How does ntdsutil know it's in Directory Restore mode?
When you start the domain controller (DC) in Directory Restore mode, the DC
sets the environment variable safeboot_option to "dsrepair." If you
want to check something in ntdsutil that is allowed only in Directory Restore
mode, you can "trick" the program by typing the following statement at
a command prompt:
set SAFEBOOT_OPTION=DSREPAIR
Don't use this approach on a live or important machine because it
could result in system damage if you try to perform system modifications when
the system isn't in Directory Restore mode.
Security FAQ
Windows Privacy Tools - http//www.privacywindows.com
|