Managing the DSRM passwords on domain controllers
This recipe shows how to manage the password to sign in to domain controllers when the Active Directory Domain Services service is not running or the domain controller is in DSRM.
Getting ready
To manage the DSRM password on a domain controller, sign in to a domain controller with a user account that is a member of the Domain Admins group, the Backup Operators group, or the Server Operators group.
For the scenario where the DSRM Administrator password is automatically synchronized with an account in Active Directory, create a disabled user account with a strong password. Document the password in a password vault. Additionally, ensure all domain controllers run Windows Server 2008 or newer versions of Windows Server and are replicating properly.
How to do it...
This recipe shows two routes:
- Manually resetting the DSRM administrator password
- Synchronizing the DSRM administrator password