Random Question About Stopping Directory Services

boss and i were discussing this.


If I have a small network with a single server acting as a domain controller and a file server, and I stop the active directory service, have I just locked myself out of the network?

Thanks!


John
__________________________________________

Work In Progress: BSCI, Sharepoint

Comments

  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    Cached credentials might carry you a little ways, but you're probably going to still run into a lot of problems, especially when those expire or when users who don't have any try to log on.

    So was this really a discussion, or were you called into his office to explain what happened to the network? icon_lol.gif
  • cnfuzzdcnfuzzd Member Posts: 208
    dynamik wrote:
    Cached credentials might carry you a little ways, but you're probably going to still run into a lot of problems, especially when those expire or when users who don't have any try to log on.

    So was this really a discussion, or were you called into his office to explain what happened to the network? icon_lol.gif


    lolz

    that would be a pretty sweet conversation


    as a side note:

    if i only have one domain controller and i stop the ntds service, and lock myself out of the network, the service will restart if i reboot, right?


    right?

    .....




    icon_cool.gif
    __________________________________________

    Work In Progress: BSCI, Sharepoint
  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    Yea, as long as it's set to automatic. Just go into services and check what it's set to.

    Just curious, how did this come up?
  • cnfuzzdcnfuzzd Member Posts: 208
    dynamik wrote:
    Yea, as long as it's set to automatic. Just go into services and check what it's set to.

    Just curious, how did this come up?

    actually, we were just sitting around discussing the changes in 2008. i mentioned this one, and he was stunned. We then determined that most likely it would be of no use to us, since most of our clients have one domain controller. (i know, i know)


    john
    __________________________________________

    Work In Progress: BSCI, Sharepoint
  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    Heh, you deal with a lot of small clients? I started doing some contract work for a guy who deals with a lot of small businesses, and I have recently been rebuilding a lot of domains from scratch because they're a single DC with no backup type of environment. How hard is it to back up the system state once in awhile? At least the machine he rebuilt has RAID this time around icon_lol.gif
  • jibbajabbajibbajabba Member Posts: 4,317 ■■■■■■■■□□
    Even worse is actually how little small companies know about Active Directory ..

    One day in my last job I was asked whether I installed a domain controller before (which meant they haven't read the CV in the first place) .. Anyway, someone deleted the usergroup from the support staff and apparently they always reinstalled the DC .. Well, since my manager wasn't there I had to help "reinstalling" it .. I just prefered an authoritative restore of the group and continue drinking my coffee ... Oh man I could tell you stories without an end :):)
    My own knowledge base made public: http://open902.com :p
  • undomielundomiel Member Posts: 2,818
    Gomjaba, I know your pain, I know it very well.
    Jumping on the IT blogging band wagon -- http://www.jefferyland.com/
  • SlowhandSlowhand Mod Posts: 5,161 Mod
    I did a project recently, deploying a brand-spankin' new Active Domain in Windows Server 2008 native mode. When going over the changes, my counterpart asked me, "what happens if we disable the AD service on both domain controllers?" I told him, "Try it, it'll be funny." icon_lol.gif

    Note: he hasn't tried it yet. . .

    Free Microsoft Training: Microsoft Learn
    Free PowerShell Resources: Top PowerShell Blogs
    Free DevOps/Azure Resources: Visual Studio Dev Essentials

    Let it never be said that I didn't do the very least I could do.
  • thesaintjimthesaintjim Member Posts: 1 ■□□□□□□□□□
    If no other domain controller is available, you can log on to the domain controller where AD DS is stopped in Directory Services Restore Mode (DSRM) only by using the DSRM Administrator account and password by default, as in Windows 2000 Server Active Directory or Windows Server 2003 Active Directory.

    You can change the default by modifying the DsrmAdminLogonBehavior registry entry. By modifying the value for that registry entry, you can log on using the DSRM Administrator account in normal startup mode to a domain controller that has AD DS stopped even if no other domain controller is available. You do not need to start the domain controller in DSRM. This can help prevent you from getting inadvertently locked out of a domain controller to which you have logged on locally and stopped the AD DS service.
Sign In or Register to comment.