Active Directory Virtualization Safeguards and Domain Controller Cloning with Windows Server 2012 Manu Pushpendran Program Manager Microsoft Corporation SIA317
Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.
Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.
Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.
Logical Clock
Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: ARID Pool: USN: 100 ID: ARID Pool: USN: 250 ID: ARID Pool: more users created = 200 DC2 receives updates: USNs >200 = 250 USN: 200 ID: ARID Pool: users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1
Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.
Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: AsavedVMGID: G1 USN: 100 ID: A USN: ID: B +150 users created: VM generation ID difference detected: EMPLOY SAFETIES = 200 USN: 200 ID: A +100 users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1 VMGID: G1 savedVMGID: G1VMGID: G1 savedVMGID: G1VMGID: G2 savedVMGID: G2VMGID: G2 DC2 again accepts updates: USNs >100 USN re-use avoided and USN rollback PREVENTED : all 250 users converge correctly across both DCs … missing users replicate back to DC1 = 200 = 250
Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.
DC1 DC2 DC3 DC1 DC2 DC3 DC1 DC2 DC3 contoso.com
DC1 DC2 DC3 DC1 DC2 DC3 DC1 DC2 DC3 contoso.com
1. Identify suitable source virtual DC 2. Authorize source DC by adding it to ‘Cloneable Domain Controllers’ group Pre-provisioned with Control Access Right (CAR) on domain-NC object (domain head) 3. Run New-ADDCCloneConfigfile Verifies pre-requisites, e.g. PDC FSMO is running Windows Server 2012 (more later on this) Verifies authorization (by checking group membership) Let’s you specify name, IP address, DNS servers, site, etc. Provide an empty file to auto-generate values Sample file provided in box at %windir%\system32\SampleDCCloneConfig.xml Schema file provided in box at %windir%\system32\DCCloneConfigSchema.xsd 4. Run Get-ADDCCloningExcludedApplicationList [-generateXML] 5. Shutdown and export source DC 6. Restart source DC 7. Import clone of source DC as many times as desired and start clone VMs
DCCloneConfig.xml sample
demo Domain Controller Cloning
PDC Source Clone3 Hyper-V Clone2 Clone1
BOOT No Yes REBOOT INTO DSRM Yes No Yes No BOOT NORMALLY No Yes
Breakout Sessions SIA312 What's New in Active Directory in Windows Server 2012 SIA404 Deep Dive on Windows Server Active Directory PowerShell SIA319 The Evolution of Active Directory Recovery SIA402 How to (un)Destroy Your Active Directory: Reloaded SIA207 Windows Server 2012 Dynamic Access Control Overview SIA341 Windows Server 2012 Dynamic Access Control Deep Dive for Active Directory and Central Authorization Policies Hands-on Labs SIA11-HOL Windows Server 2012 Active Directory Deployment and Management Enhancements SIA21-HOL Using Dynamic Access Control to Automatically and Centrally Secure Data in Windows Server 2012 Find Me Later At Windows Server 2012 Active Directory and Dynamic Access Control booth
Talk to our Experts at the TLC #TE(sessioncode) DOWNLOAD Windows Server 2012 Release Candidate microsoft.com/windowsserver Hands-On Labs DOWNLOAD Windows Azure Windowsazure.com/ teched
Scan the Tag to evaluate this session now on myTechEd Mobile