Solved

Help! Lost the AD Forest Root!

Posted on 2003-11-18
7
604 Views
Last Modified: 2008-02-26
I'm an MCSA who's been thrown in completely at the deep end with the mother of all disaster recovery challenges. Two days to resurrect a forest root domain controller that hosts a number of subdomains.

Sounds easy? Well, it was the only DC in its domain and we don't have ANY backup apart from the GHOST image created after running DCPROMO for the first time.

I work at a college, and recently set up a lab of W2K servers.

We were broken into recently, and a bunch of machines and drives were nicked from the office adjoining the lab; unfortunately this included the forest root - a machine called INSTRUCTOR which was the first DC in the Room.College domain.

Even more unfortunately, in the resulting nicking spree, the backups were nicked as well as a couple of student machines. Fortunately they were disturbed before the whole room got cleared out.

(I'm not joking.)

The remaining PCs in this room were set up as seperate DCs, each in its own subdomain. For example,

Student2DC.Student2Dom.Room.College
Student3DC.Student3Dom.Room.College

The students on these machines all logged in as Administrator in their own domains, OR Instructor in the domain Room.College.

Here's the tricky bit. There's no backup of the Forest Root, at least not since the day it was first built. The class has evolved around building the AD over the past month or so.

As luck would have it, I created GHOST images of the server prior to handing it over to the tutor so I have been able to build up a spare machine as a replacement.

However, the only existing backup of INSTRUCTOR is (quite understandably) unaware of any of its child domains, far less any of the objects in them.

I've left it disconnected from the LAN while I figure out how to proceed. One of the remaining student machines is also a Global Catalog for the domain, but won't synch with the other DCs until DNS is up and running (which means powering up INSTRUCTOR).

If I jack INSTRUCTOR back into the network, what's likely to happen? If I boot into DS Restore Mode and tell it to do a non-authoritative restore, will the other servers re-integrate with the AD?

0
Comment
Question by:tstaddon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
7 Comments
 
LVL 5

Author Comment

by:tstaddon
ID: 9772407
Should add at this point that we are talking a number of students who have paid for a 12 week course, all of whom have customised their own AD as they see fit.

Aside from the AD, there's no loss of data. The server wasn't used for generic File & Print services, all it did was authentication, DNS, and proive the teacher with a machine that was connected to an electronic whiteboard.
0
 
LVL 8

Expert Comment

by:nader alkahtani
ID: 9772714
0
 
LVL 8

Expert Comment

by:nader alkahtani
ID: 9773000
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 
LVL 5

Author Comment

by:tstaddon
ID: 9777407
Thanks for the links.

I checked the troubleshooting flowchart for this state of affairs, and no suggestion is available for this instance because the DC in question was the only server in that domain, it held all the FSMO roles prior to the theft, and was therefore the ONLY machine that had any idea of the structure of the Active Directory.

The backup only restores the server to the point it was at BEFORE the child domains were created.

This is a rough description of the directory structure as it now stands:

DISCONNECTED              |   OPERATIONAL
                                     |
Room.College                 |  Student1Dom.Room.College    Student2Dom.Room.College     Student3Dom.Room.College
DC: Instructor                 |  DC: Student1DC                     DC: Student2DC                      DC: Student2DC
Member Servers: none    |  Member Servers: None           Member Servers: None            Member Servers: None
DNS                               |  Global Catalog (created
Infrastructure Master       |  after Instructor went down)
Schema Master               |  
Global Catalog
PDC Emulator
RID Master
** Doesn't know about the Child Domains **

The students can log in locally to the DCs, but I will need them to access Instructor at some point because they are learning about AD and need access to the root domain, to join existing standalone 2K servers to the AD.

0
 
LVL 5

Author Comment

by:tstaddon
ID: 9881002
Sorry, lads, but I figured this one out on my own. I exported lists of AED objects on each server, used DCPROMO /FORCEREMOVAL to kill off the directory, then restored the instructor server, and then DCPROMO'd the other DCs.

Using the object lists, I had the network up and running again after a couple of hours.
0
 

Accepted Solution

by:
PashaMod earned 0 total points
ID: 9900343
Question closed and points refunded

PashaMod
CS Moderator
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Invest in your employees with these five simple steps to improve employee engagement and retention.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question