Protection of the Administrator Account in the Offline SAM (223301)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server
This article was previously published under Q223301 SUMMARY
This article discusses the security of the offline Security Accounts Manager (SAM) and the accounts in it.
Windows 2000 Domain Controllers store domain user accounts, group memberships and other objects in the Active Directory. The Windows 2000 Backup tool and other third-party backup programs can back up jet-based Active Directory on an online Windows 2000 domain controller.
System maintenance and restoring the Active Directory can only be performed by placing the Active Directory "offline" or in "Directory Services Restore" mode. Directory Services Restore mode, which uses a registry-based SAM accounts database to store the administrator account and other built-in users and groups, represents a different security context than the Active Directory.
Modification Type: | Major | Last Reviewed: | 11/13/2003 |
---|
Keywords: | kbinfo KB223301 |
---|
|