Robert Waldinger - How to recover active directory if disaster should occur

Post on 11-Nov-2014

2826 Views

Category:

Technology

1 Downloads

Preview:

Click to see full reader

DESCRIPTION

 

Transcript

Robert WaldingerHow to recover Active Directory if disaster should occur

Bio – Robert Waldinger• System Consultant• Work for Dell Software• Live in Munich• Blog: http://de.community.dell.com/techcenter/b/windows_management/

Disaster• „it can never happen to me“• „oh really?“

Companies think about this…

How do companies prepare for a Disaster?• Disasters are unpredictable – recovery shouldn’t be

• Recovery should be:– Planned, predictable and controlled– Documented for the people that will use it

• Adjustable for unavailable team members– Tested, practiced and updated periodically

• Automate where possible• Without practice, chance of success < 10%• Without planning, chance of success = 0%

AD-Recovery Use Cases• Recover object• Recover attribute• Recover GPO• Recover Sysvol• Forest Recovery

Recover Object

Tombstone Reanimation• isDeleted attribute• „CN=Deleted Objects“ (naming context)• 180 days – Default since Win 2003 SP1

Live Tombstoned Physically deleted

delete

Reanimate tombstone/authoritative restore

Garbage-collection

Recycle Bin• Prerequesites

– All DC‘s must run Windows Server 2008 R2 or higher– Forest Level Windows Server 2008 R2

• Enable Recycle Bin– Enable-ADOptionalFeature –Identity ‘CN=Recycle Bin

Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=test,DC=lab’ –Scope ForestOrConfigurationSet –Target ‘test.lab’

Live Deleted Physically deleted

delete

Undelete/ authoritative restore

Garbage-collection

RecycledRecycle

Deleted object lifetime

- msDS-deletedObjectLifetime

Tombstone lifetime (recycled object lifetime)

- tombstoneLifetime

Both in CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=test,DC=lab

Demo Recover Objects with Windows Server 2012 Admin Centerand configure AD Recycle Bin

Recover attribute

Reasons for attribute recovery• Data import failed• Error in IDM systems

Problems• Object was not deleted

recycle bin would not help• Other changed attributes should not be

overwritten• Also schema extensions should be covered

DemoRecover single attributeswith Recovery Manager for AD

Recover GPO

Problems• 3rd party solution needed• Sysvol, AD and registry needs to be covered

SolutionsAD Backup/Recovery tool

GPO-Management tool• Additional benefits: – Versioning– Change history– workflows

DemoRecover GPO changes

Recover Sysvol

• Authoritive restore• Restore files/scripts• Restore system State offline

Tools to be familiar with

• Adsiedit.msc• Ntdsutil.exe• Repadmin.exe• Netdom.exe• Nltest.exe

Proof your concept• Make sure your concept reflects the Microsoft guide• Make sure you have a working backup and all

needed information ready• Do a forest recovery test at least once a year

(Fire drill)

Demo

Forest-Recovery with Recovery-Manager-for-AD Forest Edition

AD Forest Disaster Recovery – What you don‘t know will hurt you

• Whitepaper: https://software.dell.com/whitepaper/active-directory-forest-disaster-recovery-what-you-dont-know-will-hurt-you822479

Please evaluate the session before you leave

.. and don’t forget to visit my

blog: http://de.community.dell.com/

techcenter/b/windows_management

top related