Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations dencom on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory crashed! Help please!

Status
Not open for further replies.

Raziel014

Technical User
Nov 1, 2005
51
NO
Help here please!

I have two 2003 Servers running where one of them is the main domain controller and it contains AD.
Yesterday, I was working on a new file server and wasn't doing anything particular and I noticed that I couldn't log on to the terminal server (same server that contains AD)

It just said that the system couldn't load the user profile.
I didn't get squat, so I restarted the server and now I can't even log in.

I get a:

LSASS.exe - System Error, security Accounts Manager initialization failed because of the following error: Directory cannot start. Error status 0xc00002e1

And then I'm told that the server reboots and starts Directory Services repair mode or something. And then it tells me to type a password and username, which I have NO IDEA what is! I don't even remember typing a password when I installed the server! Is there a default password or something? I'd hate to loose all my users! :(

I thought that perhaps it's got something to do with the rights and stuff I was setting with the home folders of the users before it crashed, but I didn't do anything to the root or anything like that. Only on the folders of the rootshare.

So the question is:

What can I do to fix this? I've tried Last good settings and it didn't work. It just rebooted after the logon window appeared. I've only got a backup from 9.June this year and it's a bit old.

But the thing is that the other 2003 Server is also a Domain Controller for some reason and it should contain AD..?
I know that these two servers did replicate AD between themselves even though I never told them to. They're only connected together as far as I know.

But can somehow start the Recovery Console and remove the AD service? And can i get the second server to be the primary domain controller containing AD?
 
Go into Control Panel > Administrative Tools > Active Directory Sites and Services. Under Default-First-Site-Name, check to see what servers are there. If what you say above is correct, both servers will be listed. If so, see which one has NTDS settings, right click and go to Properties. The connections tab will show you the replication schedule.

Also, go into Active Directory on the good server, right click on the domain name and look to see what servers are listed as the masters. If the old server is listed, you might be able to change the RID and PDC master to your working server, get domain logins working again, then recover your dead server.

For the dead server, I believe the recovery password is set when you install Active Directory. Try blank password or any old admin passwords you might have had.

"Rule #1 - When stumped, check your Event Logs!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top