Solved

Rollback plan / backup plan before ADSI Edit for MS Exchange ?

Posted on 2015-01-12
9
2,071 Views
Last Modified: 2015-01-12
I'm about to follow the article in this blog posting: http://www.itguydiaries.net/2012/07/omg-exchange-security-groups-were.html in order to restore all deleted / missing Exchange 2010 AD Security group in a single domain forest.

I'm just wondering what do I need to backup in case the ADSI edit or the SETUP.COM /PrepareSchema is screwing or making my currently working Exchange Server 2010 SP2 grinding into a halt ?

What are the roll back plan that you suggest ?

Thanks,
0
Comment
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 21

Assisted Solution

by:Radhakrishnan R
Radhakrishnan R earned 100 total points
ID: 40544316
Hi,

You can use ldifde to backup adsiedit before deleting or modifying any objects.

http://www.mysysadmintips.com/windows/active-directory/266-export-active-directory-objects-with-ldifde-before-performing-changes-with-adsi-edit

Hope this helps
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 400 total points
ID: 40544637
If you are doing and changes to the schema and you need to restore you will need a system state full backup. You can either use Windows Server Backup or a 3rd party backup tool to take the backup.

Also see the link below regarding System State Backups.
System State Backup

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545382
OK so on this case the schema is modified from the Schema master role DC, so I just need to take the backup of the Schema Master role system state only using windows backup (2008R2). ?

Is that enough ?
0
Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 40545465
That is correct. Do not take a system state backup from any other DC. Just the Schema Master. Remmeber that when you take a backup from a diffetent DC you cannot use that image on the schema master or any other DC for the matter.

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545503
ok, great, I was worried about the AD replication to the other DCs. So yes I'll just take the backup from just this one Schema master role DC.

Thanks.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 40545509
If you ever need to restore the image you need to do an Authoritative Restore which will then push out all of the changes from the backup to all of the other domain controllers to ensure they all have the same schema.

Will.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545523
Will, under what condition should I choose the "restore the image" over the normal "System State" backup only ?
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 40545564
Are you talking about a full complete iimage of the Domain Controller? The only reason for taking a complete image of a domain controller is so that if you ever run into an issue where all of your domain controllers have been compromized you would then restore the indicidual image of the DC and the promote new domain controllers from there.

In Server 2012 there is a new feature called Domain Controller cloning and if this is configured properly it works well.

Here is more info on it. Aside from that do not restore an entire image into the domain or you will run into replication issues and USN out of sync.

http://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx

Will;.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40545586
Many thanks for the clarification and explanation. All of my Domain Controller are on Windows Server 2008 R2 and 2003 with Windows Server 2003 Domain/Forest functionality level.


So I guess I don't have that feature for "cloning".
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…
Suggested Courses

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question