Link to home
Start Free TrialLog in
Avatar of BFanguy
BFanguyFlag for United States of America

asked on

change permission on Org Unit in Active Directory

I was trying to deny a group policy for domain admins and I accidently denied all access to the organization unit to domain admins.   If I remember correctly System and Enterprise admins had inherited security.    Is is possible to "Un-Deny" the Org Unit?  what should i log on as?
Avatar of Randy Downs
Randy Downs
Flag of United States of America image

Try administrator

http://technet.microsoft.com/en-us/library/cc700835.aspx

Protecting the Administrator Account
Every installation of Active Directory has an account named Administrator in each domain. This account cannot be deleted or locked out. In Windows Server 2003, the Administrator account can be disabled, but it is automatically re-enabled when you start the computer in Safe Mode
.

Avatar of BFanguy

ASKER

Safe mode or directory services restore mode?  Tried safe mode and could not sign on as administrator.
the Administrator is not supposed to be locked out in Safe mode. Note don't just rely on being an administrator.
Avatar of BFanguy

ASKER

Either I don't remember the password or it's locked.  I guess I will try one of the other domain controllers in safe mode, will post progress as i go, thanks.
ASKER CERTIFIED SOLUTION
Avatar of BFanguy
BFanguy
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of BFanguy

ASKER

found an easy answer