All Administrator Accounts Locked Out Server 2008 R2

Can you please ask your question again?

My response to your last question was:
Well I can log in locally to the VM's, but just not using the domain accounts.

Is one of the VM's is serving as the DC.
 
I can log into the DC using the local account but not the domain account.

I only have three VM's on the Domain and one serves as the domain controller.
 
Djr22192 said:
I can log into the DC using the local account but not the domain account.
That's a problem...
Can you access Active Directory from somewhere else with your domain credentials?
 
No. Two of the VM's have the AD roles installed. I cant logon on to them with any domain credentials because I believe all of the Administrator AD accounts are locked out.
 
With the other VM's it sounds like they were removed from the domain or got disassociated some how.

As for the DC, if you can't log into anything with domain credentials it sounds like you may be hosed.

It's important to note - is this a work environment? Production? Test? Are we talking about a situation where data is lost or just a lab environment where you can start over?
 
It was the production environment.

We have a really small environment. Host (phsyical) and 3 VM's (HyperV)

One of the VM's serve as the domain controller and I believe something corrupted on that VM which prevent any domain logins.

Last night I restored that VM from a older snapshot I took a few weeks again.

I was then able to login to the domain (I Believe since I went back to an older snapshot That allow me to go back in time to when all of the accounts was not locked out)
 
The lockout is at the domain level, not the VM level. So that makes no sense that restoring a VM from a snapshot would allow this. Maybe if you restored your DC to a previous snapshot that had your AD data in it - but other than that restoring a VM (not DC) would not fix this issue.

Sounds to me more like the VM was removed from the domain at some point after the snap was taken, so you reverting back to the original snap restored to the spot before the removal of the domain.
 
Yes. I restored the DC that had the AD on it. I assuming that rolled it back to a previous time when the passwords was not locked out.
 
Back
Top Bottom