Solved

Windows 2000/2003 domain

Posted on 2011-03-07
5
377 Views
Last Modified: 2013-12-05
Hi all,

I have a windows 2000 DC and a windows 2003 dc and a 2003 exchange server. The windows 2000 dc was installed first then the 2003 a fair few years later. This morning my 2000 dc failed to start with the error LSASS.EXE - system error, security accounts manager initialization failed because the following error: Directory services cannot start.

I have got the microsoft solution to the issue but it requires me to have the Directory services restore mode password, which i dont have as i didnt set the server up and i failed to change when server was working.

So as i understand my only option is to, demote the 2000 dc using dcpromo, will this then allow the 2000 to boot up and not require active directory to function? I have files on the 2000 that i need to get but obviously i cant get in to the server because of the issue and the forgotten password.

If someone could advise i would be grateful. Worried that if i run the dcpromo i will mess it up as not sure if the 2003 has all the required info.

cheers
0
Comment
Question by:adam2311
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 3

Expert Comment

by:dtrance
ID: 35058430
The 2003 DC will contain all the directory information.  You have to demote the 2000 DC however to get it cleanly out of AD.

See the utility here to reset the password.
http://www.petri.co.il/change_recovery_console_password.htm

0
 

Author Comment

by:adam2311
ID: 35059305
If i cant log on the server how would i do this? when i normally try and start up the server i get the error screen with the above message. The only way to clear this is to restart.

With the dcpromo, can i run this on my other DC to demote the win 2000 DC? cause at the moment i can't access the failed 2000 DC.
0
 

Author Comment

by:adam2311
ID: 35067258
Where i am, still need help urgently.

I have tried to change the password using dtrance methods posted however as i can not access the 2000 dc (safemode or any mode) i can not change the restore password. I can only think i need to demote the 2000 dc but how can this be done safetly without actually getting on the 2000 dc?

Is there away to disable the active directory on the 2000 dc so it will start up as the error is the 'Directory service cannot start'

cheers
0
 

Accepted Solution

by:
adam2311 earned 0 total points
ID: 35068600
I have fixed the issue.

Basically if you do not have the restore password you are screwed. There is no way to solve this issue cleanly.

So what i did was a force remove of the DC. I firstly seized the roles and transfered them to the exisiting dc. I then followed the metadate cleanup.

First Microsoft site was to seize fsmo roles : support.microsoft.com/kb/255504

then Microsoft site support.microsoft.com/kb/216498 this cleans up the dc demotion.
0
 

Author Closing Comment

by:adam2311
ID: 35120570
I managed to read through alot of microsoft support docs and old expert articles to gather all options available to me.
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

After having deployed hundreds of thousands of Terminal Services seats worldwide, I still see all the time people asking me that same old question: "If TS/RDS is that reliable why are you telling me I should reboot it that often? My DC/SQL/Exchange/…
Welcome to my series of short tips on migrations. Whilst based on Microsoft migrations the same principles can be applied to any type of migration. My first tip Migration Tip #1 – Source Server Health can be found here: http://www.experts-exchang…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question