Domain Controller: Can't Log Into Safe Mode

2

1

Today I've removed the DSRM password with PCUnlocker, and I can then boot to Directory Services Restore Mode and logged into the local administrator account with a blank password. But the most strange thing is that the Safe Mode refuses my login. I have tried to type Computer_Name/Administrator and leave the password box blank but it still doesn't work! It keeps saying the username or password is incorrect.

Could anyone here explain this issue? How can I reset the Safe Mode password then? My domain controller is running Windows Server 2008 R2. Thanks a lot!

Donald Ford

Posted 2014-09-30T07:34:40.060

Reputation: 21

I also tried on Windows 2003 domain controller and the safe mode also doesn't allow me to login. This seems to be a common problem but it's quite weird! I think the safe mode password should be the same as DSRM password, and they both are stored in the SAM database. – Donald Ford – 2014-10-02T04:02:23.180

Answers

1

Directory Services Restore Mode is different than Safe Mode. The DSRM password (which you seem to have successfully reset) becomes the password for the local Administrator account when the machine is in DSRM, but is otherwise unimportant. Note that there aren't really local accounts on domain controllers; they don't have SAM databases like workstations do.

When the machine is in actual Safe Mode, the DSRM password doesn't work because you're not in DSRM mode. You'll need to know a domain admin's password to log onto a domain controller in normal Safe Mode.

Also, to specify a domain or computer that a username is in, you need to use a backslash (\), not a forward slash. For example, MYCOMP\LocalUser specifies that you're logging onto the LocalUser of MYCOMP, while MYCOMP/LocalUser makes you try to log on as a user named MYCOMP/LocalUser to the default domain, and that's probably not going to work.

Ben N

Posted 2014-09-30T07:34:40.060

Reputation: 32 973