This recipe shows how to manage the password to sign in to domain controllers when the Active Directory Domain Services service is not running.
Managing the DSRM passwords on domain controllers
Getting ready
To make a backup of a domain controller, sign into a domain controller with a user account that is a member of the Domain Admins group, the Backup Operators group, or the Server Operators group.
For the scenario where the DSRM Administrator password is automatically synchronized with an account in Active Directory, create a disabled user account with a strong password. Document the password in a password vault. Additionally, make sure all domain controllers run Windows Server 2008, or newer versions of Windows Server.
...