Summary
In this module, you learned about how to backup and restore Active Directory environment. You learned to:
- Design backup coverage from RTO, RPO, topology, and trust boundaries.
- Validate last-known-safe backups through health, replication, incident, compatibility, catalog, key, and restore-test evidence.
- Select object, controller, domain, or forest recovery by incident scope.
- Separate AD DS database authority from SYSVOL authority.
- Recover the first writable controller in each forest-recovery domain with authoritative SYSVOL.
- Recover operations master roles, RID state, trusts, DNS, and global catalog capacity at the correct domain or forest scope.
- Reset the writable
krbtgtaccount twice in each recovered domain, waiting longer than that domain's effective maximum Kerberos ticket lifetime and proving replication convergence before the second reset; handle RODCkrbtgt_<number>accounts separately. - Evaluate VM-Generation ID safeguards without treating snapshots as the only backup.
- Require replication, DNS, SYSVOL, time, authentication, security, trust, application, and business gates before reconnection.
Learn more
- Back up the system state data
- Windows Server Backup command reference
- Determine how to recover the forest
- Enable and use Active Directory Recycle Bin
- Restore-ADObject
- Perform a nonauthoritative restore of Active Directory Domain Services
- Perform an authoritative synchronization of Distributed File System Replication replicated SYSVOL
- Force authoritative or nonauthoritative Distributed File System Replication SYSVOL synchronization
- Perform a full server recovery
- Restore-DnsServerPrimaryZone
- Recover a single domain within a multidomain forest
- Active Directory forest recovery procedures
- Perform the initial forest recovery
- Redeploy remaining domain controllers
- Seize an operations master role
- Invalidate the current relative identifier pool
- Raise the available relative identifier pool
- Reset the krbtgt password
- Reset a trust password
- Virtualized Domain Controller Architecture
- Recover from a Golden group Managed Service Account attack