Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

User rights prob. Urgent!!!

Status
Not open for further replies.

Stevehewitt

IS-IT--Management
Jun 7, 2001
2,075
GB
Hey,

I am a pretty experienced netadmin, but i fell into the big trap of removing admin rights!
I have recently changed the domain from ttuk.com to timbertradinguk.com
This one machine was last, and I have just realised that the admin cannot make the workstation join the new domain. Is there a way round this?! Can I use a command prompt or something?

Many Thanks, Steve Hewitt
IT Administrator

Windows 2000 Microsoft Certified Professional (75 - 215)

 
I'm not sure if this is relevant but I am assuming that you still have admin rights through another machine and you haven't completely locked yourself out.
Create an account on the domain, for instance ntput, that has rights to add computers to the domain.
Then login to the workstation and remove it from the domain by making it a member of a workgroup. Reboot.
Log back into the workstation and specify a new computer name (if necessary) and then specify the domain to join. When it asks you to specify an account with privedges to add users to the domain specify ntput and give it the necessary password.
Hope this helps.
 
Im a little unclear about what is going on here, but i'll assume some things in order to save you some time..


Delete the PC's computer account from your Domain Controller. Replicate if necessary.
If you can logon to the PC locally as an administrator, remove the computer from the domain, and join it to a workgroup. Change the computername, Reboot, and logon locally again to confirm changes (just an extra step to make sure).
Then, re-join the computer (as if new) to the new domain using a domain account with administrator rights and permissions to add a new computer to the domain.

Hope that helps..
Pbxman
Systems Administrator

Please let Tek-Tips members know their posts were helpful.
 
Sorry, I didn't type it out properly. I have now trashed the old domain (ttuk) controllers and brought them up as the new domain. The LOCAL administrator on the problem workstation doesn't have the rights to join a domain. This computer is the last in the domain, therefore I cannot get this workstation to join the domain as the LOCAL admin doesn't have the rights + there is no longer a valid domain the workstatation belongs to, so the domain admin password won't work! :-(

Cheers, Steve Hewitt
IT Administrator

Windows 2000 Microsoft Certified Professional (75 - 215)

 
Well, I don't know know if this might help you. Is that computer still connected to the old domain? One thing you can do (if i understand your problem) is join it to any workgroup (i.e. WORKGROUP) and reboot your machine. Log in locally then connect to the new domain. Enter in domain administrator information when prompted, and it should join you.
 
Hey,

I know how to change domain, but the LOCAL admin no longer has the rights to do it. I can't log in as the domain admin as the machine isn't part of that domain.
Is there no command line I can use?
Steve Hewitt
IT Administrator

Windows 2000 Microsoft Certified Professional (75 - 215)

 
just rebuild the pc, and learn from this mistake.
Pbxman
Systems Administrator

Please let Tek-Tips members know their posts were helpful.
 
Someone please help! This machine can't really be taken down. Is there no command prompt I can use to just make it join the new domain. I know the NEW Domain admin password but not the old one.

Cheers guys (and gals! ;-)) Steve Hewitt
IT Administrator

Windows 2000 Microsoft Certified Professional (75 - 215)

 
This seems pretty cut and dry to me(assuming you can log in as local admin):

Right click "My Computer"
Go to "Network Identification"
Click "Properties"
Change "Member of" to a Workgroup and type in any workgroup name you desire(it doesn't matter).
Ok through all the prompts. You will probably get one telling you the computer account could not be removed from the domain(oh well the old domain doesn't exist anymore anyway).

Reboot
Log in as local admin.
Right Click "My Computer"
Go to "Network Identification"
Click "Properties"
Change "Member of" to a Domain and type in the name of your new domain.
Click "OK" and it is going to ask you for a account and password. Type in the NEW Domain Administrator username and password.

Reboot.
Problem solved.

Just because the old domain is not available doesn't mean you can't join the new domain.

I may have read the above wrong, but after the third time reading it I do not see any reason why this wouldn't work.

Of course what I typed above is just re-iterating a group of above responses. Oh well, maybe it will help.

Roger
 
How about create an account on both the new domain and the old PC with the same user ID on both and set the password the same on both.Then on the domain controller make that user is a member of the users allowed to join the domain.Logon to the PC having problems using the new user and join the domain.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top