现在的位置: 首页 > 综合 > 正文

Using Terminal Services for Remote Administration of Windows 2000 DCs in Directory Service Restore Mode

2013年12月09日 ⁄ 综合 ⁄ 共 4595字 ⁄ 字号 评论关闭
This article was previously published under Q256588
On this page
SUMMARY SUMMARY
MORE INFORMATION MORE INFORMATION

SUMMARY

Some low-level maintenance of the Windows 2000 Active Directory requires that Windows 2000 domain controllers (DCs) boot to Directory Service Restore mode. Configuring Windows 2000 domain controllers with Terminal Services in Remote Administration mode permits administrators to perform operations requiring Directory Service Restore mode without having to be present at the console of the server. This article describes the use of Terminal Services to transition a Windows 2000 domain controller between online and Directory Service Restore mode.

MORE INFORMATION

Windows 2000 domain controllers perform regularly scheduled online defragmentation of the Active Directory database while the server is online. Advanced operations (including directory service repair functions and reducing the size of the Active Directory when objects are deleted) require that the Windows 2000 domain controller be rebooted in Directory Service Restore mode. To transition a Windows 2000 domain controller between online and Directory Service Restore mode:

1. Configure the Windows 2000 DC with Terminal Services in Remote Administration mode. You can add or modify Terminal Services in the Add/Remove Programs tool in Control Panel. Remote Administration mode is preferred for Windows 2000 domain controllers so that performance is not adversely impacted.For additional information about Terminal Services, click the article numbers below to view the articles in the Microsoft Knowledge Base:

243213 Impact of Running Remote Administration on a Terminal Server
243212 Determining the Mode of a Terminal Services Server
2. Create a new entry in the Boot.ini file (a hidden system file) for the Windows 2000 Domain Controller installation to permit Windows 2000 to be booted in Offline Repair mode. Add the following switch:

/SAFEBOOT:DSREPAIR /SOS

The /SAFEBOOT:DSREPAIR switch only works Windows 2000 DCs. For a sample Boot.ini file with the entry:

multi(0)disk(0)rdisk(0)partition(2)/WINNT="W2K DC //your server name" /fastdetect

Create a second entry with the same ARC path and /SAFEBOOT:DSREPAIR switch so the Boot.ini file appears as:

multi(0)disk(0)rdisk(0)partition(2)/WINNT="W2K DC //your server name" /fastdetect
multi(0)disk(0)rdisk(0)partition(2)/WINNT="W2K DC //your server name" /fastdetect /SAFEBOOT:DSREPAIR /SOS

NOTE: This should be tested locally prior to being used in a Remote Administration capacity. If the Boot.ini file is not modified properly, the computer will not come back up for connection by a Terminal Services session. Additionally, when you restart the computer, make certain you select Restart so it will properly restart. Choosing "Shut down" leaves the server turned off until someone physically goes to the server and turns it back on. The Terminal Services session will generate the following message if the server has not come back up for connection yet:

Terminal Services Client Disconnected

The server could not be found. Check that you have specified the correct server or IP address, and then try connecting again.

Click Close, and then connect again after a few moments to make the connection. For additional information about safeboot switches, click the article number below to view the article in the Microsoft Knowledge Base:

239780 Safe-Mode Boot Switches for Windows 2000 Boot.ini File
3. When transitions between Active Directory and Directory Service Restore mode are required, establish a Terminal Server session to the appropriate Windows 2000 DC, select the desired ARC entry in the Boot.ini file, and then restart the computer. Options to modify the Boot.ini file include:

Use a text editor to modify the "default=" entry in the Boot.ini file.
Use the "Startup and Recovery" option on the Advanced tab of the System tool in Control Panel to select the desired startup option.

Active Directory restorations, offline defragmentation and other advanced operations should be performed while the Windows 2000 domain controller is booted in Offline Repair mode.

Windows 2000 computers can be rebooted by an administrator at the console or over a Terminal Server client session by clicking Start, clicking Shutdown, and then clicking Restart. Provide the server with enough time to reboot and generate the Welcome to Windows screen, also, you may need to try a few times if the computer is not ready yet. When you log on to the computer in Offline Restore mode, use the administrator account and current password designated for offline administration when the Windows 2000 DC was promoted with the Active Directory Installation Wizard (Dcpromo.exe). For additional information about security and access for Terminal Services remote administration and the offline administrator account, click the article numbers below to view the articles in the Microsoft Knowledge Base:

223301 Protection of the Administrator Account in the Offline SAM
247989 Terminal Server Clients Cannot Log on to Domain Controller
250991 Cannot Log On to Windows 2000 Terminal Services with RDP Client
253831 Remote Administration of Terminal Services by Non-Administrators


APPLIES TO
Microsoft Windows 2000 Server
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Keywords: 
kbhowto kbnetwork kbdisasterrec kbtermserv KB256588

抱歉!评论已关闭.