote in message
> news:eaC5ruvyIHA.4492@TK2MSFTNGP02.phx.gbl...
>> Dean Wells (An AD MVP) has a tool to change the dsrm password on all
>> dc's.
>>
>> Script is based on SETPWD available from here that will reset all DSRM
>> passwords within a supplied forest.
>>
>>
>>
>> ftp://falcon.msetechnology.com/scripts/dsrmreset.cmd.txt
>
> So I am guessing you mean this work even when booted as a DC,
> i.e., without being in DSRMode?
>
> Cool.
>
date: Tue, 10 Jun 2008 15:37:12 -0500
author: Paul Bergson [MVP-DS]
Re: DS Restore mode password - is it perhaps replicated?
"Paul Bergson [MVP-DS]" wrote in message
news:%23l6zEnzyIHA.4848@TK2MSFTNGP05.phx.gbl...
> Sure, plus you can already set the DSRM password by running setpwd from a
> command prompt.
Sorry -- should have put this in the previous: And it works on Win2000 DCs?
> --
> Paul Bergson
> MVP - Directory Services
> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
> 2008, 2003, 2000 (Early Achiever), NT4
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> "Herb Martin" wrote in message
> news:eWNhd0wyIHA.3680@TK2MSFTNGP05.phx.gbl...
>>
>> "Paul Bergson [MVP-DS]" wrote in message
>> news:eaC5ruvyIHA.4492@TK2MSFTNGP02.phx.gbl...
>>> Dean Wells (An AD MVP) has a tool to change the dsrm password on all
>>> dc's.
>>>
>>> Script is based on SETPWD available from here that will reset all DSRM
>>> passwords within a supplied forest.
>>>
>>>
>>>
>>> ftp://falcon.msetechnology.com/scripts/dsrmreset.cmd.txt
>>
>> So I am guessing you mean this work even when booted as a DC,
>> i.e., without being in DSRMode?
>>
>> Cool.
>>
>
>
date: Tue, 10 Jun 2008 20:47:07 -0500
author: Herb Martin
Re: DS Restore mode password - is it perhaps replicated?
Yes
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
"Herb Martin" wrote in message
news:u5TiPU2yIHA.3384@TK2MSFTNGP03.phx.gbl...
>
> "Paul Bergson [MVP-DS]" wrote in message
> news:%23l6zEnzyIHA.4848@TK2MSFTNGP05.phx.gbl...
>> Sure, plus you can already set the DSRM password by running setpwd from a
>> command prompt.
>
> Sorry -- should have put this in the previous: And it works on Win2000
> DCs?
>
>
>> --
>> Paul Bergson
>> MVP - Directory Services
>> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
>> 2008, 2003, 2000 (Early Achiever), NT4
>>
>> http://www.pbbergs.com
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>>
>> "Herb Martin" wrote in message
>> news:eWNhd0wyIHA.3680@TK2MSFTNGP05.phx.gbl...
>>>
>>> "Paul Bergson [MVP-DS]" wrote in message
>>> news:eaC5ruvyIHA.4492@TK2MSFTNGP02.phx.gbl...
>>>> Dean Wells (An AD MVP) has a tool to change the dsrm password on all
>>>> dc's.
>>>>
>>>> Script is based on SETPWD available from here that will reset all DSRM
>>>> passwords within a supplied forest.
>>>>
>>>>
>>>>
>>>> ftp://falcon.msetechnology.com/scripts/dsrmreset.cmd.txt
>>>
>>> So I am guessing you mean this work even when booted as a DC,
>>> i.e., without being in DSRMode?
>>>
>>> Cool.
>>>
>>
>>
>
>
date: Wed, 11 Jun 2008 07:44:11 -0500
author: Paul Bergson [MVP-DS]
|
|