robert waldinger - how to recover active directory if disaster should occur
DESCRIPTION
TRANSCRIPT
Robert WaldingerHow to recover Active Directory if disaster should occur
Bio – Robert Waldinger• System Consultant• Work for Dell Software• Live in Munich• Blog: http://de.community.dell.com/techcenter/b/windows_management/
Disaster• „it can never happen to me“• „oh really?“
Disasters – What do you think of?
Companies think about this…
Disaster from IT’s Point of View
Disaster from Admin Point of View
How do companies prepare for a Disaster?• Disasters are unpredictable – recovery shouldn’t be
• Recovery should be:– Planned, predictable and controlled– Documented for the people that will use it
• Adjustable for unavailable team members– Tested, practiced and updated periodically
• Automate where possible• Without practice, chance of success < 10%• Without planning, chance of success = 0%
AD-Recovery Use Cases• Recover object• Recover attribute• Recover GPO• Recover Sysvol• Forest Recovery
Recover Object
Tombstone Reanimation• isDeleted attribute• „CN=Deleted Objects“ (naming context)• 180 days – Default since Win 2003 SP1
Live Tombstoned Physically deleted
delete
Reanimate tombstone/authoritative restore
Garbage-collection
Recycle Bin• Prerequesites
– All DC‘s must run Windows Server 2008 R2 or higher– Forest Level Windows Server 2008 R2
• Enable Recycle Bin– Enable-ADOptionalFeature –Identity ‘CN=Recycle Bin
Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=test,DC=lab’ –Scope ForestOrConfigurationSet –Target ‘test.lab’
Live Deleted Physically deleted
delete
Undelete/ authoritative restore
Garbage-collection
RecycledRecycle
Deleted object lifetime
- msDS-deletedObjectLifetime
Tombstone lifetime (recycled object lifetime)
- tombstoneLifetime
Both in CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=test,DC=lab
Demo Recover Objects with Windows Server 2012 Admin Centerand configure AD Recycle Bin
Recover attribute
Reasons for attribute recovery• Data import failed• Error in IDM systems
Problems• Object was not deleted
recycle bin would not help• Other changed attributes should not be
overwritten• Also schema extensions should be covered
DemoRecover single attributeswith Recovery Manager for AD
Recover GPO
Problems• 3rd party solution needed• Sysvol, AD and registry needs to be covered
SolutionsAD Backup/Recovery tool
GPO-Management tool• Additional benefits: – Versioning– Change history– workflows
DemoRecover GPO changes
Recover Sysvol
• Authoritive restore• Restore files/scripts• Restore system State offline
Microsoft Guideline
• http://technet.microsoft.com/en-us/library/planning-active-directory-forest-recovery(v=ws.10).aspx
Identify the problem
Decide how to recover the forest
Perform initial recovery
Redeploy remaining DC‘s
Cleanup
Tools to be familiar with
• Adsiedit.msc• Ntdsutil.exe• Repadmin.exe• Netdom.exe• Nltest.exe
Proof your concept• Make sure your concept reflects the Microsoft guide• Make sure you have a working backup and all
needed information ready• Do a forest recovery test at least once a year
(Fire drill)
Demo
Forest-Recovery with Recovery-Manager-for-AD Forest Edition
AD Forest Disaster Recovery – What you don‘t know will hurt you
• Whitepaper: https://software.dell.com/whitepaper/active-directory-forest-disaster-recovery-what-you-dont-know-will-hurt-you822479
Please evaluate the session before you leave
.. and don’t forget to visit my
blog: http://de.community.dell.com/
techcenter/b/windows_management