Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Adrestore.Net Vs NTDSUtil

Posted on 2010-11-18
8
Medium Priority
?
1,788 Views
Last Modified: 2012-06-22
I am sure there is an expert out there who used both Adrestore.Net as well as (AD authoritative Restore+NTDSutil). Can you please tell me the difference?

it seems like the Adrestore.net is more simpler than restoring the AD system state from Backup then restarting the DC to AD restore mode then use NTDSUtil to authoritatively restore the objects.

Since Adrestore.net is simpler and free, why would administrators use the lengthy procedure of AD Authoritative restore, I have described.

Thanks
0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 34170938
adrestore.net and the command line adrestore do a process known as "tombstone reanimation" when you use those tools it does bring the object back but all the objects that are stripped out when an object is deleted are not brought back.  With an authoritative restore they are brought back.

Gil has a great article that goes into more details   http://technet.microsoft.com/en-us/magazine/2007.09.tombstones.aspx

See the section "recovering object attributes"

This also all improves once you get the recycle bin feature in a 2008 R2 forest because then the objects are restored with all attributes intact (no more marking as authoritative or getting back a "tombstoned" object.

Thanks

Mike
0
 

Author Comment

by:jskfan
ID: 34179611
According to the article in the above link:

Adrestore is easier to use than LDP.exe.
Adrestore doesn't restore Group membership


OK,  for now I guess the best way to go is Authoritative Restore.
it says that you take a DC offline, but I believe if you have 3,4,5 DCs replicating, taking one offline will not do any harm.

Let me see if I am correct in implementing an Authoritative restore.
1-While the DC is still online, I should do System State restore from the backup tape.
2-When the restore of system state to the online DC is completed successfuly, I will reboot the DC to AD Restore Mode, by pressing F8 at the reboot.
3-Run NTDSutil and implement the authoritative restore.
4-Restart the DC to normal mode.
I believe this is how it should be done.
I prefer the authoritative restore since I don't have to worry if there is any object or attribute missing.

 
0
 

Author Comment

by:jskfan
ID: 34180778
sorry, I guess step 1 should be:
1-Take the DC offline, then do System State restore from the backup tape.
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 

Author Comment

by:jskfan
ID: 34180847
I believe I am still confused on step 1:
1-Restart the DC into AD restore mode, then restore the system state.
Stay in the AD Restore Mode and use NTDsutil to authoritatively restore the deleted object.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 34181145
Yes you stay in DSRM and mark the object as authoritative.
0
 

Author Comment

by:jskfan
ID: 34182968
<<Yes you stay in DSRM and mark the object as authoritative.>>

The confusion is when Restoring the System state of the yesterday backup:

-Should I leave the DC as it is, online and replicating with other DCs, and restore the system state?
-Should I disconnect it from the network, for instance unplug the network cable, and restore the system state?
-Should I restart in DSRM and restore the system state?
0
 

Author Comment

by:jskfan
ID: 34183218
http://technet.microsoft.com/en-us/library/bb727048.aspx

I guess I have to log into DRSM mode and do system state restore from backup tape then staying at the DRSM mode I will use ntdsutil to do the authoritative restore.
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 2000 total points
ID: 34184411
Yup you have it right, I was going to take some screen shots but didn't have time today.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question