System Admin Labs Sample 1 | Page By: MUHAMMAD IQBAL Types of Backup 1- System Backup Or Active Directory Backup 2- Additional Domain Controller (ADC) 3- Active Directory Recycle bin 1- Active Directory Backup & Recovery Requirements for Backup Active Directory must exist Need to install a feature “Windows backup feature” Requires approximately 30-40min to take backup of an AD Need dedicated Hard disk, or other media Why do we need AD / system backup? Let’s suppose, we have a lot of things in system AD like, 100 OU, and each OU as 1000 users plus each OU has 2000 policies. What happen if any disaster happens? To overcome this, off course we need a backup of either whole directory or partial backup from where we can restore in case of any disaster. Note: it is recommended that, you take backup on different HD or other system, not on the same drive. Advantages of AD backup Recover deleted objects Recover crashed system How to take AD backup There are two (2) ways to create a system backup GUI& CMD OR Either we use GUI or cmd,following window will open
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
System Admin Labs Sample
1 | P a g e B y : M U H A M M A D I Q B A L
Types of Backup
1- System Backup Or Active Directory Backup
2- Additional Domain Controller (ADC)
3- Active Directory Recycle bin
1- Active Directory Backup & Recovery
Requirements for Backup
Active Directory must exist
Need to install a feature “Windows backup feature”
Requires approximately 30-40min to take backup of an AD
Need dedicated Hard disk, or other media
Why do we need AD / system backup?
Let’s suppose, we have a lot of things in system AD like, 100 OU, and each OU as 1000 users plus each OU has
2000 policies. What happen if any disaster happens? To overcome this, off course we need a backup of either
whole directory or partial backup from where we can restore in case of any disaster.
Note: it is recommended that, you take backup on different HD or other system, not on the same drive.
Advantages of AD backup
Recover deleted objects
Recover crashed system
How to take AD backup
There are two (2) ways to create a system backup
GUI& CMD
OR
Either we use GUI or cmd,following window will open
System Admin Labs Sample
2 | P a g e B y : M U H A M M A D I Q B A L
This means, we need to install one feature before we start back up. This feature name is “windows
server backup”.
How to install that feature on GUI and CMD
Once you have installed this feature, you can see
Here there are types of Backup under “windows server backup” on most right top bar.
Types of Backup on GUI
We learn only how to create, but we will do this same process via CMD
System Admin Labs Sample
3 | P a g e B y : M U H A M M A D I Q B A L
Backup once option
Next window will be
Next will be to select right location where you want to save this backup
System Admin Labs Sample
4 | P a g e B y : M U H A M M A D I Q B A L
On next option you can select the right location
Once you press “Next” the error will generate
This means, the backup drive is also in same system, which is not recommended that is why this
message generates. Still you can back up on same drive.
When you press YES . Next window will be the last option before backup starts
System Admin Labs Sample
5 | P a g e B y : M U H A M M A D I Q B A L
After this backup will start
But as I mentioned earlier- we only wanted to discuss and learn how to take the back up on GUI.
That is very simple, so we try to learn backup on CMD.
Backup schedule option
Here we will set the time frame according to requirements
System Admin Labs Sample
6 | P a g e B y : M U H A M M A D I Q B A L
Because we don’t have dedicated hard drive so we will select 2nd option
System Admin Labs Sample
7 | P a g e B y : M U H A M M A D I Q B A L
When we add the destination
This way we will create different types of backup using GUI.
Create system state or AD backup using CMD
Similarly, to create backup on cmd, we have to install “windows backup feature” which is already
installed here.
System Admin Labs Sample
8 | P a g e B y : M U H A M M A D I Q B A L
On server command line we write this command
This command shows some more commands which can be use here.
For backup we need “start systemstatebackup” command
When we write this command, it will show you some errors or asking for target location; where you
want this back up.
Even it shows the exact syntax for this command(read the example – last line)
System Admin Labs Sample
9 | P a g e B y : M U H A M M A D I Q B A L
When we press “yes” – the backup will start. It takes approximately 30-40min.
Back up has been finished
While, the backup is happening
Real life Scenarios for Backup and Recovery
Scenario#1: - to see the solution go to page#20
let’s suppose while the backup is in progress, we add something in AD
Add one OU (mkt)
And some users in that OU
Now the scenario is that, we will check are these new things comes in this backup when we restore
Let suppose, our system has crashed and we have this backup and we created some OU and users
during the backup
Now we learn how to restore this backup using GUI or CMD
System Admin Labs Sample
10 | P a g e B y : M U H A M M A D I Q B A L
Restore the system from Backup
Very important:To restore the backup “we need to go Active Directory SAFE MODE”
During installation of Active Directory Domain Services (AD DS), you set the Administrator password
for logging on to the server in DSRM. When you start Windows Server 2008R2 in DSRM, you must
log on by using this DSRM password for the local Administrator account
Following slide shows you- if we recall our memoryduring the installation of active directory
This password is require before you go to “DSRM-Directory services Reset mode”
Let suppose, we have forgot that password- Is this password is recoverable or not ?
Yes it is recoverable– this password is inside “NTDS” folder, so we have to run “ntdsutil” on
command prompt.
Recover DSRM Password - On DC normal mode
Now we will recover the password for DSRM.
We can get some help by using “?”
System Admin Labs Sample
11 | P a g e B y : M U H A M M A D I Q B A L
Here we use this option or command to recover DSRM password
How to get help to use this option
Now we use proper command “ reset password on server %s” as we can see that , it says ! “Use NUL
for local machine”
Note: DSRM pw goes in “null” folder or database” while users password goes to “SAM” database.
Then we type null after the command
It prompts for new password
We have seen that password has been reset .
And next prompt is again on “reset DSRM admin password”, we have to come out from this prompt.
You can restart a domain controller in DSRM manually by pressing the F8 key during domain
controller startup
Here we can see, we can’t access Active directory.- we have to use that recovered password to