Jump to content

Active Directory and change password for domain admin


Recommended Posts

Posted

I have got at home couple of computers.

For the testing purposes, can we change the password for the active directory (win2003) domain admin without affecting the whole configuration for the users and groups ?

How can we change that ?

Thanks


Posted
For the testing purposes, can we change the password for the active directory (win2003) domain admin without affecting the whole configuration for the users and groups ?

how can we change ?

Posted

Use the "Active Directory Users and Computers" snapin on one of the DC machines (or the DC, if you have only one server). Change the password for the built-in "Administrator" account - but as has been previously stated, you should always have at least 2 admin accounts. Create another account with the same privilege level as the Administrator account if you have not done so already :yes:

Posted

You need to right-click on the Administrator account object itself to see the option. It's in the right-click menu itself - also note that if you are not logged on as the domain admin, or with domain admin privileges, you will not be able to reset the password for the domain Administrator account.

Posted (edited)
You need to right-click on the Administrator account object itself to see the option.
this is what I did ,,,,I hope I understood you correctly.
also note that if you are not logged on as the domain admin,

The screen that I posted for domain admin account logged in

BTW, I was logging to the domain controller PC remotely (Remote Desktop) not locally

Edited by zillah
  • 2 weeks later...
Posted (edited)
You need to right-click on the Administrator account object itself to see the option.

Administrator user is under "Users" object, I was mistakenly opening the Administrators under "Builtin" object

Edited by zillah
  • 3 weeks later...
Posted (edited)
Yes. But just so you dont lock yourself out have another backup admin account.

I have created a backup Administrator called (backupadmin), and i added him to the groups below:

1- Administrators

2- Domain Admins

3- Domain Users

Is this all what i have to do (only three groups) ?or I have to add more ?

Because all the groups that I have got for the username Administrator, is below

http://img257.imageshack.us/img257/6775/administratorsv7.jpg

administratorsv7.th.jpg

Edited by zillah
Posted

You really don't need it in anything but the Administrators group for the backup account. The account would be used strictly for unlocking the main admin account.

Posted
You really don't need it in anything but the Administrators group for the backup account.

What worried me , I can see the username : " administrator ", has been added to many gruops, not only group administrators,,,,if a username which is added to group administrators has got full previlige, why do I need to add it to other gropus as well ?

Regards

Posted

The only reason I can see adding an Administrative-level account to other groups would be if it was used as a service account (which shouldn't be done, btw), or if the administrators group was not given permissions to files or folders that some of these groups do have, but you still wanted the Administrator account to have access (that is also bad practice). Your assertion is correct, it technically should only need to be in the Domain or Enterprise Administrators group.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...