Chat now with support
Chat mit Support

Recovery Manager for AD Disaster Recovery Edition 10.2 - User Guide

Overview Getting started
Permissions required to use Recovery Manager for Active Directory Recovery Manager Console Getting and using help Configuring Windows Firewall Using Computer Collections Secure Storage servers Managing Recovery Manager for Active Directory configuration Licensing
Backing up data
Permissions required for the Backup operation Managing Backup Agent Using a least-privileged user account to back up data Using Managed Service Accounts Active Directory backups vs Windows System State backups Creating BMR and Active Directory backups Using the Backup Wizard Retrying backup creation Enabling backup encryption Backing up AD LDS (ADAM) Backing up cross-domain group membership Backing up distributed file system (DFS) data Backup scheduling Setting performance options Setting advanced backup options Using Forest Recovery Agent Unpacking backups Using e-mail notification Viewing backup creation results
Restoring data
Getting started with Active Directory recovery Managing deleted or recycled objects Restoring backed up Active Directory components Integration with Change Auditor for Active Directory Using granular online restore Restoring AD LDS (ADAM) Selectively restoring Active Directory object attributes Restoring objects in an application directory partition Restoring object quotas Restoring cross-domain group membership Performing a restore without having administrator privileges Reports about objects and operations Using complete offline restore Offline restore implications Restoring SYSVOL authoritatively Performing a granular restore of SYSVOL Recovering Group Policy Restoring data from third-party backups Using the Extract Wizard Restoring passwords and SID history
Full Replication Consolidating backup registration data Monitoring Recovery Manager for Active Directory Recovering an Active Directory forest
Forest recovery overview Deploying Recovery Manager for Active Directory Forest Edition (Disaster Recovery Edition) Permissions required to use Forest Recovery Console Forest Recovery Console Managing a recovery project Recovery methods Phased recovery Managing Forest Recovery Agent Rebooting domain controllers manually Resetting DSRM Administrator Password Purging Kerberos Tickets Managing the Global Catalog servers Managing FSMO roles Manage DNS Client Settings Configuring Windows Firewall Developing a custom forest recovery plan Backing up domain controllers Assigning a preferred DNS server during recovery Handling DNS servers during recovery Forest recovery approaches Deciding which backups to use Running custom scripts while recovering a forest Overview of steps to recover a forest Viewing forest recovery progress Viewing recovery plan Viewing a report about forest recovery or verify settings operation Handling failed domain controllers Adding a domain controller to a running recovery operation Selectively recovering domains in a forest Recovering SYSVOL Deleting domains during recovery Resuming an interrupted forest recovery Recovering read-only domain controllers (RODCs) Checking forest health Collecting diagnostic data for technical support
Restore Active Directory on Clean OS Bare metal forest recovery Using Management Shell Creating virtual test environments Using Recovery Manager for Active Directory web portal Appendices
Frequently asked questions Best practices for using Computer Collections Technical characteristics Best practices for creating backups Best practices for creating backups for forest recovery Best practices for recovering a forest Descriptions of recovery or verification steps Ports Used by Recovery Manager for Active Directory Forest Edition (Disaster Recovery Edition) Backup Wizard Online Restore Wizard Online Restore Wizard for AD LDS (ADAM) Group Policy Restore Wizard Repair Wizard Extract Wizard Events generated by Recovery Manager for Active Directory Descriptions of PowerShell commands
Add-RMADBackup Add-RMADCollectionItem Add-RMADReplicationConsole Add-RMADStorageServer Backup-RMADCollection Close-RMADFEProject Compare-RMADObject Convert-RMADBackup ConvertTo-RMADRecycledObject Copy-RMADFEBackup Create-RMADStorageAgentSetup Expand-RMADBackup Export-RMADBackup Export-RMADFERecoveryCertificate Export-RMADFEResult Export-RMADSecureStorageBackup Get-RMADBackup Get-RMADBackupAgent Get-RMADBackupInfo Get-RMADBackupObject Get-RMADBackupSecurityStatus Get-RMADCollection Get-RMADCollectionItem Get-RMADDeletedObject Get-RMADFEAvailableSubnet Get-RMADFEComputer Get-RMADFEConsole Get-RMADFEDnsCache Get-RMADFEDomain Get-RMADFEEvent Get-RMADFEGlobalOptions Get-RMADFEOperation Get-RMADFEPersistenceConnection Get-RMADFEProject Get-RMADFERecoveryAgent Get-RMADFESchedule Get-RMADGlobalOptions Get-RMADLicenseInfo Get-RMADObject Get-RMADReplicationConsole Get-RMADReplicationSchedule Get-RMADReplicationSession Get-RMADReplicationSessionItem Get-RMADReportObject Get-RMADReportObjectAttributes Get-RMADReportObjectChildren Get-RMADReportSession Get-RMADSession Get-RMADSessionItem Get-RMADSessionItemEvent Get-RMADStorageServer Get-RMADStorageServerHardeningStatus Get-RMADStorageServerRetentionPolicy Import-RMADBackup Import-RMADFERecoveryCertificate Install-RMADBackupAgent Install-RMADFERecoveryAgent New-RMADCollection New-RMADFEProject New-RMADFERecoveryMedia New-RMADSchedule Open-RMADFEProject Protect-RMADSecureStorageServer Protect-RMADStorageServer Publish-RMADBackupSecurityStatus Refresh-RMADStorageServer Register-RMADSecureStorageBackups Remove-RMADBackup Remove-RMADBackupAgent Remove-RMADCollection Remove-RMADCollectionItem Remove-RMADFERecoveryAgent Remove-RMADFESchedule Remove-RMADReplicationConsole Remove-RMADReplicationSchedule Remove-RMADReplicationSession Remove-RMADStorageServer Remove-RMADUnpackedComponent Rename-RMADCollection Restore-RMADDeletedObject Restore-RMADDomainController Restore-RMADObject Resume-RMADFERecovery Save-RMADFEProject Set-RMADCollection Set-RMADFEComputer Set-RMADFEDnsCache Set-RMADFEDomain Set-RMADFEGlobalOptions Set-RMADFEPersistenceConnection Set-RMADFERecoveryMode Set-RMADFESchedule Set-RMADGlobalOptions Set-RMADReplicationConsole Set-RMADReplicationSchedule Set-RMADStorageServerRetentionPolicy Start-RMADFERecovery Start-RMADFERecoveryAgentOperation Start-RMADFEVerification Start-RMADReplication Start-RMADReportViewer Stop-RMADFEWorkflow Test-RMADSecureStorageBackup Unprotect-RMADStorageServer Update-RMADBackupAgent Update-RMADFEProject Update-RMADLicense

Forest Recovery Agent events

Forest Recovery Agent events

Event ID Event type Description
1600 Information Resetting the passwords for domain controllers.
1601 Information Resetting the Kerberos password.
1604 Information Removing metadata and the domain controllers that have not been restored.
1608 Information Starting the Active Directory reinstallation…
1609 Information The computer is being rebooted in Directory Services Restore mode.
1610 Information The computer is being rebooted in the Normal mode.
1611 Information The domain controller demotion was started.
1626 Error The Active Directory reinstallation failed. Details: %1
1627 Error The supplied backup protection password is invalid.
1628 Error The domain controller demotion failed. Details: %1
1645 Error The supplied DSRM password does not meet the password complexity requirements.
1646 Error The specified DNS server was not available.
1647 Error DC was restarted in the wrong mode (Normal). The required mode is DSRM.
1648 Error DC was restarted in the wrong mode (DSRM). The required mode is Normal.
1649 Information Invalidating the RID pool.
3101 Error Cannot access the backup file %12.
3102 Information DNS configuration completed with addresses %48.
3103 Error Cannot prepare the backup file %12. Details: %23.
3104 Information Removing the domain %50.
3105 Error Cannot remove the domain %50. Details: %23
3106 Information Domain Controller unisolation was started.
3107 Information Domain Controller isolation was started.
3108 Information Disabling the Windows Update service.
3109 Information Enabling the Windows Update service.
3110 Information Seizing FSMO roles %51.
3111 Information The RID pool value was increased from %54 to %55.
3112 Information Stopping the service %52.
3113 Information Starting the test operation. Backup path: %12; Preferred DNS servers:%48; Temp storage: %49
3114 Information Preparing the backup file. Backup path: %12; Preferred DNS servers:%48; Temp storage: %49
3115 Information Restoring from a backup %12.
3116 Error Forest Recovery Agent installation failed. Details: %23.
3117 Error Cannot access the temporary backup folder %49. Details: %23.
3118 Information Operation %3 execution was started.
3119 Information Operation %3 was completed successfully.
3120 Error Operation %3 failed. Details: %23.
3121 Error The operation %3 was canceled by the user.
3122 Information Specifying the DNS server settings. Preferred DNS Servers: %48, alternate DNS servers: %61.
3123 Error The test operation failed. See previous events for details.
3124 Information Disabling the Global Catalog server for the domain controller %6
3125 Information Enabling the Global Catalog server for the domain controller %6
3126 Information Disabling the Global Catalog server for this domain controller.
3127 Information Enabling the Global Catalog server for this domain controller.
3128 Information Resetting the trusts passwords for the domain %50.
3129 Information Resetting the password for the domain controller %6.
3130 Information DSRM password was set successfully.
3131 Error Cannot delete the copied backup file %12. Details: %23.
3132 Error Cannot delete the IPSec backup file %12. Details: %23.
3133 Error The specified DNS servers %48 are not available.
3134 Information Current IpSec rules were backed up to %12.
3135 Information Starting the Active Directory reinstallation. Administrator name: %66,replication source domain controller:%6, replica domain DNS name:%64, site name:%65, enable GC after install: %67
3136 Information BitLocker drive encryption was successfully disabled for volume %72.
3137 Error Cannot disable BitLocker drive encryption for volume %72. Details: %23.
3138 Information BitLocker drive encryption was successfully enabled for volume %72.
3139 Error Cannot enable BitLocker drive encryption for volume %72. Details: %23.
3140 Information Custom password filters were successfully enabled.
3141 Error Cannot enable custom password filters. Details: %23.
3142 Information Custom password filters were disabled successfully.
3143 Error Cannot disable custom password filters. Details: %23.
3144 Information Metadata for the domain controller %6 was successfully removed.
3145 Information Metadata removing for the domain controller %6 completed with warnings: %38.
3146 Error Cannot set the DSRM password. Details: %23.
3147 Information Password for the krbtgt account was reset successfully.
3148 Error Cannot reset the password for the krbtgt account. Details: %23.
3149 Error Cannot validate the backup file. Details: %23.
3150 Information The test operation was successfully completed.
3151 Information The Active Directory reinstallation successfully completed.
3152 Information The domain controller was successfully demoted.
3153 Information Resetting the passwords for trusts.
3154 Information Set service %52 start type to %88.
3155 Error Cannot change start type for service %52. Details: %23.
10002 Information %89 started using authentication service %90.

 

Forest Recovery Console events

Forest Recovery Console events

Event ID Event type Description
5000 Informational Forest Recovery project was created: %56
5001 Informational Forest Recovery project was updated: %56
5002 Informational Recovery project validation was started: %56. Method %63
5003 Informational Forest Recovery project %56 was successfully validated. Domain Controller: %6
5005 Error Forest Recovery project %56 validation failed. See previous events for details.
5006 Error Forest Recovery operation failed: %18. Domain Controller: %6; Details: %23
5007 Informational The recovery process was started using the following method: %63; Domain Controller: %6; Backup file: %12; Forest Recovery project %56
5008 Informational Recovery process was finished. Domain Controller: %6; Forest Recovery project %56
5010 Error Recovery process failed. See previous events for details. Domain Controller: %6; Forest Recovery project %56
5011 Informational Operation: %18 was canceled, Domain Controller %6
5012 Informational Operation: %18 was retried; Domain Controller %6
5013 Informational Operation: %18 was paused; Domain Controller %6
5014 Informational Operation %18 was unpaused, Domain Controller %6
5015 Informational %18, Domain Controller: %6
5016 Informational Forest Recovery Agent operation: %18 was finished successfully. Domain Controller %6; Version: %62
5017 Error Forest Recovery Agent operation failed: %18; Domain Controller %6; Version: %62
5018 Informational Health check was started. Active Directory Forest: %7; Forest Recovery Project %56
5019 Informational Health check was completed successfully. Active Directory Forest: %75; Forest Recovery Project %56
5020 Error Health check was failed. Domain Controller %6; Details: %23
5021 Error Scheduled project operation failed to start. Project: %56; Operation: %18; Details: %23
5022 Informational The recovery process was resumed by the Forest Recovery Console instance %95. The original console instance where the recovery process was initiated: %94.
10003 Informational Console connected to %89 on %91 using authentication service %90.

 

AD Virtual Lab events

Active Directory Virtual Lab events

Event ID Event type Description
6100 Information New Virtual Lab Project was created: Project: %56
6101 Information Virtual Lab Project was changed: Project: %56
6102 Information Virtual Lab Project successfully connected to %57 hypervisor: Address: %58; User: %66; Project: %56
6103 Error Virtual Lab Project cannot connect to %57 hypervisor. Address: %58; User: %66; Error: %23; Project: %56
6104 Information Source machine was added to the Virtual Lab Project. Machine: %59; Project: %56
6105 Information Source machine was removed from the Virtual Lab Project. Machine: %59; Project: %56
6110 Information Forest Recovery Agent was installed on %59.
6111 Error Forest Recovery Agent installation failed on %59: %23
6112 Information Forest Recovery Agent was uninstalled on %59.
6113 Error Forest Recovery Agent uninstallation failed on %59: %23
6114 Information VMware agent was installed on %59.
6115 Error VMware agent installation failed on %59: %23
6116 Information VMware agent was uninstalled on %59.
6117 Error VMware agent uninstallation failed on %59: %23
6118 Information SCVMM agent/Disk2Vhd tool was installed on %59.
6119 Error SCVMM agent/Disk2Vhd tool installation failed on %59: %23
6120 Information SCVMM agent/Disk2Vhd tool was uninstalled on %59.
6121 Error SCVMM agent/Disk2Vhd tool uninstallation failed on %59: %23
6201 Information Virtual Lab project settings were successfully verified. Project: %56
6202 Error Virtual Lab project settings verification failed: Error(s): %37; Warning(s): %38; Project: %56
6203 Warning Virtual Lab project settings verification was finished with warning(s): %38 Project: %56
6299 Warning Virtual Lab project settings verification was finished with warning(s) but it was ignored. Then the lab creation was started. Project: %56
6300 Information Virtual Lab project lab creation was started. Project: %56
6301 Error Virtual Lab project lab creation failed. Failed targets: %37; Project: %56
6302 Error Virtual machine creation failed. Machine: %59; Error: %23
6303 Information Virtual Lab creation was successfully finished. Created targets: %68; Project: %56
6304 Warning Virtual machine creation was interrupted by a user. Machine: %59
6401 Information Virtual machine network was enabled: Machine: %59; Machine: %59
6402 Error Enabling virtual machine network failed: Machine: %59; Error: %

 

Descriptions of PowerShell commands

PowerShell cmdlets for Recovery Manager for Active Directory

Cmdlet Description
Add-RMADBackup Registers a backup in the Recovery Manager database.
Add-RMADCollectionItem Adds a new item to a Computer Collection.
Add-RMADReplicationConsole Adds a RMAD console as a replication source.
Add-RMADStorageServer Adds a secure storage server, optionally remotely installs a storage server agent.
Backup-RMADCollection Backs up an existing computer collection.
Compare-RMADObject Compares Active Directory objects. This cmdlet requires Windows PowerShell to be started using a multi-threaded apartment (MTA).
Convert-RMADBackup Converts Windows Server backups into RMAD Bare Metal Recovery backups.
ConvertTo-RMADRecycledObject Recycles specific deleted Active Directory objects.
Create-RMADStorageAgentSetup Creates storage server agent setup.
Expand-RMADBackup Extracts the contents of a specified backup file.
Export-RMADBackup Exports registration information for a backup into an .xml file.
Export-RMADSecureStorageBackup Exports a backup on a Secure Storage server to a remote network share.
Get-RMADBackup Gets backups registered with Recovery Manager.
Get-RMADBackupAgent Retrieves objects that represent Recovery Manager Backup Agents, or discovers manually preinstalled Recovery Manager Backup Agents.
Get-RMADBackupInfo Gets the content of the backups held at a specified location.
Get-RMADBackupObject Get objects from backups
Get-RMADBackupSecurityStatus Gets security check information for a specified backup.
Get-RMADCollection Retrieves Recovery Manager computer collection objects or default computer collection settings.
Get-RMADCollectionItem Retrieves information about items added to specified Recovery Manager for Active Directory computer collections.
Get-RMADDeletedObject Retrieves deleted Active Directory objects.
Get-RMADGlobalOptions Sets global settings for the application.
Get-RMADLicenseInfo Retrieves information about the installed license key file.
Get-RMADObject Retrieves specific objects from Active Directory or certain backups registered with Recovery Manager for Active Directory.
Get-RMADReplicationConsole Gets all the RMAD consoles in the replication console list.
Get-RMADReplicationSchedule Allows you to get the replication schedule from a specified computer.
Get-RMADReplicationSession Retrieves information about replication sessions.
Get-RMADReplicationSessionItem Retrieves a list of remote consoles that are involved in the specified replication session.
Get-RMADReportObject Retrieves an object representing the online comparison or restore operation item.
Get-RMADReportObjectAttributes Retrieves an object representing the online comparison or restore operation item attributes.
Get-RMADReportObjectChildren Retrieves an object representing the online comparison or restore operation item child items.
Get-RMADReportSession Retrieves an object representing the online comparison or restore operation report.
Get-RMADSession Retrieves an object representing Recovery Manager backup sessions.
Get-RMADSessionItem Gets items from a specified backup creation session.
Get-RMADSessionItemEvent Gets events from a specified backup creation session item.
Get-RMADStorageServer Returns a list of registered secure storage servers.
Import-RMADBackup Reads the backup registration information from the .xml file and returns backup descriptions in the BackupInfo objects.
Install-RMADBackupAgent Installs Recovery Manager Backup Agent on a specified computer or on each computer in a particular Computer Collection.
New-RMADCollection Creates a new computer collection.
New-RMADSchedule Creates a schedule for the backup creation operation you want to perform on a particular computer collection.
Protect-RMADSecureStorageServer Enables storage server hardening.
Publish-RMADBackupSecurityStatus Publishes security check information for a specified backup.
Refresh-RMADStorageServer Refreshes current information of the secure storage server.
Register-RMADSecureStorageBackups Registers backups on an existing secure storage server in a Recovery Manager database.
Remove-RMADBackup Allows you to selectively unregister backups from the Recovery Manager backup registration database.
Remove-RMADBackupAgent Removes Recovery Manager Backup Agent from a specified computer, or its registration information from the Recovery Manager Console.
Remove-RMADCollection Deletes specified Computer Collections.
Remove-RMADCollectionItem Removes items from a specified Computer Collection.
Remove-RMADReplicationConsole Removes an RMAD console from the replication console list.
Remove-RMADReplicationSchedule Allows you to remove the replication schedule from a specified computer.
Remove-RMADReplicationSession Deletes replication sessions from the replication history.
Remove-RMADStorageServer Removes the secure storage server.
Remove-RMADUnpackedComponent Allows you to delete components (data) unpacked from specified backups.
Rename-RMADCollection Renames a computer collection.
Restore-RMADDeletedObject Restores deleted Active Directory objects. This cmdlet requires Windows PowerShell to be started using a multi-threaded apartment (MTA).
Restore-RMADDomainController Restores a domain controller from backup.
Restore-RMADObject Restores Active Directory objects from a backup. This cmdlet requires Windows PowerShell to be started using a multi-threaded apartment (MTA).
Set-RMADCollection Sets properties for a computer collection.
Set-RMADGlobalOptions Sets global application settings
Set-RMADReplicationConsole Sets replication properties of consoles in the replication console list.
Set-RMADReplicationSchedule Sets replication schedules for a computer.
Start-RMADReplication Performs replication from other computers in the replication console list.
Start-RMADReportViewer Displays a report about the results of the online comparison or restore operation.
Test-RMADSecureStorageBackup Checks the integrity of a backup on the secure storage server.
Update-RMADBackupAgent Upgrades Recovery Manager Backup Agent on a specified computer or on each computer in a particular Computer Collection.
Update-RMADLicense Updates license key file.

PowerShell cmdlets for Recovery Manager for Active Directory Forest Edition (Disaster Recovery Edition)

Cmdlet Description
Close-RMADFEProject Closes currently opened recovery project.
Copy-RMADFEBackup Copies a backup from a network share to the secure storage server.
Export-RMADFERecoveryCertificate Exports Forest Recovery certificates.
Export-RMADFEResult Export the verification result of an RMADFE project.
Get-RMADFEAvailableSubnet For internal use only.
Get-RMADFEComputer Retrieves a list of computer settings from the current RMADFE project.
Get-RMADFEConsole Gets all registered RMAD FE consoles.
Get-RMADFEDnsCache Returns cached DNS records in the Forest Recovery project.
Get-RMADFEDomain Retrieves the domain settings.
Get-RMADFEEvent Returns recovery events related to the entire Active Directory forest or a specific domain controller.
Get-RMADFEGlobalOptions Gets global application settings.
Get-RMADFEOperation Returns information about the progress of the recovery operations.
Get-RMADFEPersistenceConnection Gets persistence connection settings.
Get-RMADFEProject Gets the current status of the RMADFE project.
Get-RMADFERecoveryAgent Returns information about Forest Recovery Agents that are installed and registered in Forest Recovery Console.
Get-RMADFESchedule Gets a schedule for the RMADFE project verification.
Import-RMADFERecoveryCertificate Imports Forest Recovery certificates.
Install-RMADFERecoveryAgent Installs Forest Recovery Agent on a specified domain controller or on each domain controller in the forest.
New-RMADFEProject Creates a new RMADFE project in the file system.
New-RMADFERecoveryMedia Creates a new Recovery Media ISO in the file system.
Open-RMADFEProject Opens the RMADFE project.
Remove-RMADFERecoveryAgent Removes Forest Recovery Agent from a specified domain controller, or its registration information from Forest Recovery Console.
Remove-RMADFESchedule Removes an existing verification schedule for the RMADFE project.
Resume-RMADFERecovery Resumes recovery process.
Save-RMADFEProject Saves the RMADFE project.
Set-RMADFEComputer Applies computer settings to the RMADFE project.
Set-RMADFEDnsCache Updates cached DNS records in the Forest Recovery project.
Set-RMADFEDomain Sets the domain settings for the current RMADFE project.
Set-RMADFEGlobalOptions Sets global settings for recovery projects.
Set-RMADFEPersistenceConnection Sets persistence connection settings.
Set-RMADFERecoveryMode Sets recovery mode for the current recovery project
Set-RMADFESchedule Applies settings to the verification schedule for the RMADFE project.
Start-RMADFERecovery Performs the restore operation for the RMADFE project.
Start-RMADFERecoveryAgentOperation Starts so-called agent operation on the remote machine where Forest Recovery agent is installed.
Start-RMADFEVerification Performs verification of the RMADFE project.
Stop-RMADFEWorkflow Stops the verification or recovery workflow of the recovery project.
Update-RMADFEProject Shows the difference between the current project and live Active Directory and updates the project.

PowerShell cmdlets for Recovery Manager for Active Directory Disaster Recovery Edition Secure Storage Server

Cmdlet Description
Get-RMADStorageServerHardeningStatus Retrieves the hardening status of the current server.
Get-RMADStorageServerRetentionPolicy Retrieves the retention policy status of the current server.
Protect-RMADStorageServer Enable storage server hardening.
Set-RMADStorageServerRetentionPolicy Sets the retention policy status of the current server.
Unprotect-RMADStorageServer Disables hardening on the storage server.

 

Verwandte Dokumente

The document was helpful.

Bewertung auswählen

I easily found the information I needed.

Bewertung auswählen