robert waldinger - how to recover active directory if disaster should occur

31
Robert Waldinger How to recover Active Directory if disaster should occur

Upload: nordic-infrastructure-conference

Post on 11-Nov-2014

2.831 views

Category:

Technology


1 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Robert Waldinger - How to recover active directory if disaster should occur

Robert WaldingerHow to recover Active Directory if disaster should occur

Page 2: Robert Waldinger - How to recover active directory if disaster should occur

Bio – Robert Waldinger• System Consultant• Work for Dell Software• Live in Munich• Blog: http://de.community.dell.com/techcenter/b/windows_management/

Page 3: Robert Waldinger - How to recover active directory if disaster should occur

Disaster• „it can never happen to me“• „oh really?“

Page 5: Robert Waldinger - How to recover active directory if disaster should occur

Companies think about this…

Page 8: Robert Waldinger - How to recover active directory if disaster should occur

How do companies prepare for a Disaster?• Disasters are unpredictable – recovery shouldn’t be

• Recovery should be:– Planned, predictable and controlled– Documented for the people that will use it

• Adjustable for unavailable team members– Tested, practiced and updated periodically

• Automate where possible• Without practice, chance of success < 10%• Without planning, chance of success = 0%

Page 9: Robert Waldinger - How to recover active directory if disaster should occur

AD-Recovery Use Cases• Recover object• Recover attribute• Recover GPO• Recover Sysvol• Forest Recovery

Page 10: Robert Waldinger - How to recover active directory if disaster should occur

Recover Object

Page 11: Robert Waldinger - How to recover active directory if disaster should occur

Tombstone Reanimation• isDeleted attribute• „CN=Deleted Objects“ (naming context)• 180 days – Default since Win 2003 SP1

Live Tombstoned Physically deleted

delete

Reanimate tombstone/authoritative restore

Garbage-collection

Page 12: Robert Waldinger - How to recover active directory if disaster should occur

Recycle Bin• Prerequesites

– All DC‘s must run Windows Server 2008 R2 or higher– Forest Level Windows Server 2008 R2

• Enable Recycle Bin– Enable-ADOptionalFeature –Identity ‘CN=Recycle Bin

Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=test,DC=lab’ –Scope ForestOrConfigurationSet –Target ‘test.lab’

Live Deleted Physically deleted

delete

Undelete/ authoritative restore

Garbage-collection

RecycledRecycle

Page 13: Robert Waldinger - How to recover active directory if disaster should occur

Deleted object lifetime

- msDS-deletedObjectLifetime

Tombstone lifetime (recycled object lifetime)

- tombstoneLifetime

Both in CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=test,DC=lab

Page 14: Robert Waldinger - How to recover active directory if disaster should occur

Demo Recover Objects with Windows Server 2012 Admin Centerand configure AD Recycle Bin

Page 15: Robert Waldinger - How to recover active directory if disaster should occur

Recover attribute

Page 16: Robert Waldinger - How to recover active directory if disaster should occur

Reasons for attribute recovery• Data import failed• Error in IDM systems

Page 17: Robert Waldinger - How to recover active directory if disaster should occur

Problems• Object was not deleted

recycle bin would not help• Other changed attributes should not be

overwritten• Also schema extensions should be covered

Page 18: Robert Waldinger - How to recover active directory if disaster should occur

DemoRecover single attributeswith Recovery Manager for AD

Page 19: Robert Waldinger - How to recover active directory if disaster should occur

Recover GPO

Page 20: Robert Waldinger - How to recover active directory if disaster should occur

Problems• 3rd party solution needed• Sysvol, AD and registry needs to be covered

Page 21: Robert Waldinger - How to recover active directory if disaster should occur

SolutionsAD Backup/Recovery tool

GPO-Management tool• Additional benefits: – Versioning– Change history– workflows

Page 22: Robert Waldinger - How to recover active directory if disaster should occur

DemoRecover GPO changes

Page 23: Robert Waldinger - How to recover active directory if disaster should occur

Recover Sysvol

Page 24: Robert Waldinger - How to recover active directory if disaster should occur

• Authoritive restore• Restore files/scripts• Restore system State offline

Page 27: Robert Waldinger - How to recover active directory if disaster should occur

Tools to be familiar with

• Adsiedit.msc• Ntdsutil.exe• Repadmin.exe• Netdom.exe• Nltest.exe

Page 28: Robert Waldinger - How to recover active directory if disaster should occur

Proof your concept• Make sure your concept reflects the Microsoft guide• Make sure you have a working backup and all

needed information ready• Do a forest recovery test at least once a year

(Fire drill)

Page 29: Robert Waldinger - How to recover active directory if disaster should occur

Demo

Forest-Recovery with Recovery-Manager-for-AD Forest Edition

Page 30: Robert Waldinger - How to recover active directory if disaster should occur

AD Forest Disaster Recovery – What you don‘t know will hurt you

• Whitepaper: https://software.dell.com/whitepaper/active-directory-forest-disaster-recovery-what-you-dont-know-will-hurt-you822479

Page 31: Robert Waldinger - How to recover active directory if disaster should occur

Please evaluate the session before you leave

.. and don’t forget to visit my

blog: http://de.community.dell.com/

techcenter/b/windows_management