Solved

Problem logging into to Windows Server 2003 using domain admin account

Posted on 2015-01-20
11
65 Views
Last Modified: 2015-01-26
When I tried logging into my server using the domain\administrator account I got a message about a temporary user profile. So I followed this procedure

http://www.sysads.co.uk/2012/11/you-are-logged-into-a-temporary-profile-in-windows-server-2008-r2/

I inadvertently deleted the wrong key so now I get a new error message when I try to login, "The User Profile Service service failed the logon.  User profile cannot be loaded" and i can not login using my domain\administrator account.  I can login using another account which is in the domain admins group but for some reason I don;t get access to some of the folders.

How can I fix my server to login using the domain\administrator account?
0
Comment
Question by:GreyHippo
  • 6
  • 4
11 Comments
 
LVL 33

Expert Comment

by:paulmacd
Comment Utility
If it's just a member server, you can remove/rejoin it to the domain.  

Then promise on a stack of MCP manuals you'll stop hacking the registry without making a backup.
0
 

Author Comment

by:GreyHippo
Comment Utility
Its a domain controller.
0
 
LVL 33

Accepted Solution

by:
paulmacd earned 500 total points
Comment Utility
Is it the only domain controller?  If not, you can still roll the FSMO roles over to another DC, demote, then promote this machine back to a DC.

If it is the only DC, you can do an authoritative restore from backup.  You do have backups...?
0
 

Author Comment

by:GreyHippo
Comment Utility
Yes, there is another domain controller.  How can I tell which has FSMO roles?  I do have backups.
0
 

Author Comment

by:GreyHippo
Comment Utility
Is there any way I can restore the registry key from a backup?
0
Too many email signature changes to deal with?

Are you constantly being asked to update your organization's email signatures? Do they take up too much of your time? Wouldn't you love to be able to manage all signatures from one central location, easily design them and deploy them quickly to users. Well, you can!

 

Author Comment

by:GreyHippo
Comment Utility
A different domain controller handles FSMO roles
0
 
LVL 33

Expert Comment

by:paulmacd
Comment Utility
Here's how to determine which DCs have which FSMO roles.

I don't know of any way to restore JUST the registry from a Windows backup.  It's possible to export the registry settings and save them as a file.  I recommend you do that before making any changes in the future.
0
 
LVL 11

Expert Comment

by:Mr Tortur
Comment Utility
Hi,
if you can log to your server using a domain admin account, even if you don't have access to all folders, can you have the rights with this account to give another account all the domain rights? if yes and if that suits you could probably avoid a major restore operation on your only dc.
As this is a win2003 server I guess there is a chance that you get rid of it soon. If not you should because microsoft support is ending this year.

Also I don't know if restoring a single key from backup is possible, and even more for a dc.. I am pessimist on this one... but maybe.

If my firt step is not acceptable for you, you should demote and promote again the server as past comments suggest, as you have another dc with fsmo roles (check all roles).

If all solutions does not satisfy you, maybe you should go with an AD restore, as past comments suggest, but don't forget that you will loose your AD changes since your backup.
0
 

Author Comment

by:GreyHippo
Comment Utility
I will try the to demote the server using DCPROMO tonight after all users have gone home.
0
 

Author Comment

by:GreyHippo
Comment Utility
I am guessing that once I demote / promote the server, it will generate new registry keys for the domain administrator.  Is this correct?
0
 
LVL 33

Expert Comment

by:paulmacd
Comment Utility
Since all that information comes from the domain, I would expect so, yes.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now