G
Guest
Hi All,
I think a lot of people may benefit if they know how to delete the Domain
Controller computer account for the purpose of the System State backup
validation.
Scenario:
Forest Functional Level is Windows 2003.
There are 2 functional domain controllers - both Windows 2003: DC_good and
DC_bad.
We took a System State backup on DC_good and DC_bad.
Now we want to pretend that virus deleted the Domain Controller computer
account of the DC_bad. Our first goal is to delete DC_bad's computer account
from
OU=Domain Controllers,DC=mydomain,DC=local.
How to do it so DC_bad's computer account would not be recreated once DC_bad
comes back online.
I tried to change the isCriticalSystemObject of the DC_bad to FALSO or
NOT_SET in the ADSIEdit, but it failed with error: "Access to the attribute
is not permitted because the attribute is owned by the Security Accounts
Manager (SAM)."
Additionaly I tried the following steps, but they did not work for me:
1. Tried to delete DC_bad from the ADUC.
2. Tried to delete DC_bad from the ADSIEdit.
3. Tried to delete DC_bad from the LDP.
4. Tried to delete DC_bad from the NTDSUtil.
The furthest where I could get was that I was able to delete
CN=NTFRS Subscriptions,CN=DC_bad,OU=Domain Controllers,DC=mydomain,DC=local
and
CN=NTFRS Subscriptions,CN=DC_bad,OU=Domain Controllers,DC=mydomain,DC=local
CN=DC_bad,CN=Domain System Volume (SYSVOL share),CN=File Replication
Service,CN=System,DC=mydomain,DC=local
but I was unable to delete the DC_bad from the OU=Domain
Controllers,DC=mydomain,DC=local irreversably. Please help me to accomplish
that.
Thank you in advance,
Alex
I think a lot of people may benefit if they know how to delete the Domain
Controller computer account for the purpose of the System State backup
validation.
Scenario:
Forest Functional Level is Windows 2003.
There are 2 functional domain controllers - both Windows 2003: DC_good and
DC_bad.
We took a System State backup on DC_good and DC_bad.
Now we want to pretend that virus deleted the Domain Controller computer
account of the DC_bad. Our first goal is to delete DC_bad's computer account
from
OU=Domain Controllers,DC=mydomain,DC=local.
How to do it so DC_bad's computer account would not be recreated once DC_bad
comes back online.
I tried to change the isCriticalSystemObject of the DC_bad to FALSO or
NOT_SET in the ADSIEdit, but it failed with error: "Access to the attribute
is not permitted because the attribute is owned by the Security Accounts
Manager (SAM)."
Additionaly I tried the following steps, but they did not work for me:
1. Tried to delete DC_bad from the ADUC.
2. Tried to delete DC_bad from the ADSIEdit.
3. Tried to delete DC_bad from the LDP.
4. Tried to delete DC_bad from the NTDSUtil.
The furthest where I could get was that I was able to delete
CN=NTFRS Subscriptions,CN=DC_bad,OU=Domain Controllers,DC=mydomain,DC=local
and
CN=NTFRS Subscriptions,CN=DC_bad,OU=Domain Controllers,DC=mydomain,DC=local
CN=DC_bad,CN=Domain System Volume (SYSVOL share),CN=File Replication
Service,CN=System,DC=mydomain,DC=local
but I was unable to delete the DC_bad from the OU=Domain
Controllers,DC=mydomain,DC=local irreversably. Please help me to accomplish
that.
Thank you in advance,
Alex