Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Active Directory failed and Can Not Be restored from Tape

Posted on 2008-11-17
Medium Priority
Last Modified: 2012-05-05
Active Directory failed and Can Not Be restored from Tape

The Firm has 1 Domain Controller, 1 exchange Server, and a few application server 2 are windows 2000 servers and 1 is windows 2003 server. All servers are part of the domain, but only one is a Domain Controller, and it runs also DHCP and DNS services.

If the Active directory failed on the domain controller, what and how should one approach this issue, if one wants to bring up the operation, and rebuild the fasiling domain controller later on.

Question by:jfk1959
LVL 35

Expert Comment

by:Joseph Daly
ID: 22979105
Ideally the best way to prevent something like this happening would be to add a secondary DC so that you have at least a little failover.

If you are going to be running with a single DC I would highly reccomend taking complete backups daily of the entire system including system state. If you cant do it to tape back it up to an external disk or another server.
LVL 70

Accepted Solution

KCTS earned 500 total points
ID: 22980610
I agree the simplest way is to have a second domain controller so you don't get into this situation in the first place - prevention is better then cure. You can make onr of the existing servers a domain controller by promting it to be a DC

From the command line promote the new machine to a domain controller with the DCPROMO command from the command line and  Select Additional Domain Controller in an existing Domain

Assuming that you are using Active Directory Integrated DNS on the first Domain Controller, Just install DNS on the new DC (from the control panel->Windows Components->Networking Services->DNS, or Configure my server wizard), DNS will then replicate to the new domain controller along with Active Directory.

To make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand, Sites, Default first site and Servers. Right click on the new server and select properties and tick the Global Catalog checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

Even with two DCs in place you still need to do regular backups though.

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question