E-Mail: webmaster@jawed.co.in
All the content/s are collected from the search engines and/or free resources. Please read disclaimer before using/downloading any content/stuffs or whatsoover.
All Logo/s,Trade Mark/s,Stuff/s,Content/s,Material/s,Software/s are property of their respective owner
For any query please contact at webmaster@jawed.co.in
How do you backup AD?
Backing up Active Directory is essential to maintain the proper health of the Active
Directory database. You can backup Active Directory by using the NTBACKUP tool
that comes built-in with Windows Server 2003, or use any 3rd-party tool that
supports this feature. Backing up the Active Directory is done on one or more of your
Active Directory domain Controllers (or DCs), and is performed by backing up the
System State on those servers. The System State contains the local Registry,
COM+ Class Registration Database, the System Boot Files, certificates from Certificate
Server (if it’s installed), Cluster database (if it’s installed), NTDS.DIT, and the SYSVOL
folder To ensure your ability to actually use this backup, you must be aware of the
tombstone lifetime. By default, the tombstone is 60 days (for Windows 2000/2003 DCs),
or 180 days (for Active Directory based upon Windows Server 2003 SP1 DCs).
Longer tombstone lifetime decreases the chance that a deleted object remains in
the local
directory of a disconnected DC beyond the time when the object is permanently
deleted from online DCs. The tombstone lifetime is not changed automatically
when you upgrade to Windows Server 2003 with SP1, but you can change the
tombstone lifetime manually after the upgrade. New forests that are installed
with Windows Server 2003 with SP1 have a default tombstone lifetime of
180 days. Read my "Changing the Tombstone Lifetime Attribute in Active Directory"
article for more info on that. Any backup older than 60/180 days is not a good
backup and cannot be used to restore any DC. You do not need to backup all your
DCs' System States, usually backing up the first DC in the Forest + the first DCs
in each domain is enough for most scenarios. Purpose of Performing Regular
Backups You need a current, verified, and reliable backup to: • Restore Active
Directory data that becomes lost. By using an authoritative restore process, you
can restore individual objects or sets of objects (containers or directory
partitions) from their deleted state. Read my "Recovering Deleted Items in Active
Directory" article for more info on that.
• Recover a DC that cannot start up or operate normally because of software
failure or hardware failure. • Install Active Directory from backup media (using the
dcpromo /adv command). Read my "Install DC from Media in Windows Server 2003"
article for more info on that.
• Perform a forest recovery if forest-wide failure occurs. All these are reasons to
have good working and reliable backups.
Note: One of the Active Directory features that was introduced in Windows
Server 2003 with Service Pack 1 was the Directory Service Backup Reminders.
With this reminder, a new event message, event ID 2089, provides the
backup status of each directory partition that a domain controller stores.
This includes application directory partitions and Active Directory
Application Mode (ADAM) partitions. If halfway through the tombstone
lifetime a partition has not been backed up, this event is logged in the
Directory Service event log and continues daily until the partition is backed up.
Note: You can only back up the System State data on a local computer.
You cannot back up the System State data on a remote computer.
For Question & Answer on Application Partition, DC- Backup, Sysvol etc. click here
For Question & Answer on DHCP and Its process etc. click here
For Question & Answer on IP Address,
Subnet Mask, ARP etc. click here
For Question & Answer on DNS, DNS Zones etc. click here
For Question & Answer on DNS, DNS Zones and AD etc. click here
For Question & Answer on Windows Clustering , NLB, WINS click here
For Question & Answer on IAS & RAS, PAT, NAT, VPN click here
For Question & Answer on Domain, DC, Active Directory and its features etc. click here
For Question & Answer on LDAP,AD- Structure & Namespace etc. click here
For Question & Answer on Application Partition, DC- Backup, Sysvol etc. click here
For Question & Answer on Recovery/Restore of DC & GC etc. click here
For Question & Answer on Global Catalog, REPLMON. LDP, ADSIEDIT etc. click here
For Question & Answer on Netdom, Sites, KCC, ISTG etc. click here
For Question & Answer on FSMO and its roles etc. click here
For Question & Answer on Active Directory (AD) & its backup etc. click here
For Question & Answer on GPO, GPC and GPT etc. click here