Event ID - 16405

Event Id16405
SourceSAM
DescriptionDuring the installation of the Directory Service, this servers machine account was deleted hence preventing this Domain Controller from starting up.
Event InformationAccording to Microsoft:
Cause:

There are two known scenarios for this problem:
1. The account is deleted during the installation of a domain controller.
2. The domain controller is in a ""steady state"" for some time, and then its machine account is deleted.
In both situations, you can use Dcdiag.exe to resolve the problem. In the second situation, you can use an authoritative restore operation if a backup is available.
Recovery Case 1:
Steady State Scenario and Active Directory Backup of the Domain Exists Having a recent backup of Active Directory for the domain is the best-case scenario for recovery.
Use the following steps for recovery:
1. Perform an authoritative restore operation of the domain controllers machine account on a domain controller (for example, domain controller A) other than the broken domain controller (for example, domain controller B). Domain controller A should be a replication partner of domain controller B. You can check this in the Sites and Services snap-in. If domain controller B has a connection object from domain controller A, domain controller B replicates from domain controller A.
2. On domain controller B, turn off Key Distribution Center by typing the following command: net stop kdc
3. On domain controller B, use the Sites and Services snap-in to perform a Replicate Now operation on the connection object for domain controller A; that is, force a replication cycle from domain controller A to domain controller B. Domain controller B replicates in its machine account, and starts to perform normally again.

Recovery Case 2:
No Backup or the Account Was Deleted During Dcpromo
1. Run Dcdiag.exe with the following command-line option:dcdiag /s:localhost /repairmachineaccount
NOTE: When you use this command-line option, Dcdiag must be run locally on the computer you want to fix.
The logged on user running the command should either be a domain admin
Reference LinksHow to Recover from a Deleted Domain Controller Machine Account in Windows 2000

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.