Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

allow restore of a DC without admin rights

Status
Not open for further replies.

peterve

IS-IT--Management
Mar 19, 2000
1,348
NL
How can I allow someone to rebuild an entire DC, when that person only has
- a ntbackup backup of the system state
- new hardware, fresh installed 2003, local admin password
- Directory Services Restore password

I don't want that user to have local admin rights or Domani Admin rights once the server is up and running

How can I do this ?

thanks

--------------------------------------------------------------------
How can I believe in God when just last week I got my tongue caught in the roller of an electric typewriter?
---------------------------------------------------------------------
---------------------------------------------------------------
 
I think I've found a way to do it
It requires the enterprise/domain admin to prepare a copy of a DC in vmware. I've written a procedure to do so on my blog:
Next, you can provide the vmware image to the local admin.
If he needs to recover AD, he should boot up the vmware image, go into restore mode and restore the most up to date ntds.dit file
(domain admin rights are not required for this)

I still need to do some additional testing with a p2v first, so watch out for new blog posts on that topic



--------------------------------------------------------------------
How can I believe in God when just last week I got my tongue caught in the roller of an electric typewriter?
---------------------------------------------------------------------
---------------------------------------------------------------
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top