Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Rollback plan / backup plan before ADSI Edit for MS Exchange ?

Posted on 2015-01-12
9
Medium Priority
?
2,549 Views
Last Modified: 2015-01-12
I'm about to follow the article in this blog posting: http://www.itguydiaries.net/2012/07/omg-exchange-security-groups-were.html in order to restore all deleted / missing Exchange 2010 AD Security group in a single domain forest.

I'm just wondering what do I need to backup in case the ADSI edit or the SETUP.COM /PrepareSchema is screwing or making my currently working Exchange Server 2010 SP2 grinding into a halt ?

What are the roll back plan that you suggest ?

Thanks,
0
Comment
  • 4
  • 4
9 Comments
 
LVL 23

Assisted Solution

by:Radhakrishnan R
Radhakrishnan R earned 400 total points
ID: 40544316
Hi,

You can use ldifde to backup adsiedit before deleting or modifying any objects.

http://www.mysysadmintips.com/windows/active-directory/266-export-active-directory-objects-with-ldifde-before-performing-changes-with-adsi-edit

Hope this helps
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 1600 total points
ID: 40544637
If you are doing and changes to the schema and you need to restore you will need a system state full backup. You can either use Windows Server Backup or a 3rd party backup tool to take the backup.

Also see the link below regarding System State Backups.
System State Backup

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545382
OK so on this case the schema is modified from the Schema master role DC, so I just need to take the backup of the Schema Master role system state only using windows backup (2008R2). ?

Is that enough ?
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 1600 total points
ID: 40545465
That is correct. Do not take a system state backup from any other DC. Just the Schema Master. Remmeber that when you take a backup from a diffetent DC you cannot use that image on the schema master or any other DC for the matter.

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545503
ok, great, I was worried about the AD replication to the other DCs. So yes I'll just take the backup from just this one Schema master role DC.

Thanks.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 1600 total points
ID: 40545509
If you ever need to restore the image you need to do an Authoritative Restore which will then push out all of the changes from the backup to all of the other domain controllers to ensure they all have the same schema.

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545523
Will, under what condition should I choose the "restore the image" over the normal "System State" backup only ?
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 1600 total points
ID: 40545564
Are you talking about a full complete iimage of the Domain Controller? The only reason for taking a complete image of a domain controller is so that if you ever run into an issue where all of your domain controllers have been compromized you would then restore the indicidual image of the DC and the promote new domain controllers from there.

In Server 2012 there is a new feature called Domain Controller cloning and if this is configured properly it works well.

Here is more info on it. Aside from that do not restore an entire image into the domain or you will run into replication issues and USN out of sync.

http://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx

Will;.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545586
Many thanks for the clarification and explanation. All of my Domain Controller are on Windows Server 2008 R2 and 2003 with Windows Server 2003 Domain/Forest functionality level.


So I guess I don't have that feature for "cloning".
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It is a real story and is one of my scariest tech experiences. Most users think that IT experts like us know how to fix all computer problems. However, if there is a time constraint and you MUST not fail the task or you will lose your job, a simple …
Steps to fix “Unable to mount database. (hr=0x80004005, ec=1108)”.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question