These release notes provide information about the Quest® Recovery Manager for Active Directory 10.3 release.
Recovery Manager for Active Directory enables fast, online recovery. Comparison reports highlight what objects and attributes have been changed and deleted in Active Directory enabling efficient, focused recovery at the object or attribute level. Accurate backups and a quicker recovery enable you to reduce the time and costs associated with AD outages and reduce the impact on users throughout your organization.
Recovery Manager for Active Directory is based on patented technology.
Recovery Manager for Active Directory 10.3 is a release with new features and functionality. See New Features and Enhancements.
This section covers new features and enhancements in Quest® Recovery Manager for Active Directory 10.3.
New feature to backup your Recovery Manager for Active Directory (RMAD) Console settings and project files, allowing you to quickly reinstall the product and restore its configuration to the last backed up state in case RMAD becomes inoperable due to a failure. Additionally with a backed up RMAD console configuration file you can install a new Recovery Manager for Active Directory Disaster Edition Forest Recovery console on a new host. This is useful for adding another RMAD console.
The Directory Services Restore Mode (DSRM) can be paused during recovery. Recovery Manager for Active Directory now has advanced actions that can be performed during the pause step, including an option to run a script, quarantine files and define custom rules for handling of malicious files.
Recovery Manager for Active Directory now supports integrity checks for Active Directory® backups. This new capability in Recovery Manager for Active Directory ensures that integrity checks are automatically performed when a backup is registered and integrity checks can be configured to be performed after a scheduled backup.
Before starting a forest recovery operation, you should specify a method for selecting a preferred DNS server for each domain controller in your recovery project. Recovery Manager for Active Directory 10.3 has enhanced these methods and how the preferred DNS server is automatically detected.
Recovery Manager for Active Directory integration with On Demand Recovery enables the restoration and undelete of on-premises objects that are synchronized with Azure Active Directory. The RMAD Hybrid Connector service has been updated to no longer use SQL Server® for Hybrid configuration and the TLS v1.2 protocol is now being enforced when communicating with On Demand Recovery.
NOTE |
With the removal of the SQL Server® for the Hybrid configuration, after upgrade to 10.3 it is required to re-enter credentials for each domain listed under Discovered Domains. |
Recovery Manager for Active Directory 10.3 has updated the default properties for all new computer collections. The option to Use preinstalled Backup Agent is now selected by default as this is the recommended practice for management of the backup agent. The option Automatically configure Windows Firewall and Ensure Forest Recovery Agent is deployed are not selected by default. It is highly suggested to review selected options on existing computer collections.
Support for agent based restore with LSA protection for Windows 2022.
Full support for OAuth2 authentication method for email notifications. Required due to deprecation of basic authentication for Exchange Online.
Enhancement | ID (old) | Azure DevOps |
---|---|---|
Recovery Manager for Active Directory 10.3 | ||
Salting mechanism for forest recovery project password hashes | N/A | 412667 |
Show AD tombstone lifetime settings somewhere in a product UI | N/A | 353685 |
Allow for password complexity | N/A | 253917 |
BackupAgent does not respect global logging setting 'Create a new set of log files: Never' on the DC side. | N/A | 381957 |
TLS 1.2 - Enforce in Hybrid Connect Service for communication to On Demand | N/A | 384624 |
Recovery Manager for Active Directory 10.2.2 Hotfix 2 | ||
Support for OAuth2 authentication method for email notifications. Required due to deprecation of basic authentication for Exchange Online | N/A | 384541 |
Recovery Manager for Active Directory 10.2.2 | ||
Improve message the error while creating remote DCOM object failed because "Access is denied" | N/A | 263396 |
Cannot restore a user from a backup that requires credentials for accessing it | N/A | 267022 |
Support GMSA account type to run PS custom script (Agent side only) | N/A | 317648 |
Installation option for hybrid service in the main product setup | N/A | 346507 |
New hybrid configuration Powershell API | N/A | 346513 |
Installer check updated for .NET 4.8 | N/A | 349988 |
Full support for GMSA accounts for RMAD DRE/FE/Standard | N/A | 352707 |
Support for Windows 2022 with exceptions. See User Guide | N/A | 363862 |
Recovery Manager for Active Directory 10.2.1 | ||
Usability improvements to the Computer Collections Properties dialog including removal of Logging tab and introduction of new tab for Secondary Storage | N/A | 283362 |
Creation of Management Shell Guide which lists all available PowerShell® cmdlets, with examples. Appendix removed from User Guide | N/A | 275100 |
Recovery Manager for Active Directory 10.2 | ||
Rename system state backups to Active Directory® backups | RMADFE-3009 | 218405 |
Hide the "Components" tab in computer collection settings | RMADFE-3042 | 218415 |
SCOM 2019 support | N/A | 219783 |
Pass through Synchronize across time zones from windows task scheduler to RMAD | RMADFE-952 | 220703 |
Create Logs Daily to be on by default | N/A | 223980 |
Display operating system version for all backups | N/A | 228741 |
Resolved Issues | ID (old) | Azure DevOps |
---|---|---|
Recovery Manager for Active Directory 10.3 | ||
Online Restore Wizard: Reporting on Unchanged Objects | N/A | 377277 |
Incorrect email subject message after unsuccessful/incomplete recovery | N/A | 406720 |
Computer Column - Timing column for the backup jobs to assist users in estimating job lengths | N/A | 351058 |
When the Additional path is offline, then a job that's only using local-storage completes with a warning. With Remote Storage, the job fails with an error. | N/A | 370690 |
ISO boot fails with a BSOD on Windows 2022 lab. To fix the issue, you need to add the latest cumulative update (any update after 7C-KB5015879) into WinRE.wim. Download the LCU September 13, 2022 — KB5017316 (OS Build 20348.1006) (microsoft.com). See the Quest Knowlege Base article KB4368806 for commands that need to be run. | N/A | 376632 |
Online Restore Wizard Directory object not found when restoring with old 2012 R2 backup to 2019 DC | N/A | 380226 |
Issue with install - invalid SQL hostname during install/upgrade | N/A | 388182 |
FSMO Roles are not displayed in the recovery report after restore | N/A | 376235 |
Tab order on SQL Installer page is wrong | N/A | 397266 |
Recovery Manager for Active Directory 10.2.2 Hotfix 3 | ||
RMAD fails to perform backups when using GMSA account after Microsoft Patch applied KB5022289 \ KB5022286 | N/A | 406231 |
Recovery Manager for Active Directory 10.2.2 Hotfix 2 | ||
Include product name and version to the self-extracted installation package | N/A | 367930 |
Remove Autorun from build, CD package | N/A | 380288 |
Email notifications to O365 email is not supported when Basic Authentication disabled on tenant | N/A | 386176 |
RMAD Console crashes when recovering SYSVOL from a backup using Repair Wizard | N/A | 388796 |
SCOM: computer collection and RMAD instances are in not monitored health state | N/A | 393392 |
Option to "Repair" an installation is grayed out | N/A | 383571 |
Online restore wizard does not work on Windows 2016 with LSA protection and Secure Boot enabled | N/A | 226670 |
Online restore wizard does not work on Windows 2022 with agent based restore and with LSA protection enabled | N/A | 367163 |
Recovery Manager for Active Directory 10.2.2 Hotfix 1 | ||
Restore-RMADDeletedObject cmdlet crashes when it's used without explicitly specified credentials | N/A | 382646 |
Domains that are not synced with Azure AD should be present in the list of discovered domains but should not cause error (require credentials) while saving the configuration | N/A | 380628 |
Cannot save ODR integration settings in RMAD due to an old forest/dc listed in discovered domains | N/A | 380625 |
Offline Restore Wizard fails with Access Denied to install Offline Restore Agent | N/A | 375451 |
Setup folder does not include .NET 4.8 after changing product requirement | N/A | 373180 |
Full replication between two consoles is failing with 'The given key was not present in the dictionary' error | N/A | 322095 |
Recovery Manager for Active Directory 10.2.2 | ||
RMAD replication doesn't work with Group Managed Service Account (gMSA) configured for console connection | RMADFE-2594 | 242195 |
gMSA cannot be used when setting up replication | RMADFE-2519 | 242560 |
Use a gMSA account from one domain as the agent account for backing up DCs in a different domain does not work | N/A | 265197 |
RMAD not finding backups requested by ODR in different timezones | N/A | 316404 |
BackupAgent does not respect global logging setting "Create a new set of log files: Never" | N/A | 322747 |
Update DisksInfoProvider to be more current and ignore unnecessary drive types | N/A | 323924 |
ERDiskAD.mdb does not get imported, gets overwritten by blank rmad.db3 when installing the new version. | N/A | 352421 |
A v10.2.1 pre-installed backup agent fails when backup is requested by a v10.1.1 console | N/A | 353765 |
Updating backup agent fails if custom port is configured. | N/A | 354851 |
Global settings dialog has a slightly broken layout on several tabs | N/A | 358457 |
RMAD Console - Replication: Backup information is not being cleaned out of the console when it no longer exists on source | N/A | 359553 |
RMAD Console: Diagnostic Logging drop-down reverts to Global Settings when enabled within Advanced settings of Computer Collection | N/A | 363140 |
Installer log messages are truncated | N/A | 364258 |
Recovery Manager for Active Directory 10.2.1 Hotfix 2 | ||
RMAD Console Replication error (XML error) during replication when backup runs on master console | N/A | 351462 |
Cleanup of metadata during restore of an unprotection object failed from accidental deletion | N/A | 354567 |
RMAD Console: Diagnostic Logging drop-down reverts to Global Settings when enabled within Advanced settings of Computer Collection | N/A | 363140 |
RMAD build 10.2.1.36279 will not install and triggers MS Defender notification | N/A | 366313 |
Recovery Manager for Active Directory 10.2.1 Hotfix1 | ||
Error with diagram explaining Change Auditor integration | N/A | 323348 |
GMSA workflow in the documentation is reportedly missing steps | N/A | 325726 |
Cannot retry a snapshot if certain errors occurred while creating a backup | N/A | 330733 |
Recovery Manager for Active Directory 10.2.1 | ||
Allow to unselect Console storage immediately as alternative has been configured | N/A | 220573 |
Large number of scheduled tasks can cause Console, Replication and PowerShell cmdlets to be extremely slow | RMADFE-1837 | 242166 |
Remove a BOM prefix from the script file | N/A | 257798 |
Unpacking the backup and the retention policy may fail if the DC cannot be accessed via LDAP from the RMAD console machine | N/A | 279431 |
RPC calls to Backup Agent are not retried on RPC_S_SERVER_TOO_BUSY error | N/A | 314812 |
Misleading 'Unable to map the network share IPC$ on the computer' error message on attempt to map UNC share | N/A | 316902 |
Installation fails with an invalid error message when using a local windows credential to connect to the remote SQL server | N/A | 317818 |
Online Restore Wizard cannot undelete an object using a non-administrative account. Restoring an object in Online Restore Wizard using a non-administrative account may result in the following error for NT-Security-Descriptor attribute: "Cannot retrieve attribute value(s) from Active Directory. Possible reason: Insufficient access rights." To ignore this error, the NT-Security-Descriptor attribute can be excluded from the list of restored attributes. |
N/A | 293311 |
Recovery Manager for Active Directory 10.2 Hotfix 1 | ||
Installation of Quest personal certificates to the local certificate store failed. Receive error message to install Quest certificates later. This should not be required. | N/A | 274643 |
Computer Collection scheduled tasks removed after upgrade to 10.2 if gMSA used as the scheduled task account | N/A | 280854 |
rmad.db3 file gets overwritten during an uninstall -> install of version 10.2 | N/A | 283069 |
Cannot retain the uncheck "Global Catalog Servers" option in the Advanced tab of the Computer Collection properties window | N/A | 230397 |
It will display 'Network access is denied' error in Win2016/2019 if specify account to restore GPO with "domain\username" format | N/A/ | 233623 |
Cannot see some advanced objects in the object picker in Online Restore Wizard | N/A | 275027 |
Recovery Manager for Active Directory 10.2 | ||
Security Vulnerability - Sensitive comments embedded within client-side code sent to an end user machine | RMADFE-3244 | 218142 |
Security Vulnerability - Runtime hardening (SEP, ASLR and other) | RMADFE-3248 | 218146 |
Full replication fails when a DC is selected for the option 'Unpack each backup upon its creation' in the master console | RMADFE-1858 | 218500 |
Storage agent settings are not applied on install | N/A | 219910 |
No progress/wait indication after clicking 'OK' on the 'Add Console…' dialog | N/A | 224321 |
Backup fails if the Domain Controllers OU has a AzureADKerberos computer object in it as part of Azure AD FIDO deployment | N/A | 227903 |
Improve documentation with information on number of scheduled computer collections for optimal performance | N/A | 232614 |
Access Violation in the ProcessRequest function and crashes service | N/A | 232682 |
Remove mutual exclusion mechanism between replication process and restore process | RMADFE-1575 | 237972 |
Display correct backup info and support restore for Collections with containers (not DCs) | N/A | 240580 |
Retriable VSS error causes undefined behavior in Backup Agent on retry | N/A | 241825 |
Modify the configuration to remove collision problems with SHA1, moved to SHA256 | N/A | 253913 |
Retention policy ignores collection and consider backups of all collections | N/A | 259645 |
Recovery Manager for Active Directory fully supports Transport Layer Security (TLS) 1.2. It is recommended that you upgrade to TLS 1.2 for secure communications.
Security Resolved Issue | ID (old) | Azure DevOps |
---|---|---|
Recovery Manager for Active Directory 10.3 | ||
Salting mechanism for forest recovery project and ADVL project password hashes | N/A | 412667 |
Enforce password complexity on Forest Recovery project | N/A | 253917 |
TLS 1.2 - Enforce in Hybrid Connect Service for communication to On Demand | N/A | 384624 |
Recovery Manager for Active Directory 10.2.1 | ||
Do not use SHA1 for key derivation function to generate hash for creation of AES-256 key for backup encryption |
--- | --- |
© ALL RIGHTS RESERVED. Términos de uso Privacidad Cookie Preference Center