Link to home
Start Free TrialLog in
Avatar of jonmenefee
jonmenefeeFlag for United States of America

asked on

Changing Admin password on Server 2008 DC

Hey guys

I have been tossing some softballs lately but now I have a hard one to figure out.  Customer has had the same Administrator password for the past 6 years and they are working just fine, but a new IT guy wants to change the Administrator password.  Sounds simple enough except that when he does it, the onsite website stops working and people start having trouble surfing the Internet.  Sounded like a DNS issue but I cannot figure out why that would happen. Do I need to restart the Domain Controller when I change the Administrator password or should I log out and log back in as Admin?  When we change it back to the original password everything starts to work again.  We never have tried restarting the DC when this happens.
SOLUTION
Avatar of Will Szymkowski
Will Szymkowski
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Far more likely is that in the past services and shares and who knows what else have been set up to run using the domain administrators account.  This is not an uncommon mistake of Amatuer admins who don't fully understand network security.
If you change the password during a period of least disruption and monitor the security event logs on your DC's then you will like see authentication failures and by investigating these you will hopefully locate what's breaking
Also just examine Seevices on each server and look for anything that has a Run As User of Administratir.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jonmenefee

ASKER

Thanks guys

Ok, we have one domain controller, a Server 2008 with DNS and DHCP installed on it and from what I can tell the DNS services are running as a local account

I have attached a couple of screenshots that shows the DNS settings and the Services Log on As area.

Thanks and looking forward to your replies!!
DNS-Service.jpg
Services.jpg
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Before the password is changed, I can ping the website (that is currently on the DC) from within the network and it gives me the internal IP address of the server.  When I change the password and wait about 30 minutes, when I try and ping the server it times out and instead of the Internal IP address it gives me the external IP address.

The DC is running a website that is being moved off very soon (the project I am on) that is accessible from the Internet using an uncommon port number.  Simply typing in the address wont work, it does require using a unique port.  Even with that little small bit of security I told them to take the website off the DC.  So we are doing just that and we are also changing the Admin password.  When the password was attempted to be changed yesterday, nearly all the people on the network lost connection to the internal website and they had trouble getting to the Internet.

There is no NAS and no Proxy server running.  Everyone's only DNS setting is the DC's IP address.  that's what is making me think its the DNS that is causing the issue.  Should I log off the Administrator when the password is changed and see if that makes a difference?

Also, in the script above, the c:\test\servers.txt, is that a txt that I put the servers names in? or is that where the output goes?
that is where you put the server names in. the 30 minute wait is probably the TTL (time to live) for your DNS.  Since the main item is the website I'd be checking the apppool s that is probably where the problem is.
We are still looking at the services but that is where I believe the problem is.  Thanks for all the help guys! :-)