BRC - Bare Metal Restore fails at final boot (Active Directory Server)

Written By Tami Sutcliffe (Super Administrator)

Updated at September 18th, 2025

Problem: When performing a Bare Metal Restore of a system with Active Directory installed, the device might fail to boot and instead display a blue screen. 

Cause: This issue is due to a permission issue with Active Directory. Specifically, the permissions are not set correctly for the C:\Windows\NTDS directory.

Solution: To resolve this issue, do the following:

  1. Click the F8 key when the machine is booting select the Advanced Boot Options option.
  2. Select Directory Services Restore Mode.
  3. Log in using the local Admin credentials.
  4. Add full permissions for the local SYSTEM account to the C:\Windows\NTDS directory.
  5. Reboot into normal mode.

The user should now be able to log in using Domain user credentials.