Restoring Active Directory on a Windows 2000 Server

Posted on 2006-03-31
Last Modified: 2010-03-18
I am getting ready to introduce a new DC into my Windows network. My new DC will be running Windows 2003 Server. Before I run forest prep and domain prep on my current Windows 2k Server DC to prepare the transfer of FSMO roles to a '03 Server I want to successfully restore AD in my test environment. I setup Windows 2k Server using VMware in my test environment. I successfully backed up my log files and system state of my "live" DC. I made my test server a DC and created my current domain. I restarted in Active Directory Restore Mode and restored from backup system state and log files from my production network DC. When I reboot I am getting a error that says that there were errors during startup and to review event viewer. I am unable to use my keyboard and mouse within VMware to do anything other than restore from my last saved snapshot. I think the problem is that I need to restore AD to identical hardware with critical updates, service packs, and programs installed because "system state" holds the registry. I believe that I need to duplicate what I did in my production environment to my test environment and then copy my test environment the same way I copied the "system state" and "log files" on my production network. If I can restore my test AD successfully to my test environment from my test environment than I will know that I did everything right to backup AD and restore it properly. I can use this knowledge to restore AD during my FSMO roles transfer to my new DC on my production network if there is any kind of problem. I used this KB article verbatim ( to backup and restore AD. Please let me know if I am on the right track.


Question by:Natldiag
    LVL 48

    Expert Comment

    Hi Natldiag,

    your dead on track, the issues with restoring is that it wasnt designed to be restored on a different set of hardware

    LVL 48

    Expert Comment


    you wont have any problems with adminprep tools, they are simple and 99% of the times effective, on the off chance that you do get errors, someone on here would have had them too. Be careful when talking about your restore and FSMO roles, understanding where FSMO roles are held at the time of backup is crucial as if you introduce backups back into a forest and then have multiple instances of the same role......

    your best bet is to have a disaster recovery action plan written up
    LVL 12

    Accepted Solution

    There are other ways to 'backup' your active directory and be up-and-running faster than restoring from backup.

    Try this on a VMware configuration with 2 domain controllers:
    - Configure VMWare as an additional domain controller. Do not make it a GC. Replicate.
    - Shut down VMWare DC.
    - Perform upgrades on the live server.
    - If anything goes wrong, boot the VMWare DC in AD restore mode, and enable Authorative restore for all Naming Contexts.
    - Boot VMWare normally
    - Boot the old DC normally. The Active Directory on VMware 'overwrites' the changes made on the production DC.

    Otherwise, there are some pitfalls restoring to dissimilar hardware, yes.

    This article is all about it:

    Some notes about it here:

    Hope this helps.

    Author Comment

    Thank you Rant32 for the above help.
    When you say "enable Authorative restore for all Naming Contexts" are you talking about restoring AD from backup as discussed in this kb article?;en-us;241594&sd=tech

    LVL 12

    Expert Comment

    Oops, forgot about this one.

    You can't authoratively restore the schema, you'll have to restore the AD on all domain controllers if something goes wrong with the schema update.

    OTOH, I've never seen it fail.

    Featured Post

    Why You Should Analyze Threat Actor TTPs

    After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

    Join & Write a Comment

    Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
    A common practice in small networks is making file sharing easy which works extremely well when intra-network security is not an issue. In essence, everyone, that is "Everyone", is given access to all of the shared files - often the entire C: drive …
    This video discusses moving either the default database or any database to a new volume.
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now