I found an old server under a desk at work and needed to determine if there was any usable data on it before disposing of it. It was a standalone Windows 2003 r2 server which was a member of a workgroup and not our domain so I could not use a domain password. I asked around, and nobody knew the password and none of the old passwords given to me worked either.
I had a copy of Hiren’s boot cd which I booted the server from, and chose the password tools. In there is Active Password Changer which was able to find the SAM file, and get the user names from it. I was then able to set the Administrator user to have no password.
You do need physical access to the server to perform this, but I had reset the password to blank in about 3 minutes with the help of this free tool.