Active Directory Disaster Recovery Paul Simmons Support Engineer Directory Services Microsoft Corporation.

Slides:



Advertisements
Similar presentations
Copyright line. Maintaining an Active Directory Environment Exam Objectives Backup and Recovery Backup and Recovery Offline Maintenance Offline Maintenance.
Advertisements

Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Presented by Peter Gubarevich Optimal Solutions, Ltd Conference Microsoft IT Pro Tallinn, December 01, 2011 Something About Restoring Your Server.
Module 13: Maintaining the Active Directory Database
VMware Data Recovery Presented by Kroll Ontrack at WI Area VMware User’s Group Presented by Kroll Ontrack at WI Area VMware User’s Group.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 13: Server Management and Monitoring.
8.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Chapter 12 - Backup and Disaster Recovery1 Ch. 12 – Backups and Disaster Recovery MIS 431 – Created Spring 2006.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
A+ Guide to Software, 4e Chapter 4 Supporting Windows 2000/XP Users and Their Data.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 12: Managing and Implementing Backups and Disaster Recovery.
A+ Guide to Software, 4e Chapter 5 Troubleshooting Windows 2000/XP Startup.
Ntdsutil.exe and the Microsoft Active Directory Curtis Clay III Charleta McKoy Windows 2000 Directory Services Team Microsoft Corporation.
Module 8 Implementing Backup and Recovery. Module Overview Planning Backup and Recovery Backing Up Exchange Server 2010 Restoring Exchange Server 2010.
Module 12: Planning for and Recovering from Disasters.
1. Preventing Disasters Chapter 11 covers the processes to take to prevent a disaster. The most prudent actions include Implement redundant hardware Implement.
1 Module 2 Installing Windows NT. 2  Overview Preparing for Installation Installing Windows NT Performing a Server-based Installation Troubleshooting.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 14: Problem Recovery.
1 Objectives Discuss the Windows Printer Model and how it is implemented in Windows Server 2008 Install the Print Services components of Windows Server.
1 Chapter Overview Backing Up Your Network Backing Up and Restoring Active Directory.
Module 8: Designing Active Directory Disaster Recovery in Windows Server 2008.
Microsoft ® Official Course Module 12 Monitoring, Managing, and Recovering AD DS.
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Chapter-4 Windows 2000 Professional Win2K Professional provides a very usable interface and was designed for use in the desktop PC. Microsoft server system.
13.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 13: Implementing Data and.
Administering Windows 7 Lesson 11. Objectives Troubleshoot Windows 7 Use remote access technologies Troubleshoot installation and startup issues Understand.
Microsoft ® Official Course Module 13 Troubleshooting and Recovering Windows 8.
Module 13: Configuring Availability of Network Resources and Content.
Chapter Fourteen Windows XP Professional Fault Tolerance.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
Chapter 18: Windows Server 2008 R2 and Active Directory Backup and Maintenance BAI617.
Module 12: Managing Disaster Recovery. Overview Preparing for Disaster Recovery Backing Up Data Scheduling Backup Jobs Restoring Data Configuring Shadow.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
1 Microsoft Exchange 2000 Server Maintenance and Troubleshooting System Maintenance and Monitoring Database Operation and Maintenance Backup, Restore,
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
Maintaining Active Directory Domain Services
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter 11 Backup and Recovery of Exchange Server 2003.
Module 9 Planning a Disaster Recovery Solution. Module Overview Planning for Disaster Mitigation Planning Exchange Server Backup Planning Exchange Server.
Catastrophic Hardware Failure & Recovery with Exchange Server 2003 Eileen Brown IT Evangelist Microsoft UK
Active Directory Maintenance, Troubleshooting, and Disaster Recovery Lesson 11.
Guide to MCSE , Enhanced 1 Activity 12-1: Backing Up Files and Folders Using the Backup Utility Objective: To explore the use of Windows Server 2003.
Module 13 Implementing Business Continuity. Module Overview Protecting and Recovering Content Working with Backup and Restore for Disaster Recovery Implementing.
Chapter 12: SYSVOL: Old & New BAI617. Chapter Topics What is SysVol? Understanding File Replication System (FRS) Understanding 2008 R2 Distributed.
11 DISASTER RECOVERY Chapter 13. Chapter 13: DISASTER RECOVERY2 OVERVIEW  Back up server data using the Backup utility and the Ntbackup command  Restore.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 13 Understanding and Installing Windows 2000 and Windows NT.
Systems Management Server 2.0: Backup and Recovery Overview SMS Recovery Web Site location: Updated.
1 Week #10Business Continuity Backing Up Data Configuring Shadow Copies Providing Server and Service Availability.
Operations Master / FSMO Roles in Active Directory : Suhail Ashfaq Butt.
Module 15 Managing Windows Server® 2008 Backup and Restore.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
High Availability in DB2 Nishant Sinha
IT1001 – Personal Computer Hardware & system Operations Week7- Introduction to backup & restore tools Introduction to user account with access rights.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
Unit 10 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/24/2016 Instructor: Williams Obinkyereh.
1 Microsoft Windows Server 2003 Active Directory Infrastructure Backing Up and Restoring Active Directory Goals  Use the.
Create setup scripts simply and easily.
Maintaining Windows Server 2008 File Services
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Unit 10 NT1330 Client-Server Networking II Date: 8/16/2016
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Global Catalog and Flexible Single Master Operations (FSMO) Roles
CIS MS Windows Operating System
Presentation transcript:

Active Directory Disaster Recovery Paul Simmons Support Engineer Directory Services Microsoft Corporation

Definition  Resolving problems on Microsoft ® Windows ® domain controllers that affect client, domain, or forest operation– In the least amount of time In the least amount of time With the least amount of pain With the least amount of pain With the best possible results With the best possible results

Preventive Maintenance  Use good hardware and test it regularly  Test deployments in a lab before deployment  Practice recovery scenarios in a lab  Remove single points of failure  Never have only one domain controller in a domain  Back up before and after every major state change

Recovery Options  Rebuild Winnt32, Dcpromo, and Re-replicate Winnt32, Dcpromo, and Re-replicate Known recovery time and results Known recovery time and results  Restore Windows Backup (Ntbackup.exe) to restore to a known good state Windows Backup (Ntbackup.exe) to restore to a known good state Re-replicate Re-replicate  Repair Esentutl repair of database is a last resort Esentutl repair of database is a last resort Use integrity check to see if database is damaged Use integrity check to see if database is damaged

Recovery Tools  Ntbackup – System State  Ntdsutil – Metadata Cleanup  Esentutl – Database Validation and Repair  Winnt32 – Rebuild  Dcpromo – Re-promote  Component level recovery FAZAM FAZAM Dfsutil.exe Dfsutil.exe

Ntbackup  Features: Backs up Active Directory ® in online mode Backs up Active Directory ® in online mode Scheduled backups Scheduled backups  What to back up System state: Active Directory, boot files, registry, and more System state: Active Directory, boot files, registry, and more  Resources: Q240363: “How to Back Up and Restore the System State” Q240363: “How to Back Up and Restore the System State” Q233427: “Files and Folders Not Backed Up Using the Ntbackup.exe Tool” Q233427: “Files and Folders Not Backed Up Using the Ntbackup.exe Tool”

Backup Limitations  Backup life = tombstonelifetime value Default = 60 days old Default = 60 days old Password change interval = 30 days Password change interval = 30 days Password history = 2 (current and previous) Password history = 2 (current and previous) Backup useful life = 60 days or two default password changes Backup useful life = 60 days or two default password changes Old backups can reintroduce tombstoned objects Old backups can reintroduce tombstoned objects  Schema rollback is not supported

Ntdsutil  Metadata cleanup Remove orphaned domain controllers or domains Remove orphaned domain controllers or domains  Integrity check and repair Wrapper around Esentutl Wrapper around Esentutl Tells you if database is damaged Tells you if database is damaged  Authoritative restore Mark selected objects on domain controller as authoritative Mark selected objects on domain controller as authoritative

Nonauthoritative Restore  What is it? Restore to known good point using Ntbackup Restore to known good point using Ntbackup Reboot into Active Directory mode to sync changes Reboot into Active Directory mode to sync changes  When to use Recover from hardware failure Recover from hardware failure Return to known good state on single domain controller Return to known good state on single domain controller  Options Rebuild server from scratch. Re-run Dcpromo. Rebuild server from scratch. Re-run Dcpromo. Restore machine to a known good point and sync deltas. Restore machine to a known good point and sync deltas.

Authoritative Restore  What is it? Restore to known good point using Ntbackup Restore to known good point using Ntbackup Make objects on reference domain controller as “master copy” for Active Directory Make objects on reference domain controller as “master copy” for Active Directory  When to use Accidental deletion or modification of objects or containers in the Active Directory Accidental deletion or modification of objects or containers in the Active Directory Corruption of objects/attributes in the directory Corruption of objects/attributes in the directory  Options Find a good domain controller that has the objects and make it authoritative Find a good domain controller that has the objects and make it authoritative Restore from a backup that contains the objects and make it authoritative Restore from a backup that contains the objects and make it authoritative

Authoritative Restore  Boot into offline restore mode Press F8 during boot phase Press F8 during boot phase Log on with offline administrator account Log on with offline administrator account  Mark objects in Ntdsutil as authoritative Find machine with objects or restore them Find machine with objects or restore them Restore subtree or entire database (rare) Restore subtree or entire database (rare)  Best practice Use most specific distinguished name path needed for recovery Use most specific distinguished name path needed for recovery Restore Active Directory over Terminal Services–Q Restore Active Directory over Terminal Services–Q256588

Winnt32 and Dcpromo  What is it? Reinstall of OS Reinstall of OS Run Dcpromo Run Dcpromo  When to use Known recovery time and end result Known recovery time and end result No applications or services to protect No applications or services to protect  Options Maintain standby server that can be shipped to remote site Maintain standby server that can be shipped to remote site

Scenarios  Hardware failure  Deleted objects in Active Directory  Flexible Single Master Operation (FSMO) recovery  Demo of authoritative restore

Hardware Failure  Scenario: Domain controller experiences catastrophic hardware failure Domain controller experiences catastrophic hardware failure  Goal: Replace bad hardware or entire server and resume operations Replace bad hardware or entire server and resume operations  Given: Valid backup Valid backup Identical hardware Identical hardware

Hardware Failure (2)  Process Replace server or hardware Replace server or hardware Restore from tape backup Restore from tape backup Re-replicate Re-replicate  Alternatives Winnt32 and Dcpromo Winnt32 and Dcpromo

Hardware Failure (3)  Restore to dissimilar hardware Q263532: “Disaster Recovery of Active Directory on Dissimilar Hardware” Q263532: “Disaster Recovery of Active Directory on Dissimilar Hardware”  Requirements Same number of drives and drive letters Same number of drives and drive letters Complete backup of system state and system drive Complete backup of system state and system drive Same NICS, video cards, HAL, kernel, and number of processors Same NICS, video cards, HAL, kernel, and number of processors Remove teaming network cards on target Remove teaming network cards on target Same disk drive controller and configuration Same disk drive controller and configuration

Deleted Objects in Active Directory  Scenario Critical objects have been deleted from Active Directory Critical objects have been deleted from Active Directory  Goal To recover the objects without re-creating them To recover the objects without re-creating them  Given A valid backup A valid backup

Deleted Objects in Active Directory (2)  Resolution; restore from tape and authoritative restore in Ntdsutil: Restore recent backup containing deleted objects Restore recent backup containing deleted objects Mark deleted objects as authoritative using Ntdsutil Mark deleted objects as authoritative using Ntdsutil Authoritative restore in Ntdsutil Authoritative restore in Ntdsutil  Alternative: Find replica domain controller that hasn’t received the deletions Find replica domain controller that hasn’t received the deletions Mark deleted distinguished name as authoritative (no restore required) Mark deleted distinguished name as authoritative (no restore required)

Deleted Objects in Active Directory (3)  Protection Set replication schedule once every four days on “backup domain controller” Set replication schedule once every four days on “backup domain controller” Mark objects as authoritative when deletion detected Mark objects as authoritative when deletion detected

FSMO Recovery  Flexible Single Master Operations (FSMO)  Q223787: “Flexible Single Master Operation Transfer and Seizure Process”  Transfer roles Preferred Preferred Graceful Graceful  Seizure of roles Last resort Last resort That server cannot come back online…EVER. That server cannot come back online…EVER.

Ntdsutil FSMO Transfer UI

Demo: User Objects Created

Demo: Repadmin /Showmeta

Demo: System State Backup

Demo: Deleted Objects

Demo: Restore System State

Demo: Advanced Options

Demo: Authoritative Restore

Demo: Authoritative Restore (2)

Demo: Repadmin /Showmeta with Incremented Version Numbers

Additional References:  Server recovery: ministration/fileandprint/recovery.asp ministration/fileandprint/recovery.asp ministration/fileandprint/recovery.asp  Q241594: “HOW TO: Perform an Authoritative Restore to a Domain Controller in Windows 2000”  Microsoft Windows 2000 Server Distributed Systems Guide, Chapters 9 and 10