Backup AD Structure, Passwords

markterry
markterry used Ask the Experts™
on
Hello,

I am trying to see if there is a way, besides using system restore, to backup my AD. I want to push this to an online backup and want to keep it smaller. I seem to remember maybe there is a way to do this with VBScript, maybe I am wrong.

Any ideas are appreciated. Hoping to result in a small file that would allow me to import users and passwords back into a brand new AD controller in the event of a fire or something.

Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Brian PiercePhotographer
Awarded 2007
Top Expert 2008

Commented:
A backup of the SYSTEM STATE is the recommended way to backup AD.  While you could export most acount details with a script (passwords would be tricky as they are not actually stored as such), AD contains much more than this including group information SIDS and a whole plethora of other stuff
Commented:
If you want to be able to run a regularly scheduled minimum-size backup of AD for disaster recovery, you should look at using an AD backup/clone utility like UMove (http://utools.com/UMove.asp) that can reload AD from scratch.  The problem is that the system state doesn't include the machine private keys, which are required for a bare-metal restore of AD.  Utilities like UMove and AD Recovery Manager include the private keys in the backup.

Author

Commented:
Thanks guys.

Gideon, I like the sound of your solution, could you please elaborate on why the machine's Private Keys are important? It seems to me like the recommended approach of System State should include everything you need.
Success in ‘20 With a Profitable Pricing Strategy

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Top Expert 2013

Commented:
The best thing here would be to have a second DC offsite/remote location.  That doesn't mean don't backup AD but in a fire/major issue situation that other DC would be there.

Thanks

Mike
Commented:
The System State is sufficient to restore AD on the same computer, however it cannot be used to move AD to a clean install of Windows.  For a list of some of the missing files and settings that need to be backed up see http://utools.com/help/StagingLayout.asp and http://utools.com/help/ReloadComprehensive.asp.

Author

Commented:
Thank you Gideon, i think your answer makes the most sense for my environement. We are not large enough to have an offsite location, but we are worried about having to install to brand new machines incase of fire or other disaster.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial