You can restore individual objects using the Online Restore feature of RMAD. Alternatively, you can restore the entire Active Directory® database, and then select individual objects for authoritative restore.
While RMAD supports both methods, online restore is the recommended option as it is faster and simpler. The online restore method allows you to easily restore individual directory objects and object attributes without restarting domain controllers and putting Active Directory® offline, thus achieving near-zero downtime.
The RMAD online restore method facilitates the restoration of objects and objects attribute values, without putting Active Directory® offline. The product can:
Recover deleted objects with all their attributes and links by using the functionality provided by Microsoft’s Active Directory® Recycle Bin feature.
Convert the tombstones into regular objects before applying the attribute values held in the backup.
In the latter scenario, Active Directory retains the object’s tombstone for a specified configurable period of time (tombstone lifetime) in order to enable Active Directory® replication to propagate the deletion. An object can only be undeleted if its tombstone exists. After applying the backed-up attribute values, the online restore process adjusts replication-related properties of the restored objects, so that Active Directory® replication propagates the restored data to all domain controllers. Optionally, online restore can force replication of the restored data to decrease propagation delay.
When Microsoft’s Active Directory® Recycle Bin feature is enabled in the Active Directory® forest, RMAD can use the functionality provided by Microsoft’s Active Directory® Recycle Bin feature to undelete the object with all its attributes and links to the state the object was in immediately before deletion. No backups required in this recovery scenario.
In other recovery scenarios, when Microsoft’s Active Directory® Recycle Bin feature is disabled or not supported, RMAD first restores all the attributes preserved in the object’s tombstone. The remaining attributes are then restored from backup. If the backed-up value of an attribute differs from the value restored from the tombstone, then the backed-up value is restored. As a result, after the recovery operation completes, the restored object has the same attribute values, group memberships, and security descriptor as it had when the backup was created.
It is possible to determine which attributes are preserved in object tombstones by analyzing the AD schema. In such attributes, the third bit in the searchFlags property is set to 1. You can therefore enumerate these attributes using a filter that contains a matching rule such as the following:
searchFlags:1.2.840.113556.1.4.803:=8
An online restore is authoritative meaning that Active Directory® replication updates all domain controllers with the restored data. However, online restore includes some additional functions. This method is designed to overcome the limitations inherent in a normal authoritative restore performed using Windows tools. These limitations are as follows:
Domain controllers must be restarted in Directory Services Restore mode, and the entire Active Directory® database must be restored.
When restoring an object, you must restore all attributes, which may overwrite valuable data stored in the object.
When restoring a container, you must restore the entire sub-tree rooted in that container. There is no ability to restore only child objects of certain types.
To restore an object’s linked attributes, you need to restore both the object, and all objects to which the linked attributes refer; for example, if you only restore a deleted user, the user’s group memberships are not restored.
It is not possible to select individual objects for restore based on changes that occurred in Active Directory® since backup creation.
To overcome these limitations, the online restore method includes the following capabilities:
Selective restoration of objects without putting Active Directory® offline, and without restoring the entire Active Directory database.
Selective restoration of attribute values in directory objects; this allows you to specify exactly what object data should be restored.
Selective restoration of child objects by object type. This allows you, for example, to restore only those users in a certain container and leave other child objects intact.
Unattended restoration of linked attributes, such as the Member Of attribute. For example, when you undelete a user with online restore, the user’s group memberships are also restored.
Comparison of a backup with Active Directory®, or with another backup, to facilitate Active Directory® change tracking and troubleshooting: this allows you to select precisely the objects that should be restored.
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center