Summary

Completed

In this module, you learned about how to backup and restore Active Directory environment. You learned to:

  • Design backup coverage from RTO, RPO, topology, and trust boundaries.
  • Validate last-known-safe backups through health, replication, incident, compatibility, catalog, key, and restore-test evidence.
  • Select object, controller, domain, or forest recovery by incident scope.
  • Separate AD DS database authority from SYSVOL authority.
  • Recover the first writable controller in each forest-recovery domain with authoritative SYSVOL.
  • Recover operations master roles, RID state, trusts, DNS, and global catalog capacity at the correct domain or forest scope.
  • Reset the writable krbtgt account twice in each recovered domain, waiting longer than that domain's effective maximum Kerberos ticket lifetime and proving replication convergence before the second reset; handle RODC krbtgt_<number> accounts separately.
  • Evaluate VM-Generation ID safeguards without treating snapshots as the only backup.
  • Require replication, DNS, SYSVOL, time, authentication, security, trust, application, and business gates before reconnection.

Learn more