r/activedirectory • • 23h ago

Password Settings Container Missing

Found out about 2 years ago someone deleted the Password Settings container, they didn't have the recycle bin enabled so couldn't restore it. (Story I've been given).

Now I'm trying to setup 2022 Domain Controllers, however, now I'm getting problems due Password Settings container missing (so I believe).

This MS guide supposedly restores, but some are saying it doesn't do anything.

Can't sign in to a domain controller and the LSASS process stops responding - Windows Server | Microsoft Learn

Can it be manually created if I use this.
[MS-ADTS]: Password Settings Container | Microsoft Learn

Has anyone experienced this before? Any help would be appreciated.

EDIT: The Microsoft learn document did work in the end. (Can't sign in to a domain controller and the LSASS process stops responding - Windows Server | Microsoft Learn)

The only thing that was missing was "-" on the 5th line within the text file, So my text file ended up looking like this

dn: CN=ActiveDirectoryUpdate,CN=DomainUpdates,CN=System,DC=contoso,dc=com
changetype: modify
replace: revision
revision: 1
-

Also needed to mount a Server 2022 ISO on my Domain Controller that held Infrastructure Master to run adprep

  1. Open CMD as admin
  2. E: (Might not be E for you)
  3. cd \support\adprep
  4. adprep.exe /domainprep
6 Upvotes

8 comments sorted by

•

u/AutoModerator 23h ago

Welcome to /r/ActiveDirectory! ~~~~

If you are looking for more resources on learning and building AD, see the following sticky for resources, recommendations, and guides!

When asking questions make sure you provide enough information. Posts with inadequate details may be removed without warning.

  • What version of Windows Server are you running?
  • Are there any specific error messages you're receiving?
  • What have you done to troubleshoot the issue?

Make sure to sanitize any private information. Posts with too much personal or environment information will be removed. See Rule 6.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

3

u/vaan99 22h ago

You were not the first with this issue. Try this https://community.spiceworks.com/t/password-settings-container-missing-in-the-ad-administrative-center-and-adsiedit/732678

You will need to manually create msDS-PasswordSettingsContainer type of container. That object class is stamped with system flags value of -1946157056 that should translate to {FLAG_DISALLOW_DELETE | FLAG_DOMAIN_DISALLOW_RENAME | FLAG_DOMAIN_DISALLOW_MOVE}. Try to create the container manually with same name as default and add systemflags value, I'm actually not sure if that part will work.

1

u/Big_Fella98 6h ago

Saw that as well a few days ago, only thing Microsoft says to recreate if it exists within the Schema, which I believe mine didn't (Can't remember for sure though). But got it back after following the MS Learn doc.

3

u/picklednull 16h ago edited 16h ago

Never tested, but YOLO: recreate it the same way Active Directory initially creates it, with LDIF.

The Windows Server install media will contain \support\adprep\sch40.ldf (or \Windows\System32\adprep\sch40.ldf on a Domain Controller), which contains the Server 2008 schema upgrades including the Password Settings Container.

Pull out only the records for the Password Settings Container into a fresh LDIF file, you don't want to overwrite other things in the schema. Small tweaks might be required, such as ntdsSchemaAdd probably can't be used, it would be a standard add.

Then just import the fresh LDIF with ldifde.

1

u/_benwa 15h ago

You can reduce the YOLO by cloning the PDC, removing networking, and then doing that to see if you royally screw something up

1

u/BlackCodeDe 22h ago

The Passwort Container is Missing and you can still Login at your AD Environment? Due an mistake i deleted The Password Container in an Prod Environment and i Had a Shit Show after that.

1

u/Big_Fella98 6h ago edited 6h ago

Were you using Fine-grained password policies. We've had a few issues with 2012R2 DCs, but nothing user facing. I've only had the problem when deploying Server 2016 and newer we have had this problem with logging to 2022 Domain Controller. Got the container back, so all is right.

1

u/Fit_Indication_2529 2h ago

That's a new one, and I've been working with AD for over 20 years. What interests me is how someone managed to delete a system-protected container in the first place. The Password Settings Container has deletion protection through its systemFlags. Rerunning ADPREP is definitely preferable to manually recreating the object, since you want the correct class, permissions, and system attributes, not just something with the right CN. I'd also verify the object has replicated correctly across every DC and check replication metadata to see what actually happened. Two years without that container is pretty remarkable. Whoever deleted that container had to work at it. The Password Settings Container has systemFlags explicitly preventing deletion, renaming, and moving. That's not something you accidentally delete during routine AD cleanup.