Symantec Backup Exec 12.5 DLO: Can I restore a user deleted from AD?

We're using Symantec Backup Exec 12.5 DLO to backup users in our organization.

I realized that if a user is deleted from the Active Directory then the backup data is unrecoverable because of a key needed to decrypt the files being deleted as well.

Is there any way to restore the files of this user? Or if not is there a procedure I could follow to avoid this situation in the future? (like disabling encryption for that user only, just before he/she's deleted from AD)

- C.L.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Are you only using backup exec DLO ? or also BE for normal backup
BE has an Active directory client, who backs-up the AD
What version of BE are you using ?


fbmeitAuthor Commented:
I wouldn't want to restore users. We can't have all the users that leave the organization stay in the AD forever just for the backup server. I would like to know if there's any other way to go about it without being dependent on the AD domain account of each user.

As mentioned we use 12.5.
anyway you should be able to retore to a different location
why are there doc on there PC's and not on central storage

Cheers Wim
10 Holiday Gifts Perfect for Your Favorite Geeks

Still have some holiday shopping to do for the geeks in your life? While toys, clothing, games, and gift cards are still viable options for your friends and family, there’s more reason than ever to consider gadgets and software.

fbmeitAuthor Commented:
All data are stored on the server. We don't use the users' desktop to store backup files. We've got the encryption for storage enabled

This post can clear things up:

I don't mind losing this one user's data. I was wondering if this can be avoided in the future in any way
can't you just restore the users data to a differrent location ( afolder on your server) before deleting the user ?



Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
I am not sure about 12.0 as we are using 12.5, but you can check if the following works for you

go to Restore System State - -> Active Directory --> DC=XYZ --> OU (go to the user OU) and then you can restore the user
fbmeitAuthor Commented:
I guess restoring the user's data before we delete it from AD is the way to go. The only disadvantage is that we'll have to manually encrypt the data using third-party software.

Based on my findings and your answers I'm guessing that after the user is deleted the data can no longer be recovered unless first restore the user in AD (which I haven't tested yet)

Thank you for your help Wim
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Storage Software

From novice to tech pro — start learning today.