Link to home
Start Free TrialLog in
Avatar of jesaja
jesajaFlag for Switzerland

asked on

windows 2003/2008 Server authoritative restore of single object

If there is only one Domain controller in a network and I need to restore just one object by using ntdsutil in AD restore mode.
Is it possible or those it depent on the backup software. The normal procedure is to boot in restore mode run the restore of ad from the backup software, use ntdsutil and set it to authoritative and specify the object, boot normal.

Avatar of Vaidas911
Vaidas911
Flag of Lithuania image

You need to have Windows System state or similar backup and restore AD object. Authoritative is not necesary if you have the only one DC -your DC will not sync with other DC incorrect information (authoritative restore overides incorrect (incorrectly modified) information).
http://www.computerperformance.co.uk/w2k3/utilities/windows_authoritative_restore.htm

Windows Server R2 presented recycle bin of AD - you can restore objects right away.
You can re-animate the tombstoned object with adrestore. If will not restore back-links to groups and the object will be striped.

http://technet.microsoft.com/en-us/sysinternals/bb963906.aspx

With 2008 you can restore objects from a snapshot (taken with ntdsutil).
Avatar of jesaja

ASKER

So it is correct that any Backup Software completely restores the AC Database.
And if there is only one DC no other DCs will overwrite the restored database/objects.


If an object is deleted by using adsiedit I think it cannot be restored with adrestore.


*Any AD aware backup software.

A single DC domain has not any replication partners so I don't replicate restored or deleted objects.

I have only tested ADrestore with user objects, so if you delete attributes within adsi adrestore can't help you. (btw you don't have to boot in DSRM to use re-animation).




Avatar of jesaja

ASKER

With a singel DC domain I do not need to boot in DSRM, right?
ASKER CERTIFIED SOLUTION
Avatar of snusgubben
snusgubben
Flag of Norway image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
But you should offcourse have more then one DC for redundancy! :)