Solved

Rollback plan / backup plan before ADSI Edit for MS Exchange ?

Posted on 2015-01-12
9
1,247 Views
Last Modified: 2015-01-12
I'm about to follow the article in this blog posting: http://www.itguydiaries.net/2012/07/omg-exchange-security-groups-were.html in order to restore all deleted / missing Exchange 2010 AD Security group in a single domain forest.

I'm just wondering what do I need to backup in case the ADSI edit or the SETUP.COM /PrepareSchema is screwing or making my currently working Exchange Server 2010 SP2 grinding into a halt ?

What are the roll back plan that you suggest ?

Thanks,
0
Comment
  • 4
  • 4
9 Comments
 
LVL 20

Assisted Solution

by:Radhakrishnan Rajayyan
Radhakrishnan Rajayyan earned 100 total points
Comment Utility
Hi,

You can use ldifde to backup adsiedit before deleting or modifying any objects.

http://www.mysysadmintips.com/windows/active-directory/266-export-active-directory-objects-with-ldifde-before-performing-changes-with-adsi-edit

Hope this helps
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 400 total points
Comment Utility
If you are doing and changes to the schema and you need to restore you will need a system state full backup. You can either use Windows Server Backup or a 3rd party backup tool to take the backup.

Also see the link below regarding System State Backups.
System State Backup

Will.
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
OK so on this case the schema is modified from the Schema master role DC, so I just need to take the backup of the Schema Master role system state only using windows backup (2008R2). ?

Is that enough ?
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
Comment Utility
That is correct. Do not take a system state backup from any other DC. Just the Schema Master. Remmeber that when you take a backup from a diffetent DC you cannot use that image on the schema master or any other DC for the matter.

Will.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
ok, great, I was worried about the AD replication to the other DCs. So yes I'll just take the backup from just this one Schema master role DC.

Thanks.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
Comment Utility
If you ever need to restore the image you need to do an Authoritative Restore which will then push out all of the changes from the backup to all of the other domain controllers to ensure they all have the same schema.

Will.
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
Will, under what condition should I choose the "restore the image" over the normal "System State" backup only ?
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
Comment Utility
Are you talking about a full complete iimage of the Domain Controller? The only reason for taking a complete image of a domain controller is so that if you ever run into an issue where all of your domain controllers have been compromized you would then restore the indicidual image of the DC and the promote new domain controllers from there.

In Server 2012 there is a new feature called Domain Controller cloning and if this is configured properly it works well.

Here is more info on it. Aside from that do not restore an entire image into the domain or you will run into replication issues and USN out of sync.

http://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx

Will;.
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
Comment Utility
Many thanks for the clarification and explanation. All of my Domain Controller are on Windows Server 2008 R2 and 2003 with Windows Server 2003 Domain/Forest functionality level.


So I guess I don't have that feature for "cloning".
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now