ACRONIS BACKUP AND RECOVERY 10 - ACTIVE DIRECTORY BACKUP AND RESTORE Скачать руководство пользователя страница 5

Copyright © Acronis, Inc., 2000-2009 

 

 

 

Make sure that the Active Directory database folder is included into the backup. The easiest way 
to do this is to create a full image backup of your system drive, and drives where AD database 
and transaction logs are located. 

 

Make sure that files making up the AD database (.dit, .chk, .log files) are not in the exclusion list. 

 

Make sure that the Create snapshots using VSS option is selected for the backup. 

 

4.

 

Active Directory recovery 

As mentioned above, the AD recovery would differ, depending on what type of recovery is required. 
Moreover, in some cases you even don’t need to touch your domain controller backup –  all the 
information required for the recovery is already available. 

In order to cover major AD recovery scenarios, let’s consider the following disaster scenarios: 

 

Domain controller is lost, other domain controllers are available. 

 

All domain controllers are lost (or there was only one). 

 

Active Directory database is corrupted and AD service doesn’t start. 

 

Certain information is accidentally deleted from the Active Directory. 

 

4.1.

 

Domain Controller restore (other DCs are available) 

When one of the domain controllers is lost, the AD service is still available. Therefore, other domain 
controllers will contain data which is more up-to-date than the data in the backup. For example, if a 
user account has been created in the AD after the backup was taken, the backup won’t contain this 
account. 

Thus, we want to perform a recovery which will not affect the current state of the Active Directory – 
this operation is called nonauthoritative restore. 

Active Directory records are constantly replicated between the domain controllers. At any given 
moment, the same record may contain a certain value on one domain controller, and a different 
value on another. To prevent conflicts and loss of information, AD uses incrementing versions (called 
Update Sequence Number –  USN) attached to every AD object. USNs are used to determine the 
direction of replication –  records with greatest USN are considered as most up-to-date, and 
replicated to other servers. 

During nonauthoritative restore, the AD is restored from the database with the original USN stored in 
the backup.  

Live domain controllers cannot have AD records with a USN that is smaller than the one contained in 
the backup – since a USN is always increasing in value. Thus, the AD records from the backup have 
little value during such restore –  more up-to-date records from other domain controllers will 
overwrite them during the replication. 

Moreover, it is not mandatory to restore AD in this recovery scenario at all. To restore the domain 
controller functionality, it is sufficient to re-create the domain controller itself (using the 
dcpromo.exe tool). Once replication completes, the domain controller will be up and running again. 

To summarize, the following steps should be completed in order to restore a domain controller when 
other DCs are available: 

Содержание BACKUP AND RECOVERY 10 - ACTIVE DIRECTORY BACKUP AND RESTORE

Страница 1: ...Active Directory backup and restore with Acronis Backup Recovery 10...

Страница 2: ...tive Directory backup 3 4 Active Directory recovery 5 4 1 Domain Controller restore other DCs are available 5 4 2 Domain Controller restore no other DCs are available 6 4 3 Active Directory database r...

Страница 3: ...ng of accidentally deleted or modified AD records Required operations and tools may vary depending on the type of information that needs to be restored and availability of other domain controllers 3 A...

Страница 4: ...in this document but as a bare minimum back up at least monthly To summarize the following needs to be done in order to perform complete Active Directory database backup Make sure that at least one o...

Страница 5: ...after the backup was taken the backup won t contain this account Thus we want to perform a recovery which will not affect the current state of the Active Directory this operation is called nonauthori...

Страница 6: ...although the information loss will be very significant in this case To summarize the following steps should be completed when restoring the last the only domain controller 1 Make sure the newest avai...

Страница 7: ...D database files 4 Restore the files from the backup use file level restore from an image level backup to accomplish that 5 Reboot the computer Make sure the Active Directory service has started succe...

Страница 8: ...there is no need to reboot a domain controller There are several tools that perform such recovery many of them are available for free For example a command line tool from Windows Sysinternals called...

Отзывы: