Windows Server 2008R2 AD Backup and Disaster Recovery Procedures
Total Page:16
File Type:pdf, Size:1020Kb
Windows Server 2008R2 AD Backup and Disaster Recovery Procedures Peter Van Keymeulen, 2012 EDE Consulting ICT Infrastructure Architect Version: 3.3 Windows Server 2008R2 AD Backup and Disaster Recovery Procedures 1. Contents 1. CONTENTS ........................................................................................................................................... 2 2. CONTACT INFORMATION ....................................................................................................................... 4 3. VERSION CONTROL .............................................................................................................................. 5 4. TERMS AND ABBREVIATIONS ................................................................................................................. 5 5. INTRODUCTION ..................................................................................................................................... 6 6. SCOPE ................................................................................................................................................. 6 7. ACTIVE DIRECTORY CONTENT BACKUP AND RESTORE METHODS ............................................................. 6 7.1 System State Backup.................................................................................................................... 7 7.2 Active Directory Recycle Bin ......................................................................................................... 8 7.3 Active Directory Snapshot Backups .............................................................................................. 9 7.4 Tombstone Reanimation ............................................................................................................. 10 8. INSTALLING AND CONFIGURING BACKUPS ............................................................................................ 10 8.1 System State Backup.................................................................................................................. 10 8.2 Snapshot Backups ...................................................................................................................... 11 8.2.1 Manual Snapshots ................................................................................................................. 11 8.2.2 Scheduled Snapshots ............................................................................................................ 11 8.3 Enable Active Directory Recycle Bin .......................................................................................... 12 8.4 Configuring Garbage collection process ..................................................................................... 12 8.4.1 Without Recycle Bin ............................................................................................................... 13 8.4.2 With Recycle Bin .................................................................................................................... 13 9. WHEN TO RESTORE............................................................................................................................ 14 10. WHERE TO RESTORE .......................................................................................................................... 15 11. COMMON TASKS ................................................................................................................................ 15 11.1 Remove Domain Controller from DNS ........................................................................................ 15 11.2 Remove Domain Controller from Active Directory ...................................................................... 15 11.3 Change the Active Directory Restore Mode (DSRM) Administrator Password .......................... 17 11.4 Verification of a Successful Restore ........................................................................................... 17 11.5 How to Disable Initial Replication ............................................................................................... 18 12. ACTIVE DIRECTORY CONTENT RECOVERY ........................................................................................... 18 12.1 Overview ..................................................................................................................................... 18 12.1.1 Authoritative Restore ............................................................................................................. 18 12.1.2 Non-Authoritative Restore ..................................................................................................... 19 12.2 Recovery through System State Backup .................................................................................... 19 12.2.1 Restore your Backups files to restore from ........................................................................... 19 12.2.2 Non-Authoritative Restore ..................................................................................................... 20 12.2.3 Authoritative Restore ............................................................................................................. 21 12.3 Recovery through tombstone object reanimation ....................................................................... 22 12.3.1 Authoritative Restore through LDP.exe ................................................................................. 23 12.3.2 Authoritative Restore through ADRestore.exe ...................................................................... 24 12.4 Active Directory Recovery through Snapshots ........................................................................... 24 12.5 Active Directory Restore through Recycle Bin ............................................................................ 26 12.6 Restoring Back-Links .................................................................................................................. 28 12.6.1 Restore group memberships through NTDSUTIL and LDIFF ............................................... 28 12.6.2 Restore security principals two times .................................................................................... 29 13. ENTIRE DOMAIN RECOVERY ................................................................................................................ 29 14. ENTIRE FOREST RECOVERY................................................................................................................ 30 15. FSMO ROLES RECOVERY .................................................................................................................. 32 15.1 Overview ..................................................................................................................................... 32 15.2 How to find the existing FSMO role holders ............................................................................... 34 15.3 How to Seize a Role ................................................................................................................... 34 15.4 How to Move a Role .................................................................................................................... 35 16. SYSVOL RECOVERY ......................................................................................................................... 35 16.1 Overview ..................................................................................................................................... 35 2/42 Windows Server 2008R2 AD Backup and Disaster Recovery Procedures 16.2 Authoritative SYSVOL Restore ................................................................................................... 36 17. ACTIVE DIRECTORY DATABASE OPERATIONS ....................................................................................... 36 17.1 Repairing a corrupted Database ................................................................................................. 36 18. RECOVERING INDIVIDUAL GROUP POLICY OBJECTS ............................................................................. 37 18.1 Rollback GPO update ................................................................................................................. 38 18.2 Restore one or more GPOs ........................................................................................................ 38 19. FAST DISASTER RECOVERY FROM DELAYED REPLICATED SITE ............................................................ 38 19.1 Introduction ................................................................................................................................. 38 19.2 Recover a domain on another site .............................................................................................. 38 20. ACTIVE DIRECTORY SITE DISASTER RECOVERY PROCEDURES ............................................................. 39 20.1 Introduction ................................................................................................................................. 39 20.2 RTO and RPO Times .................................................................................................................. 39 20.3 When to go into DRP mode ........................................................................................................ 40 20.4 Putting ADS into Disaster Recovery Mode ................................................................................. 40 20.5 Common tasks when going into DR mode ................................................................................