Corrupted AD in Small Business Server 2011 - SBS 2011

Posted on 2011-09-25
Medium Priority
Last Modified: 2013-12-02
Running SBS 2011 and using the supplied backup solution.

I fouled up a RODC and corrupted my AD (no GP, SYSVOL, etc.).  Appears that my best bet is to do a system state restore but this isn't an area I'm familiar with.

If this is the best bet, I need some help on how to perform this on a VM in Hyper-V.

Also asked another question about problems loading the backups during a system restore.

Question by:a_devildog_0331
  • 2
LVL 10

Expert Comment

ID: 36595923
If the SYSVOL and GPO are missing on RODC then yoou have other way to rebuild SYSVOL tree, That does not indicate that the AD is corrupted.

How did you indefied that AD is corrupted? Pleas provide us more info about you setup, DC's, backup strategy etc.. to help you better.


Author Comment

ID: 36713423
RODC was on a VM that was deleted.  When I tried to create another VM and attach the disk, it didn't like it (different ID number).  I then made it worse by doing a DCPROMO on it and trying to repromote it (lost all the info).

Essentially, when the RODC VM was deleted, I lost access to the GPO and all SYSVOL info.  The SBS server no longer was the PDC and DCPROMO was no help.

I've since performed a system state restore using a guide I found on Google and all appears to be working correctly.

If there was something I could have done differently, I'd still like to know.
LVL 10

Accepted Solution

abhijitwaikar earned 2000 total points
ID: 36714088
Way to recover your DC:
1) Demote and re-promote the server but its valid in multiple DC environment.
2) System state restore-- both single plus multi DC environment.
3) Restoring a Domain Controller Through Re-installation --Single DC and you do not have backup .

Also I would suggest to run DCDIAG, repadmin and check event viewer to confirm the everything is place.


Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
If you need to implement application level security in an Access database application or other VBA code, I strongly encourage you to take advantage of Active Directory groups.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question