Solved

WINDOWS 2003 R2 AND ACTIVE DIRECTORY RESTORE

Posted on 2013-12-10
13
458 Views
Last Modified: 2013-12-10
Hello All,

I am in trouble. I need to restore AD from System State backup file. Unfortunately, I am struggling to access the server locally (after starting it on safe mode). The server is running AD and it does not have local account.

Is there a way to go about it and perform a restore?

Much appreciate your help.
0
Comment
Question by:TMAA
  • 6
  • 6
13 Comments
 
LVL 14

Assisted Solution

by:comfortjeanius
comfortjeanius earned 500 total points
ID: 39709100
You need to start the server in Active Directory Restore Mode not safe mode.

To restart the domain controller in Directory Services Restore Mode locally

1. Restart the domain controller.

2. When the screen for selecting an operating system appears, press F8.

3. On the Windows Advanced Options menu, select Directory Services Restore Mode.

4. When you are prompted, log on as the local administrator.

0
 

Author Comment

by:TMAA
ID: 39709125
Thank You.

I have followed all the steps (1-4), where I get stuck is at login screen.

I do not have local administrator account. Tried to create new user under Computer Management>Systems Tools> NO Users and Groups option.

How will I manage to access the server locally is my problem. Unless, there is another way to restore AD.

Please help
0
 
LVL 14

Expert Comment

by:comfortjeanius
ID: 39709216
You do not know the local administrator password or the local administrator is disable?
0
 

Author Comment

by:TMAA
ID: 39709220
The server don't have local users and groups. All users worked from AD. Now AD has a problem, hence all the troubles.
0
 
LVL 14

Expert Comment

by:comfortjeanius
ID: 39709270
It is probably disabled

1. Start your computer in to Safe mode with networking support.

2. Log on as the administrator.

3. Click Start, click Run, type cmd, and then press Enter.

4. At the command prompt, type the following command, and then press Enter:

net user administrator /active:yes

5. Restart your computer.


Note: You can use the recovery console to access the computer even if the local Administrator account is disabled. Disabling the local Administrator account does not prevent you from logging on to the recovery console as Administrator.
0
 

Author Comment

by:TMAA
ID: 39709418
Thanks,

The command completed successfully....awaiting server restart.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 18

Expert Comment

by:sarang_tinguria
ID: 39709443
How many DC's do you have ..If multiple DC's then forget system state backup
If single DC, you need to have DSRM password to login to DSRM mode
0
 

Author Comment

by:TMAA
ID: 39709455
Single DC. You are right, I need DSRM password...

How do I get it, or after running net user administrator /active:yes I should be able to create one after login in as a domain admin?
0
 
LVL 14

Accepted Solution

by:
comfortjeanius earned 500 total points
ID: 39709505
When you start Windows Server 2003 in Directory Services Restore Mode, the local Administrator account is authenticated by the local Security Accounts Manager (SAM) database. Therefore, logging on requires that you use the local administrator password, not an Active Directory domain password. This password is set during Active Directory installation when you provide the password for Directory Services Restore Mode.

1. Restart the domain controller.

2. When the screen for selecting an operating system appears, press F8.

3. On the Windows Advanced Options menu, select Directory Services Restore Mode.

4. When you are prompted, log on as the local administrator.


Here the KB Article for Resetting DRSM Administrator Password
0
 

Author Comment

by:TMAA
ID: 39709701
Edited..

Thank you
0
 
LVL 14

Assisted Solution

by:comfortjeanius
comfortjeanius earned 500 total points
ID: 39709858
You will have to authenticate locally to the domain controller.

Then follow the instructions that I first provide to enter Active directory Restore Mode "ID: 39709100"

I received these instructions from Restore Active Directory from backup
Once you authenticate with the administrator password

1. To start the Windows Server 2003 backup utility, click Start, point to All Programs, point to Accessories, point to System Tools, and then click Backup.


This procedure provides steps for restoring from backup in Wizard Mode. By default, the Always Start in Wizard Mode check box is selected in the Backup or Restore Wizard. If the Welcome to the Backup Utility Advanced Mode page appears, click Wizard Mode to open the Backup or Restore Wizard.

2. On the Welcome to the Backup or Restore Wizard page, click Next.

3. Click Restore files and settings, and then click Next.

4. Select System State, and then click Next.

5. On the Completing the Backup or Restore Wizard page, click Advanced.

6. In Restore files to, click Original Location, and then click Next.

7. Click Leave existing files (Recommended), and then click Next.

8. In Advanced Restore Options, select the following check boxes, and then click Next:

Restore security settings
Restore junction points, but not the folders and file data they reference
Preserve existing volume mount points

9. For a primary restore of SYSVOL, also select the following check box: When restoring replicated data sets, mark the restored data as the primary data for all replicas.

A primary restore is required only if the domain controller that you are restoring is the only domain controller in the domain. A primary restore is required on the first domain controller that is being restored in a domain if you are restoring the entire domain or forest.
Now click "Finish" and "Close" when this process has finish
If you do not want to authoritatively restore any objects, click Yes to restart the computer. The system will restart and replicate any new information that is received since the last backup with its replication partners.
If you want to authoritatively restore any objects or if you want to create an LDAP Data Interchange Format (LDIF) file to restore back-links on this domain controller, click No to remain in Directory Services Restore Mode.
0
 

Author Closing Comment

by:TMAA
ID: 39709986
Thank you so much for your assistance.

I have managed to restore the Active Directory.
0
 
LVL 14

Expert Comment

by:comfortjeanius
ID: 39710206
Congratulations!!!! No problem glad to be of assistance

@(^_^)@
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now