UltraBac System State/Active Directory Restore

Overview

Three types of Active Directory restores exist: Authoritative, Non-Authoritative, and Primary.

 

 

A base installation of Windows Server will have four subobjects under "System State" in a File-by-File Agent set. These objects are seen when a local or remote file-by-file set is loaded, assuming the File-by-File Agent has been installed on the system being backed up. The subcomponents of the System State are the following:

 

 

The System State of an Active Directory host contains more subcomponents under the "System State" icon seen in the UltraBac interface:

 

 

NOTE:  The Windows Service Pack at the restore target must be the same as that of the machine at the time of backup.

 

NOTE:  When pushing the restore to a remote system booted into Directory Services Mode, be sure that full version of UltraBac is installed on the restore target.

Prerequisites for Full Operating System Restore

 

NOTE:  When attempting to restore an Active Directory host to a new installation of Windows, a base version of Active Directory, using only the default components, must be installed before attempting the restore.

 

NOTE:  In previous versions of Windows Server, the preferred method of reaching the Advanced Boot Options menu was to press F8 immediately after the power-on self-test (POST) process completed. This often required numerous attempts and rapid pressing of the F8 key. Windows Server 2012 and later boots significantly more quickly than previous versions, making it difficult to press F8 at the correct time. You can use one of the methods in this article to boot to the Advanced Boot Options menu instead of pressing F8.

 

Start the domain controller in "Directory Services Restore" mode before restoring the System State:

 

  1. Reboot the system.

  2. Press F8 immediately after the power-on self-test (POST) process.

  3. Select "Directory Services Restore/Repair Mode" from the boot options, and press "Enter."
  4. Log in using the Administrator account and password stored in the SAM (Security Accounts Manager), created when Active Directory was installed. For the domain use the local computer name.

  5. Select "OK" within the "Desktop" dialog box.

 

NOTE:  Active Directory/domain administrator accounts are not available, as the Active Directory is offline. The SAM account must also be defined in UltraBac before attempting restore.

Restoring the System State Using UltraBac

With the domain controller in “Directory Services Restore” mode before restoring the System State:

 

  1. Install UltraBac with local authentication credentials.

  2. If UltraBac is already installed using domain credentials, change the credentials to the Administrator account and password in the SAM.

  1. Enter the local administrator account when prompted by UltraBac.

 

ub_93_activedirectoryrestore2_authentication.jpg

Fig. 1 - Authentication Options.

 

  1. Once the installation of UltraBac is completed, open the UltraBac Management Console.

  2. Select the Manage tab and click on the "Storage Devices" icon and define where your backup is stored and then click "Close.".

 

active_directory_restore_manage_sd.jpg

Fig. 2 - Define Storage Device Location of Backup.

 

  1. From the Restore tab select "Media" to pull up and load the backup and then click OK.

 

active_directory_restore_media.jpg

Fig. 3 - Load Backup Index.

 

  1. A prompt will open asking for the Restore Target. Select your Restore Target and click OK

 

active_directory_restore_target.jpg

Fig. 4 Restore Target

 

  1. Choose both System State and the OS partition for restore.

 

active_directory_restore_os_ss.jpg

Fig. 5 - Select OS and System State for Restore.

 

NOTE:  When restoring the System State/Active Directory, all System State components must be restored. If one component is excluded from the restore, all objects will be excluded.

 

  1. Select the "Action" icon and "Restore this Backup".

 

active_directory_restore_action.jpg

Fig. 6 - Select Restore this Backup.

 

  1. On the Restore Options screen "Restore in-use files" and "Overwrite Always" must be selected. Click Next.

 

ub_93_activedirectoryrestore2_restore_options.jpg

Fig. 7 - Restore Options.

 

  1. On the second Restore Options screen, make sure to select "Run unattended" and then click Restore..

 

active_directory_restore_options2.jpg

Fig. 8 - Restore Options second screen

 

  1. Once the restore is finished, you will get a "Confirm Reboot" screen.

 

active_directory_restore_complete.jpg

Fig. 9 - Confirm Reboot

 

  1. Click "No" or "Cancel" and an NTDSUTIL command window will open.

 

NOTE:  There is a known bug that the NTDSUTIL command window will open no matter which choice you choose.

 

  1. If you are going to do an Authoritative Restore then you will need to leave the NTDSUTIL command window open, otherwise you can type"q" in the command window to close it.

 

NOTE:  It is highly recommended to do the authoritative restore from an existing domain controller and not the one you are restoring, this way you will not lose any AD objects and changes since the last backup.

  1. A Reboot Request window will open, and click "OK".

 

active_directory_reboot_request.jpg

Fig 10 - Reboot Request

 

  1. Before going further, the next steps depend upon what level the Active Directory Schema is at, and what Operating System the Domain Controller is running.

 

2012/2012 R2/2016/2019 Active Directory Schema with Multiple Domain Controllers

2012/2012 R2/2016/2019 Active Directory Schema with a Single Domain Controller

2008/2008 R2 Active Directory Schema with Multiple Domain Controllers

2008/2008 R2 Active Directory Schema with a Single Domain Controller