Solved

How do I recreate a lost computer account in a domain controller?

Posted on 1997-11-07
2
763 Views
Last Modified: 2013-12-14
We lost a hard drive on one of our NT boxes in our domain.  We were able to restore it from a backup to a new drive, but I think we screwed up the computer account on the Primary Domain Controller (PDC).

The problem I think is that in order to restore the backup, we had to reinstall NT first.  During setup,  we added the computer to the PDC and checked the "create computer account" option.  

This worked fine, but after we restored the backup no domain users could logon to the machine and if we tried to get to the machine from the PDC, we got a "trust" error message.

I think where we screwed up was that when we installed NT we overwrote the original security identifier for the failed machine that was stored on the PDC so that when we restored the backup, the oriiginal security info was restored but it no longer matches what is on the PDC.

Does anyone know how to fix this?  If I go into Server Manager and then select the computer that failed and "remove" it from the domain and then "add" it to the domain, I always get the error "The trust relationship between this workstation and the primary domain failed."

Any ideas?
0
Comment
Question by:magenta
2 Comments
 
LVL 4

Accepted Solution

by:
arminl earned 200 total points
ID: 1768493
Delete the faulty account using Server Manager, change the Domain Name in the WS control-panel, network applet to a workgroup name that does not exist and reboot. Log on locally, change the domain name back to the name of your domain, check the "create computer account" checkbox and enter a domain administrator's name and password.

You'll receive a "Welcome to domain xxxxx" message, reboot and everything should be allright.

Armin Linder
arminl@adlon.de
0
 

Expert Comment

by:touse
ID: 4398717

Since you say you have tried adding and removing it from the domain (multiple times, I hope), go the the website www.sysinternals.com and D/L newsid.exe and run it.

This replaces the sid on a nt/2k machine.

--touse
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cookie issue 7 44
Permanently disable Server 2012 hiberfil.sys file 3 58
FlexNet and ususweb.dll 3 15
Connecting two servers 30 49
The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now