Restoring Active Directory on a Windows 2000 Server

Posted on 2006-03-31
Medium Priority
Last Modified: 2010-03-18
I am getting ready to introduce a new DC into my Windows network. My new DC will be running Windows 2003 Server. Before I run forest prep and domain prep on my current Windows 2k Server DC to prepare the transfer of FSMO roles to a '03 Server I want to successfully restore AD in my test environment. I setup Windows 2k Server using VMware in my test environment. I successfully backed up my log files and system state of my "live" DC. I made my test server a DC and created my current domain. I restarted in Active Directory Restore Mode and restored from backup system state and log files from my production network DC. When I reboot I am getting a error that says that there were errors during startup and to review event viewer. I am unable to use my keyboard and mouse within VMware to do anything other than restore from my last saved snapshot. I think the problem is that I need to restore AD to identical hardware with critical updates, service packs, and programs installed because "system state" holds the registry. I believe that I need to duplicate what I did in my production environment to my test environment and then copy my test environment the same way I copied the "system state" and "log files" on my production network. If I can restore my test AD successfully to my test environment from my test environment than I will know that I did everything right to backup AD and restore it properly. I can use this knowledge to restore AD during my FSMO roles transfer to my new DC on my production network if there is any kind of problem. I used this KB article verbatim (http://support.microsoft.com/kb/240363) to backup and restore AD. Please let me know if I am on the right track.


Question by:Natldiag
  • 2
  • 2
LVL 48

Expert Comment

ID: 16347010
Hi Natldiag,

your dead on track, the issues with restoring is that it wasnt designed to be restored on a different set of hardware

LVL 48

Expert Comment

ID: 16347025

you wont have any problems with adminprep tools, they are simple and 99% of the times effective, on the off chance that you do get errors, someone on here would have had them too. Be careful when talking about your restore and FSMO roles, understanding where FSMO roles are held at the time of backup is crucial as if you introduce backups back into a forest and then have multiple instances of the same role......

your best bet is to have a disaster recovery action plan written up
LVL 12

Accepted Solution

Rant32 earned 500 total points
ID: 16349158
There are other ways to 'backup' your active directory and be up-and-running faster than restoring from backup.

Try this on a VMware configuration with 2 domain controllers:
- Configure VMWare as an additional domain controller. Do not make it a GC. Replicate.
- Shut down VMWare DC.
- Perform upgrades on the live server.
- If anything goes wrong, boot the VMWare DC in AD restore mode, and enable Authorative restore for all Naming Contexts.
- Boot VMWare normally
- Boot the old DC normally. The Active Directory on VMware 'overwrites' the changes made on the production DC.

Otherwise, there are some pitfalls restoring to dissimilar hardware, yes.

This article is all about it:

Some notes about it here:

Hope this helps.

Author Comment

ID: 16371677
Thank you Rant32 for the above help.
When you say "enable Authorative restore for all Naming Contexts" are you talking about restoring AD from backup as discussed in this kb article? http://support.microsoft.com/default.aspx?scid=kb;en-us;241594&sd=tech

LVL 12

Expert Comment

ID: 16569119
Oops, forgot about this one.

You can't authoratively restore the schema, you'll have to restore the AD on all domain controllers if something goes wrong with the schema update.

OTOH, I've never seen it fail.

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Nslookup is a command line driven utility supplied as part of most Windows operating systems that can reveal information related to domain names and the Internet Protocol (IP) addresses associated with them. In simple terms, it is a tool that can …
The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question