Home All Groups Group Topic Archive Search About

How to Switch domains without having admin rights?

Author
19 Mar 2009 1:57 AM
ghurty
Hi,


I have a computer that was part of a domain. The administrator had limited
login to the domain only, no local login.

I have an account that has regular user rights, no administrator rights.

I want to connect the workstation to a new domain. But I cant change the
settings since I dont have admin rights.

Anything for me to do besides reformatting the whole machine?

Thanks

Author
19 Mar 2009 7:04 AM
Florian Frommherz [MVP]
Howdie!

ghurty wrote:
> I have a computer that was part of a domain. The administrator had limited
> login to the domain only, no local login.
>
> I have an account that has regular user rights, no administrator rights.
>
> I want to connect the workstation to a new domain. But I cant change the
> settings since I dont have admin rights.
>
> Anything for me to do besides reformatting the whole machine?

Talk to the admin folks of the old domain to unjoin it for you.

cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
Author
19 Mar 2009 4:53 PM
ghurty
That is not an option, because the previous domain name was fired in disgrace
after it was found out that he was doing illegal activity.

Thanks


Show quoteHide quote
"Florian Frommherz [MVP]" wrote:

> Howdie!
>
> ghurty wrote:
> > I have a computer that was part of a domain. The administrator had limited
> > login to the domain only, no local login.
> >
> > I have an account that has regular user rights, no administrator rights.
> >
> > I want to connect the workstation to a new domain. But I cant change the
> > settings since I dont have admin rights.
> >
> > Anything for me to do besides reformatting the whole machine?
>
> Talk to the admin folks of the old domain to unjoin it for you.
>
> cheers,
> Florian
> --
> Microsoft MVP - Group Policy
> eMail: prename [at] frickelsoft [dot] net.
> blog: http://www.frickelsoft.net/blog.
> Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
>
Author
19 Mar 2009 5:08 PM
Ace Fekay [Microsoft Certified Trainer]
In news:D5149EEA-828F-4C5C-B219-BD169370C5BB@microsoft.com,
ghurty <ghu***@discussions.microsoft.com>, posted the following:
> That is not an option, because the previous domain name was fired in
> disgrace after it was found out that he was doing illegal activity.
>
> Thanks

I would imagine at this point that disjoining the machine is the least of
your problems because it appears that you need to recover the domain admin
credentials. I'm somewhat surprised that the credentials were not confided
with company principals or that there weren't alternate credentials created.

Here are some possible solutions:

HOW TO: Reset your Lost 2003 Active Directory Admin Password
http://www.geeksaresexy.net/2009/03/12/how-to-reset-your-lost-2003-active-directory-admin-password/

Windows 2000 AD:
http://www.petri.co.il/reset_domain_admin_password_in_windows_2000_ad.htm

Windows 2003 AD
http://www.petri.co.il/reset_domain_admin_password_in_windows_server_2003_ad.htm

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
ace***@mvps.RemoveThisPart.org

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.
Author
19 Mar 2009 11:59 PM
Lanwench [MVP - Exchange]
Ace Fekay [Microsoft Certified Trainer] <firstnamelastn***@hotmail.com>
wrote:
Show quoteHide quote
> In news:D5149EEA-828F-4C5C-B219-BD169370C5BB@microsoft.com,
> ghurty <ghu***@discussions.microsoft.com>, posted the following:
>> That is not an option, because the previous domain name was fired in
>> disgrace after it was found out that he was doing illegal activity.
>>
>> Thanks
>
> I would imagine at this point that disjoining the machine is the
> least of your problems because it appears that you need to recover
> the domain admin credentials. I'm somewhat surprised that the
> credentials were not confided with company principals or that there
> weren't alternate credentials created.
> Here are some possible solutions:
>
> HOW TO: Reset your Lost 2003 Active Directory Admin Password
> http://www.geeksaresexy.net/2009/03/12/how-to-reset-your-lost-2003-active-directory-admin-password/
>
> Windows 2000 AD:
> http://www.petri.co.il/reset_domain_admin_password_in_windows_2000_ad.htm
>
> Windows 2003 AD
> http://www.petri.co.il/reset_domain_admin_password_in_windows_server_2003_ad.htm

Yes, I agree with Ace here. To the OP: your company needs to hire someone to
look after the network who knows how to do this for you. I don't mean this
harshly, but the fact that you're asking in a public newsgroup indicates
that you may be a bit out of your natural element.

But that said, resetting the local admin password (not the domain one) is
all you need to do. Note that you will lose your old domain user profile.
Author
19 Mar 2009 5:51 PM
dkumar
I think in this case you can reset the ADMIN password using ERD- Commander... Good tool in bad time. -- dkumar ------------------------------------------------------------------------ dkumar's Profile: http://forums.techarena.in/members/63487.htm View this thread: http://forums.techarena.in/active-directory/1143558.htmhttp://forums.techarena.in
Author
19 Mar 2009 6:54 PM
Ace Fekay [Microsoft Certified Trainer]
"dkumar" <dkumar.3pb5bb@DoNotSpam.com> wrote in message
news:dkumar.3pb5bb@DoNotSpam.com...
>
> I think in this case you can reset the ADMIN password using ERD-
> Commander... Good tool in bad time.
>

That would work for the local machine account, but not AD, unless they
changed that?

Ace
Author
21 Mar 2009 7:58 PM
Garry Starck - MCITP
Hi Ghurty

Use ERD Commander bootable CD, and just navigate the GUI and select the rest
local Admin Password. Anythin goes, even blank

Regards
--
Garry Starck
MCITP, MCTS AD, MCSE 2003 Messaging, MCDBA


Show quoteHide quote
"ghurty" wrote:

> Hi,
>
>
> I have a computer that was part of a domain. The administrator had limited
> login to the domain only, no local login.
>
> I have an account that has regular user rights, no administrator rights.
>
> I want to connect the workstation to a new domain. But I cant change the
> settings since I dont have admin rights.
>
> Anything for me to do besides reformatting the whole machine?
>
> Thanks
Author
21 Mar 2009 8:22 PM
Garry Starck - MCITP
Hi Ghurty, You di not mention type os OS of this box, if it does hoever
happen to be that of a Win 2000 OS, take that harddrive out and slave it in
another machine, search for the sam.    file in the
C:\WINDOWS\system32\config directory and delete it. Put the harddrive back in
the original box and boot up. Administrator has now got a blank password.
This does not work on XP, 2003 or above
--
Garry Starck
MCITP, MCTS AD, MCSE 2003 Messaging, MCDBA


Show quoteHide quote
"ghurty" wrote:

> Hi,
>
>
> I have a computer that was part of a domain. The administrator had limited
> login to the domain only, no local login.
>
> I have an account that has regular user rights, no administrator rights.
>
> I want to connect the workstation to a new domain. But I cant change the
> settings since I dont have admin rights.
>
> Anything for me to do besides reformatting the whole machine?
>
> Thanks