JSI Tip 4418. The Configure Your Server Wizard sets blank recovery mode password?

Jerold Schulman

November 11, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

When you used the Configure Your Server Wizard to promote the first domain controller in a forest, prior to applying Service Pack 2 (SP2), the password for Directory Service Restore mode and the Recovery Console was set to a null value. This leaves the first domain controller in a forest open to a local attack, if it is NOT physically secured.

After applying SP2, or later, to the vulnerable domain controller, run:

  %SystemRoot%System32setpwd.exe [/s:].

When prompted with:

Please type the password for DS Restore Mode Administrator Account:,

type a new password.

NOTE: You can rerun setpwd if you make a mistake.




Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like