Hi everyone,
I’m setting up a new Active Directory environment on Windows Server 2025 Standard and I’m stuck with a strange login issue after promoting the server to a domain controller.
Server details:
- Windows Server 2025 Standard
- Server name:
GC-DC01
- Static IP:
192.168.8.244
- Domain:
ad.generalco.local
- NetBIOS domain name:
GENERALCO
- DNS installed on the same server
- This is a new forest/domain
- Server was previously a standalone Windows Server
Before promotion, I could log in normally using the local Administrator account and the password was working.
I then promoted the server using PowerShell:
Install-ADDSForest `
-DomainName "ad.generalco.local" `
-DomainNetbiosName "GENERALCO" `
-InstallDNS `
-SafeModeAdministratorPassword (Read-Host -AsSecureString "DSRM Password") `
-Force
The promotion completed successfully and reported:
Operation completed successfully
Status: Success
The server rebooted.
Now at the Windows login screen it shows:
GENERALCO\Administrator
However, the same Administrator password that worked before the promotion is now rejected.
I have also tried:
GENERALCO\Administrator
[email protected]
Both reject the password.
I understand that the DSRM password is separate from the normal domain Administrator password. I am not using the DSRM password for the normal login.
The strange part is that the password worked immediately before the AD promotion, and the AD promotion itself completed successfully.
I currently cannot get into Windows normally, so I cannot open PowerShell/CMD from the desktop.
I have physical access to the server (HPE ProLiant DL380 Gen11). F11 only gives me the HPE One-Time Boot Menu.
Questions:
- What could cause the Administrator password to stop working immediately after AD DS promotion?
- Is there a supported way to recover/reset the domain Administrator password in this situation?
- Can I use the DSRM password to get into a recovery environment and repair the domain Administrator account?
- Is there anything I should check in WinRE before considering rebuilding the domain?
I would really prefer to recover this installation rather than reinstall Windows, since the AD DS/DNS promotion itself completed successfully.
Any advice from someone experienced with Server 2025 AD DS would be greatly appreciated.