Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

changing domain administrator password

Status
Not open for further replies.

jeffkr

IS-IT--Management
Feb 2, 2005
12
US
Hi,
We had a VERY weird thing happen this morning.It appears that the domain administrator ( administrator) password was somehow changed. I have no idea what the new password is . no intrusion was detected and I was the only one in the office at the time. I went to rdp into a server and for the message that the system could not log me in due to incorrect username or password.The consoles for one of the domain controllers was already up logged in and I found this in the security event log:

Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 642
Date: 10/20/2010
Time: 8:04:14 AM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: xxxxDC01
Description:
User Account Changed:
Target Account Name: Administrator
Target Domain: NORTHVILLE
Target Account ID: NORTH\Administrator
Caller User Name: xxxxDC01$
Caller Domain: NORTHVILLE
Caller Logon ID: (0x0,0x3E7)
Privileges: -
Changed Attributes:
Sam Account Name: -
Display Name: -
User Principal Name: -
Home Directory: -
Home Drive: -
Script Path: -
Profile Path: -
User Workstations: -
Password Last Set: 10/20/2010 8:04:14 AM
Account Expires: -
Primary Group ID: -
AllowedToDelegateTo: -
Old UAC Value: -
New UAC Value: -
User Account Control: -
User Parameters: -
Sid History: -
Logon Hours: -


I have a backup enterprise admin account and a backup domain admin account. I could use to change the password back to something I would know.
I dont know what ramifications I would have changinge it without knowing the old on.
any help would be appreciate any help

Jeff
 
Knowing the old one won't do you any good once you change it. If it's been changed, as the audit clearly shows, and yet there was no intention or need for it to be changed, I'd start with the assumption that you've been compromised. I'd certainly change it immediately before whomever has that valid credentials uses them to change all of your other administrative account passwords, essentially locking you our of your active directory.

Pat Richard MVP
Plan for performance, and capacity takes care of itself. Plan for capacity, and suffer poor performance.
 
so then I just do a change password from aduc ?
I've never change the domain id like that.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top