Re: SID

From: Chad A. Gross [SBS Community Member] (chad.gross_at_laytonflower.nospam.com)
Date: 10/06/04


Date: Wed, 6 Oct 2004 00:43:01 -0500

Hi Brian -

Did you have any local users set up on the PC (besides the local
Administrator)? Did you try logging in with the local Administrator's
password?

A Windows 2k / XP PC has to have at least one local user - Administrator by
default. Assuming you used the local Administrator account to join the PC
to a domain, most often no local users are created - users simply use their
domain account to log into the PC. If the PC is removed from the domain,
there still aren't any local user accounts (besides the Administrator) - but
without being joined to the domain, the PC cannot validate the domain user
credentials. Now, with XP for sure - it caches logins, which allows users
to log into an XP PC with their domain account even if a domain controller
isn't available. However, I'm assuming that once the PC is removed from the
domain, the cached credentials are removed as well.

The solution for the remaining PCs is to verify that you know the local
Administrator account, or set up a new local user account with local admin
privilegs. Then when you remove the PCs from the domain, you can log in
locally with this account & password, and have the necessary permissions to
join the new domain.

HTH!

-- 
Chad A. Gross - SBS MVP
SBS ROCKS!
www.msmvps.com/cgross
www.gosbs.org
Brian Agius wrote:
> My client had his server fail. We chose to rebuild the server. When
> we set the server up and connected the computers the users accounts
> were accepted but because we have a new server the workstation SID's
> were no longer valid. Therefore, we decided that we had to have the
> workstation join a workgroup and then join the new domain. We tried
> this on to machines (while connected to the network) each machine
> stated that it could not disconnect from the domain (old domain) but
> succeed in joining the workgroup. When we rebooted these machines all
> the accounts (guest, users and administrators) were gone completely.
> There was nothing we could do but reinstall the software.
>
> The question is
> a:) Can someone explain this to me because I do not believe it should
> have happened?
>
> b:) Considering it did happen and we have to more machine to join the
> domain can any recommend a sure fire procedure to follow so the
> machines join the domain without us having to reinstall all of the
> software?
>
> Thanks 


Relevant Pages

  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... you have risen to an Administrator this would be a given. ... server and run all LOB apps on these. ... If there are no encrypted files, just reset the DSRM account ...
    (microsoft.public.windows.server.sbs)
  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... Teneo> Interesting post and Im now gonna be a party pooper... ... connections) before cutting power to the server and to the Internet ... If there are no encrypted files, just reset the DSRM account ... and try old domain Administrator account's passwords. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote desktop: cannot copy files why still not working
    ... I created a new user on the XP box, set as an administrator ... this new user account is local to the XP system, ... In my environment, when I do an RDP connection to a server, I first log ... member of the local administrators group on the server. ...
    (microsoft.public.windows.server.security)
  • Re: Remote desktop: cannot copy files why still not working
    ... this new user account is local to the XP system, and a member of the local administrator's group on that workstation. ... In my environment, when I do an RDP connection to a server, I first log on to the xp workstation using my regular, non-privileged domain account, run mstsc, and then logon to the server using a domain account that is a member of the local administrators group on the server. ... In addition, I frequently use runas to run privileged applications on the workstation using my "administrator" account, and have found that files cannot be copied between those applications and anything running under the credentials of my regular account - even though my administrator account actually does have full access to everything on the workstation - just not through my regular account's view of that workstation. ...
    (microsoft.public.windows.server.security)
  • Re: Shared Fax device not available anymore after reboot server!?!
    ... the error message one by one to the Newsgroup for accurate research. ... You can send fax by using Administrator account. ... after the reboot of the server no account is able to fax anaymore. ...
    (microsoft.public.windows.server.sbs)