Administrator cant logon to his domain workstation as administrator

From: James W. Long (JamesLong_at_wowway.com)
Date: 08/31/04


Date: Tue, 31 Aug 2004 00:40:30 -0400

Dear all:

        HELP!

 My workstation fell out of the domain and I cant get it back in!
 I dont have a clue how it happened. I was trying to get to it
 from another client and could not see its files anymore.
 Then, I noticed my DC could not see it either.
 Then I noticed it would not logon when rebooted.

 I can logon to the DC fine,
 I can logon to hal9000 in the hal9000 (local) domain fine,
 and I can logon to to hal9000.jewelconsulting only IF
 IF I turn off the DC or disconnect the cable.

My set up:

1 win2k adv server DC. jewelntserver.jewelconsulting.org (jewelntserver)
10.0.0.50

2 win2k pro client hal9000.jewelconsulting.org (hal9000) 10.0.0.10

3 win2k pro client c18909-f.jewelconsulting.org (c18909-f) 10.0.0.20

The administrator cant login to his own account
(which he has everything on)
on the hal9000 machine as administrator.
 hal9000 no longer shows up in AD computers
on the DC.

  However....

  Turning off the DC or disconnecting the cable from hal9000 allows me
  to logon to hal9000 as administrator of jewelconsulting,
  but the domain doesnt see me, even if brought up afterwards.
  I think hal9000 is operating on a a cached copy in this case.

No domain computers can get to me, the messages are
 "no logon server available", when UNC access is tried from them,
and " Hal9000 is not accessable, network path noth found "
when clicked in "my network places" from other computers.

but, I can see other computers from Hal9000 via a UNC reference.
(AHA it works one direction... so the domain DOES know about me).

(also, in hal9000 I can get user profile info on the profiles on it,
and THERE, it lists Jewelconsulting\administrator. so It knows that much,
and the type of that account is "local")

I cant get any account info from the dc while on hal9000 other than that.
no listings of any types of accounts from the dc at all in the
jewelconsulting domain.

 when I try to log on to hal9000 with the dc on and all connected up
normally, the
message is: the machine account does not exist on the dc or the password is
incorrect.

 I tried adding a new machine in AD , but AD says I cant because a
pre-windows2000
machine is already in use. - (odd, it was native from the get go).
probably a good thing
this did not succede.

I would REALLY like hal9000 to get back into my domain, how do I do it?
can I save my account on hal9000? can I rescue the machine account on the
DC?

This machine has all my stuff.

 Thank you in advance to all you bright souls!

  James W Long.



Relevant Pages

  • XP Logon nightmare
    ... I am having the exact same error message. ... Logon failure: user account restriction. ... Not only are the other four computers are still able to access the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: new Administrative Group or new Storage Group?
    ... where are the properties located for confiuring a user account to be ... able to only use OWA. ... I'd suggest you experiment but prohibiting interactive logon ... >> restrict their AD account to logon to any computers. ...
    (microsoft.public.exchange.admin)
  • Re: Security Event ID 533 - user cant access OWA or RWW
    ... How about if I allow logon to the server, but restrict the other computers she can logon to? ... Checked her account in ADUC and found nothing wrong compared to other users. ...
    (microsoft.public.windows.server.sbs)
  • Re: new Administrative Group or new Storage Group?
    ... Student logon or something like ... where are the properties located for confiuring a user account to be ... >>> restrict their AD account to logon to any computers. ... How can I make it so the student mailboxes will be displayed by ...
    (microsoft.public.exchange.admin)
  • Re: change from limited account to administrator
    ... there was us both administartors now its only one user ... that is on a limited account, wanted to do a system restore but cant ... logon using the hidden default admin account, ...
    (microsoft.public.windowsxp.general)