Try logging on DSRM mode
--please don't forget to Accept as answer if the reply is helpful--
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have one Domain Controller running Windows Server 2016
While adding a group of users to the Active Directory somehow the administrator account password got changed (or maybe even the account got deleted altogether?). I can no longer log onto the server. I tried logging onto the server as one of the users I had created and those accounts are all disabled.
I tried booting the server off of the boot disk and changing the password by typing the following in the command line:
f:
cd windows\system32
ren Utilman.exe Utilman.exe.old
copy cmd.exe Utilman.exe
net user Visioneer password
(where Visioneer is my username and password is my new password). However, I get an error saying the user name could not be found. Thus it leads me to believe maybe the account was deleted? When I try to log in as Administrator it says that the account is disabled.
I cant login to my server anymore. How do I regain access?
Try logging on DSRM mode
--please don't forget to Accept as answer if the reply is helpful--
Hello @Braden ,
Thank you for posting here.
How many DCs are there in your AD forest?
If you only have one DC and there is recent backup of this DC, we can try to restore this DC from the recent backup.
1)Start or restart the DC, press F8 to enter the safe mode and then select “Directory Services Restore Mode”.

2) Logon the DC with DSRM Administrator account (ComputerName\Administrator or .\Administrator) and password.
3) Perform the AD DS standard recovery procedure, that is an unauthoritative restore.
4) Start-> Server Manager->tools-> Windows Server Backup->Recover
5) Select the location where the backup is stored: This server or A back stored on another location
6) Select the backup date which should not before the system Tombstone Lifetime, and the default value is 180 days.
7) Select “System state” in the Select Recovery Type.
8) Select location for system state recovery:
Original location with the option “Perform an authoritative restore of Active Directory files”. By default, we do not select this check box.
Alternate location
9) Click “Next”, please DO NOT select the check box “Automatically reboot the server to complete the recovery process”.
10) After the restore process is completed successfully, you can click the restart button. Because if you only have one DC, you do not need to use ntdsutil.exe tool to mark objects as authoritative.
By the way, would you please tell us how you did it (add a group of users to the Active Directory)?
Hope the information above is helpful.
Should you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Just checking if there's any progress or updates?
--please don't forget to Accept as answer if the reply is helpful--
Hello @Braden ,
Thank you for your update.
I am so glad to hear that "I ended up tearing out the hard drives and salvaged what I could off of them.".
As always, if there is any question in future, we warmly welcome you to post in this forum again. We are happy to assist you!
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.