{"id":2110,"date":"2017-05-12T19:25:28","date_gmt":"2017-05-12T19:25:28","guid":{"rendered":"http:\/\/microsoftgeek.com\/?p=2110"},"modified":"2017-05-12T19:33:58","modified_gmt":"2017-05-12T19:33:58","slug":"how-to-reset-the-local-admin-password-of-a-hyper-v-vm","status":"publish","type":"post","link":"https:\/\/microsoftgeek.com\/?p=2110","title":{"rendered":"How to reset the local admin password of a Hyper-V VM"},"content":{"rendered":"<p>Do you ever get that sinking feeling, when you\u2019ve forgotten the root password to your test lab?\u00a0 Again?<\/p>\n<p>I hate it too!\u00a0 So I decided to figure out a way around it, using an work around.<\/p>\n<p>Reboot your VM with your Windows OS or Server install disc.\u00a0 Any version will work.<\/p>\n<p><img decoding=\"async\" id=\"i-15\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/1.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/1.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/1.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/1.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/1.png?w=768 768w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/1.png 821w\" alt=\"Image\" \/><\/p>\n<p>Hit Shift+F10 for a command prompt.<\/p>\n<p><img decoding=\"async\" id=\"i-17\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/2.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/2.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/2.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/2.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/2.png 671w\" alt=\"Image\" \/><\/p>\n<p>make a copy of utilman and replace the original binary with a copy of CMD.\u00a0 This will allow us to use an ages-old trick to launch a command prompt as the System account from the logon screen.<\/p>\n<p><img decoding=\"async\" id=\"i-20\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/3.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/3.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/3.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/3.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/3.png 677w\" alt=\"Image\" \/><\/p>\n<p>Once completed, restart the system.<\/p>\n<p><img decoding=\"async\" id=\"i-22\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png?w=768 768w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png?w=1024 1024w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/4.png 1040w\" alt=\"Image\" \/><\/p>\n<p>At this point, clicking the Accessibility Icon in the bottom-left hand corner, or hitting left-shift 5 times will call the UtilMan, which we earlier replaced with cmd. This means you now have access to a system authority level account without needing to logon! \u00a0You can have a lot of fun with this. \u00a0More on that later.<\/p>\n<p><img decoding=\"async\" id=\"i-29\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png?w=768 768w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png?w=1024 1024w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/5.png 1041w\" alt=\"Image\" \/><\/p>\n<p>We are now just a few short steps away from a localadmin account.<\/p>\n<p>The quickest way to do this is to create an account:<\/p>\n<blockquote><p>net user \/add localadmin Dr0wssap!<\/p><\/blockquote>\n<p>Now give the account privilege.<\/p>\n<blockquote><p>net localgroup administrators localadmin \/add<\/p><\/blockquote>\n<p><img decoding=\"async\" id=\"i-31\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/6.png?w=646\" sizes=\"(max-width: 646px) 100vw, 646px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/6.png?w=646 646w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/6.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/6.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/6.png 656w\" alt=\"Image\" \/><\/p>\n<p>Now simply logon with these credentials.<\/p>\n<p><img decoding=\"async\" id=\"i-33\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/7.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/7.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/7.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/7.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/7.png 674w\" alt=\"Image\" \/><\/p>\n<p>To save on keystrokes, you can use .\\ notation to log on to the local system.<\/p>\n<p><img decoding=\"async\" id=\"i-36\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png?w=768 768w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png?w=1024 1024w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/8.png 1161w\" alt=\"Image\" \/><\/p>\n<p>And you\u2019re in!<\/p>\n<p>From here, you can use other means to reset your domain accounts to gain access to your lab again.<\/p>\n<p>As I mentioned earlier, the ability to launch a privileged command prompt at the logon screen allows for some curious behavior. \u00a0For instance, if you call Explorer, very interesting things happen. \u00a0Not as much fun on Windows Server 2012 or Windows 8. \u00a0On Server 2008 or Windows 7, you can have the Start Bar and desktop display over top of the logon screen!<\/p>\n<p>Here is an example of a similar situation, launching Explorer while a Task Sequence is running.<\/p>\n<p><img decoding=\"async\" id=\"i-27\" class=\"size-full wp-image\" src=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/example-start-screen-over-logo-task.png?w=650\" sizes=\"(max-width: 650px) 100vw, 650px\" srcset=\"https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/example-start-screen-over-logo-task.png?w=650 650w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/example-start-screen-over-logo-task.png?w=150 150w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/example-start-screen-over-logo-task.png?w=300 300w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/example-start-screen-over-logo-task.png?w=768 768w, https:\/\/foxdeploy.files.wordpress.com\/2013\/08\/example-start-screen-over-logo-task.png 1024w\" alt=\"Image\" \/><\/p>\n<p>This is also a potent security risk. \u00a0It is a reminder of why we always maintain physical control of our servers and encrypt our VM Virtual Hard Drives. \u00a0With the new ease of cloning Domain Controllers as VMs, someone might potentially attempt this on a domain controller. \u00a0If they are able to log on as the Local System or local Admin account to a DC, there is opportunity for mischief.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Do you ever get that sinking feeling, when you\u2019ve forgotten the root password to your test lab?\u00a0 Again? I hate it too!\u00a0 So I decided to figure out a way around it, using an work around. Reboot your VM with your Windows OS or Server install disc.\u00a0 Any version will work. Hit Shift+F10 for a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51,53],"tags":[],"class_list":["post-2110","post","type-post","status-publish","format-standard","hentry","category-server-virtualization-hyper-v-2","category-virtualization-virtual"],"_links":{"self":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2110"}],"version-history":[{"count":12,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2110\/revisions"}],"predecessor-version":[{"id":2122,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2110\/revisions\/2122"}],"wp:attachment":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}