IT News & Technology update

Provide comprehensive update related to Computer, technology, software, anti virus and another electric device

Does Ntdsutil.exe know it's in Directory Restore mode?

Written by IT News on 10:25 PM

NTDSUTIL is a tool used for many Active Directory database maintenance tasks, such as defragmenting the DB, moving the DB and/or log files to a different place, cleaning the DB and more.

NTDSUTIL will allow you to perform many of it's functions while the DC is up and running. However some of the maintenance tasks (such as performing an offline defragmentation of the DB and moving the files to a different location, along with the Authoritive restore commands) require that you start the DC in Directory Restore mode, found when you access the boot menu by pressing F8 before the server starts it's startup sequence.

When you start the domain controller in Directory Restore mode, the DC sets the environment variable safeboot_option to "dsrepair."

If, for some reason, you want to access the "protected" features of NTDSUTIL while it is NOT in the Directory Restore mode, you will receive an error similar to this:

If you want to check something in NTDSUTIL that is allowed only in Directory Restore mode, you can "trick" the program by typing the following statement at a command prompt:

Lamer Note: Type the above command into a different CMD window, NOT the one that NTDSUTIL is running in.

Don't use this approach on a live or important machine because it could result in system damage if you try to perform system modifications when the system isn't in Directory Restore mode.

Active Directory Tip: Kerberos basics for Windows authentication

Written by IT News on 12:19 AM

KERBEROS PROTOCOL: WHAT EVERY ADMIN SHOULD KNOW ABOUT WINDOWS AUTHENTICATION

Kerberos can be a difficult protocol to understand for some Active Directory admins, so it's best to start at the beginning. Expert Gary Olsen describes the basics of how Kerberos authentication and authorization works for Windows.

erberos is a protocol that, prior to Windows 2000 Server, Windows NT admins could ignore. At that time, Microsoft used NTLM for authentication, which was fine for the Windows world -- but nowhere else.

With the inception of Windows 2000, Microsoft adopted Kerberos as an authentication protocol. Not only was it much more secure and efficient than NTLM, but it also played nicely with other operating systems such as Unix.

Click here to read this full article

Search This Blog

Ads and Sponsored by:



Want to subscribe?

Subscribe in a reader.