Abstract
I have recently installed a Windows 2003 Server at home and I set up a local domain using Active Directory features. Everything worked fine until I changed the Domain Admin password. It seems that I mistyped the new password twice (which I would attribute to the previous heavy night out), and, well, I could not log on the Domain Controller anymore (I did not have a backup admin account, I do now!).
A few tricks about resetting the Domain Admin Password on Windows 2000 Server have been published, but after Microsoft strengthened some security aspects on Windows 2003 Server, those hacks do not work anymore.
After struggling a few days, I finally managed to reset the domain account and I am going to present the trick to you in this paper.
This trick has a few important requirements, be sure you meet them before yelling at me.
This paper does NOT intend to serve any malicious sort of hackers, but just lousy administrators (like me). N.B.: This is known to work on Windows Server 2003 Standard Edition, without any service pack installed. Let me know if you have tried it on another configuration. Thanks!
Requirements
These are compulsory!
You need:
1/ Local access to the Domain Controller (DC).
2/ The Local Administrator password.
3/ Two tools provided by Microsoft in their Resource Kit: SRVANY and INSTSRV. Download them from
here.
The Local Administrator account is