UltraBac System State/Active Directory Restore with Windows Server 2008/2008 R2

Prerequisites for Full Operating System Restore

 

Restoring the System State Using UltraBac

Once you have completed the first part of the restore under Restoring the System State Using UltraBac then you will complete the restore depending upon the Active Directory Schema level and the Domain Controller Operating System.

 

Since restore methodologies differ depending on the Active Directory Schema you set up at the time of backup, please review the following sections to find the appropriate restore procedure to continue with the restore

 

2008/2008 R2 Active Directory Schema with Multiple Domain Controllers

2008/2008 R2 Active Directory Schema with a Single Domain Controller

2003/2003 R2 Active Directory Schema with Multiple Domain Controllers

2003/2003 R2 Active Directory Schema with a Single Domain Controller

 

NOTE:  The Windows Service Pack at the restore target must be the same as that of the original machine at the time of backup.

 

2008/2008 R2 Active Directory Schema with Multiple Domain Controllers.

NOTE:  It is highly recommended to do the authoritative restore from an existing domain controller and not the one you are restoring, this way you will not lose any AD objects and changes since the last backup.

NOTE:  Only do these steps on Windows Server 2008 / 2008 R2 / 2012 / and 2012 R2 domain controllers. Do NOT do these registry entries on any Windows Server 2016 or 2019 domain controllers or it will cause a USN rollback error on the domain controller. For Windows Server 2016 and 2019 domain controllers, they are by default already in a non-authoritative mode, and to make authoritative you would use the instructions for NTDSUTIL authoritative restore.

 

  1. Stop the DFSR Service on all domain controllers.

  2. Start the Registry Editor.

  3. Navigate to "HKLM\SYSTEM\CurrentControlSet\Services\DFSR."

  4. Create a key called "Restore."

  5. Create a string value called "SYSVOL."

 

On one of the existing domain controllers:

 

  1. For the string value called "SYSVOL," give it the value of "authoritative."

 

ub_93_activedirectoryrestore2_registry_options.jpg

Fig. 3 - Registry Options.

 

On the remaining domain controllers:

 

  1. For the string value called "SYSVOL," give it the value of "non-authoritative."

 

ub_93_activedirectoryrestore2_restore_options2.jpg

Fig. 4 - Registry Options.

 

  1. Navigate to "HKLM\SYSTEM\CurrentControlSet\Control\BackupRestore."

  2. Create a key called "SystemStateRestore."

  3. Create a string value called "LastRestoreId."

  4. For the string value called "LastRestoreId" give it the value of "10000000-0000-0000-0000-000000000000".

 

ub_93_activedirectoryrestore2_restore_options3.jpg

Fig. 5 - Registry Options.

 

Once the registry settings have been put into place, you must start the DFSR service on the domain controller that was made authoritative, and then on each of the other domain controllers.

 

To verify the restore was successful, open Windows PowerShell and type <repadmin/showrepl>.

 

ub_93_activedirectoryrestore2_repadmin.jpg

Fig. 6 - Repadmin example.

 

You should see a screen similar to the one above showing all connections as successful.

Once everything has been restored, it is highly recommended to remove the registry settings you entered above.

2008/2008 R2 Active Directory Schema with a Single Domain Controller.

  1. Stop the DFSR service.

  2. Start the Registry Editor.

  3. Navigate to "HKLM\SYSTEM\CurrentControlSet\Services\DFSR."

  4. Create a key called "Restore."

  5. Create a string value called "SYSVOL."

  6. For the string value called "SYSVOL," give it the value of "non-authoritative."

 

ub_93_activedirectoryrestore2_restore_options2.jpg

Fig. 7 - Registry Options.

 

  1. Navigate to "HKLM\SYSTEM\CurrentControlSet\Control\BackupRestore."

  2. Create a key called "SystemStateRestore."

  3. Create a string value called "LastRestoreId."

  4. For the string value called "LastRestoreId" give it the value of "10000000-0000-0000-0000-000000000000."

 

ub_93_activedirectoryrestore2_restore_options3.jpg

Fig. 8 - Registry Options.

 

  1. Once the registry settings have been put into place, you must then start the DFSR service.

 

NOTE:  It is highly recommended to remove the registry settings you entered above after restore is completed.

2003 Active Directory Schema with Multiple Domain Controllers

NOTE:  It is highly recommended to do the authoritative restore from an existing domain controller and not the one you are restoring; this way you will not lose any AD objects and changes since the last backup.

 

  1. Stop the NTFRS Service on all domain controllers.

  2. Start the Registry Editor.

  3. Navigate to “HKLM\System\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup."

  4. Double click on "BurFlags."

 

On one of the existing domain controllers that will be the "authoritative" Domain Controller:

 

  1. Assign it a value of D4 (hex) or 212 (dec).

 

ub_93_activedirectoryrestore2_restore_options4.jpg

Fig. 9 - Registry Options.

 

On the remaining domain controllers that are "non-authoritative":

 

  1. Assign it a value of D2 (hex) or 210 (dec).

 

Once the registry settings have been put into place, you must start the NTRFS service on the domain controller that was made authoritative, and then on each of the other domain controllers.

 

To verify the restore was successful, open up Windows PowerShell and type <repadmin/showrepl>.

 

In the power shell window you should see all connections as successful.

 

Once everything has been restored, it is highly recommended to remove the registry value from the "BurFlags" registry key you entered above.

2003 Active Directory Schema with a Single Domain Controller

  1. Stop the NTFRS Service.

  2. Start the Registry Editor.

  3. Navigate to "HKLM\System\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup."

  4. Double click on "BurFlags."

  5. Assign it a value of D2 (hex) or 210 (dec).

 

Once the registry settings have been put into place, you must start the NTRFS service. Once everything has been restored, it is highly recommended to remove the registry value from the "BurFlags" registry key you entered above.