<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Restartable AD DS and DSRM Logon Behaviors</title><link>http://msmvps.com/blogs/ad/archive/2008/10/21/restartable-ad-ds-and-dsrm-logon-behaviors.aspx</link><description>Ever since Windows 2000&amp;#39;s implementation of Active Directory (AD) we have had a method to restore AD objects that were removed. Although it hasn&amp;rsquo;t been as easy as hitting CTRL-Z to undo a mistakenly deleted object or to try to restore from the</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Restartable AD DS and DSRM Logon Behaviors</title><link>http://msmvps.com/blogs/ad/archive/2008/10/21/restartable-ad-ds-and-dsrm-logon-behaviors.aspx#1666442</link><pubDate>Tue, 27 Jan 2009 19:23:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1666442</guid><dc:creator>grinder</dc:creator><description>&lt;p&gt;On &lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/cc732714.aspx"&gt;technet.microsoft.com/.../cc732714.aspx&lt;/a&gt; another options for DSRMAdminLogonBehavior&lt;/p&gt;
&lt;p&gt;0 (default for Windows Server 2008) - The DSRM Administrator account cannot be used to log on.&lt;/p&gt;
&lt;p&gt;You can only log on to the domain controller with a domain account. This requires an additional domain controller to authenticate the request and working connectivity, name resolution, authentication, and authorization between the local domain controller and the authenticating domain controller.&lt;/p&gt;
&lt;p&gt;1 - The DSRM Administrator account can be used to log on only when the AD DS service is stopped.&lt;/p&gt;
&lt;p&gt;This value can improve functionality by allowing more options for logging on to a domain controller. However, keep in mind that the DSRM Administrator account password is not checked against any password policy.&lt;/p&gt;
&lt;p&gt;You might change the entry to this value in a domain that has a single domain controller, or on a domain controller that is on an isolated network, or on one that points to itself or other offline domain controllers exclusively for name resolution.&lt;/p&gt;
&lt;p&gt;2 - The DSRM Administrator account can be used to log on at any time. Using this value is not recommended because the DSRM Administrator account password is not checked against any password policy.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1666442" width="1" height="1"&gt;</description></item><item><title>re: Restartable AD DS and DSRM Logon Behaviors</title><link>http://msmvps.com/blogs/ad/archive/2008/10/21/restartable-ad-ds-and-dsrm-logon-behaviors.aspx#1666438</link><pubDate>Tue, 27 Jan 2009 18:58:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1666438</guid><dc:creator>grinder</dc:creator><description>&lt;p&gt;Very thanks for Instructions.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1666438" width="1" height="1"&gt;</description></item><item><title>re: Restartable AD DS and DSRM Logon Behaviors</title><link>http://msmvps.com/blogs/ad/archive/2008/10/21/restartable-ad-ds-and-dsrm-logon-behaviors.aspx#1651668</link><pubDate>Wed, 22 Oct 2008 20:49:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1651668</guid><dc:creator>BrianM</dc:creator><description>&lt;p&gt;That is what I get for posting way to early in the morning for me. &amp;nbsp;:)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1651668" width="1" height="1"&gt;</description></item><item><title>re: Restartable AD DS and DSRM Logon Behaviors</title><link>http://msmvps.com/blogs/ad/archive/2008/10/21/restartable-ad-ds-and-dsrm-logon-behaviors.aspx#1651663</link><pubDate>Wed, 22 Oct 2008 19:41:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1651663</guid><dc:creator>GrammarGuy</dc:creator><description>&lt;p&gt;Nice post - but please check your spelling and grammar before you post.&lt;/p&gt;
&lt;p&gt;Examples from your post above:&lt;/p&gt;
&lt;p&gt;...where removed. &amp;nbsp;(were)&lt;/p&gt;
&lt;p&gt;Although it hasn’t been as easy as hitting CTRL-Z to undo a mistakenly deleted object or to try to restore from the Recycle Bin. (Poor sentence structure).&lt;/p&gt;
&lt;p&gt;...now functions as service. (as a service)&lt;/p&gt;
&lt;p&gt;...in a norm state. (normal)&lt;/p&gt;
&lt;p&gt;Value 0 had to big of an impact (too)&lt;/p&gt;
&lt;p&gt;...a little to liberal for my likings (too)&lt;/p&gt;
&lt;p&gt;...when you want to all the DRSM (allow)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1651663" width="1" height="1"&gt;</description></item></channel></rss>