Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Backing up Virtual Machine Domain Controllers from within or from above...?

Posted on 2015-02-15
7
Medium Priority
?
150 Views
Last Modified: 2015-02-16
Hi,

I cant seem to get a concrete answer on this.
If you have virtual domain controllers running windows server 2008(r2) or 2012(r2) on Hyper-V, do you backup the virtual machine and host level using windows server backup and VSS taking care of consistency or do you have to backup the domain controller from within itself as a guest OS?

I just cant seem to get a concrete answer on this.

Thanks!
0
Comment
Question by:dqnet
7 Comments
 
LVL 37

Expert Comment

by:bbao
ID: 40611596
commonly for a working DC running on a guest OS, it is NOT recommended to back up at VM level, in your case at Hyper-V level, simply because it may cause out-of-sync or conflicts once the restored DC get back online when other DCs in the same AD are also alive, especially when there is a huge change after the DC/VM was backed up.
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 2000 total points
ID: 40611604
I don't believe Windows Server Backup is AD VSS aware when backing up at the host level.

I always backup DCs at the guest level, host-level backups are really only useful if your DCs go down and you are unable to recover them using any other methods.
0
 
LVL 37

Expert Comment

by:bbao
ID: 40611629
FYI - let's check an official document giving more details and discussions about this issue.

Backup and Restore Considerations for Virtualized Domain Controllers
https://technet.microsoft.com/en-us/library/virtual_active_directory_domain_controller_virtualization_hyperv(v=ws.10).aspx

"The supported method of restoring a domain controller to a healthy state is to use an Active Directory–compatible backup application, such as Windows Server Backup, to restore a system state backup that originated from the current installation of the domain controller."

"if you restore a domain controller by using a copy of the virtual hard disk (VHD) file, you bypass the critical step of updating the database version of a domain controller after it has been restored. Replication will proceed with inappropriate tracking numbers, resulting in an inconsistent database among domain controller replicas. In most cases, this problem goes undetected by the replication system and no errors are reported, despite inconsistencies between domain controllers."

"Do not copy or clone VHD files of domain controllers instead of performing regular backups. If he VHD file is copied or cloned, it becomes stale. Then, if the VHD is started in normal mode, there might be a divergence of replication data in the forest. You should perform proper backup operations that are supported by Active Directory Domain Services (AD DS), such as using the Windows Server Backup feature."

"Do not use the Snapshot feature as a backup to restore a virtual machine that was configured as a domain controller. Problems will occur with replication when you revert the virtual machine to an earlier state. ... Although using a snapshot to restore a read-only domain controller (RODC) will not cause replication issues, this method of restoration is still not recommended."
0
NEW Veeam Backup for Microsoft Office 365 1.5

With Office 365, it’s your data and your responsibility to protect it. NEW Veeam Backup for Microsoft Office 365 eliminates the risk of losing access to your Office 365 data.

 

Expert Comment

by:Huig Guijt
ID: 40611815
Software like Veeam is application aware because of its VSS writers. With this option enabled you can safely backup and restore a domain controller. It even enables you to live backup the machine without interuption and then restore just your AD.
See also: http://helpcenter.veeam.com/backup/80/vsphere/restore_vead.html and http://helpcenter.veeam.com/backup/80/vsphere/application_aware_processing.html
0
 
LVL 12

Expert Comment

by:Mr Tortur
ID: 40612367
Hi,
I agree with past comments.
What is important in case you need to restore is Active Directory DB and objects.
So Either backup it up using the guest method (back up system state that include AD DB), or using the "host" method with a software that supports backup and restore of AD objects or entire DB.
It seems Veeam does that, I know it for reading documentation yet, but I have never tested a backup and a restore on AD object/DB.
0
 

Author Comment

by:dqnet
ID: 40612647
Thanks guys!
0
 
LVL 40

Expert Comment

by:Philip Elder
ID: 40612763
Windows Server Backup from the host level is VSS aware for any VSS service running in Services.msc. This includes ADDS.

However, we do not back up from the host unless using a proven third party product.

When running WSB at the host level we ran into all sorts of problems with VSS collisions. So much so that we dropped WSB across the board for host base backups. This was on 2008 RTM/R2 (we've been running standalone and clustered Hyper-V at client sites since 2008 RTM) with no improvements with each new OS iteration.

We back up in-guest as a rule unless we are dealing with complex clustered environments or hosting setups.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses

927 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question