Active Directory Forest Recovery - Perform a nonauthoritative restore of Active Directory Domain Services

Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2 and 2012

To perform a nonauthoritative restore, complete the following procedure.

The following procedures use the wbadmin.exe to perform a nonauthoritative restore of Active Directory or Active Directory Domain Services (AD DS). If you're using a different backup solution or if you intend to complete the authoritative restore of SYSVOL later in the forest recovery process, you can perform an authoritative restore of SYSVOL by using these alternative methods:

Perform a nonauthoritative restore

Use the following procedure to perform a nonauthoritative restore of AD DS and an authoritative restore of SYSVOL at the same time by using wbadmin.exe. The backup must explicitly include system state data; a full server backup that is used for full server recovery won't work. A Bare Metal Recovery Backup (BMR) will contain a system state backup. For more information about creating a system state backup, see Backing up the System State data.

Perform a nonauthoritative restore of AD DS and authoritative restore of SYSVOL using wbadmin.exe**

Include the -authsysvol switch in your recovery command, as shown in the following example:

wbadmin start systemstaterecovery \<otheroptions\> -authsysvol

For example:

wbadmin start systemstaterecovery -version:01/01/2023-13:00 -authsysvol

Restore

Next steps