不使用 Windows 备份的 Windows 2016 Active Directory 还原
我一直在网上阅读如何在需要时恢复广告,并使用DSRM和Windows备份理解该过程。这是我的问题,如果您不使用Windows备份,但是第三方解决方案却不知道广告,只能备份文件。如果DSRM没有网络访问权限,如何使用DSRM还原NTDS.DIT文件?
提前致谢...
I have been reading online how to restore AD if ever needed and understand the process using DSRM and Windows Backups. Here is my question, what if you are not using Windows backup, but a third party solution that is not AD aware and only backing up files. How do you restore the NTDS.dit file using DSRM if DSRM do not have network access?
Thanks in advance...
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
•由于DSRM是Windows Server,并且 AD角色特定的内置实用程序,默认情况下,它使用备份实用程序,即域控制器上的广告服务。它的唯一条件是必须启用至少系统状态备份才能使DC能够将服务器还原为以前的状态。因此,在DSRM模式下,只有Windows Server备份实用程序起作用,而没有其他功能。因此,一旦使用DSRM实用程序恢复了广告服务,我建议您通过特定于AD的备份实用程序来恢复AD的其他配置,即IE,Manage Engeengine的Active Directory备份和恢复工具。有关其设置的更多详细信息,请参阅下面的详细信息: -
https://www.manageengine.com/ad-recovery-manager/active-directory-backup-tool.html
•当启用dsrm(目录服务restore模式)时,域控制器在< strong>离线模式,即,默认情况下,其网络接口卡被禁用,因此,它无法远程访问任何备份文件。因此,在这种情况下,您应该将最新且最新的未更改的备份文件放置在域控制器本身上本地的驱动器位置上,将包含'ntds.dit'文件包含在域控制器本身上,并通过正常启动并访问远程网络位置存储相关文件并将其复制/移动到本地可访问的驱动器/目录位置上的域控制器。然后,进入DSRM模式并访问备份文件并在域控制器上再次恢复备份文件肯定会帮助您再次实现广告服务。
•此外,在DSRM模式下,域控制器被脱机,被视为成员服务器,如果在其上也安装了DNS角色,那么DC很难搜索另一个由于DNS服务无法访问,网络上的远程位置。在这种情况下,您可以使用网关/路由器的 IP地址浏览网络以获取备份文件的任何位置。
•有关在DSRM模式下还原广告服务的详细步骤,请参考以下链接: -
https://redmondmmag.com/articles/2015/08/12/restore-active-directory-directory-system-states.aspx.aspx
另外,请参考官方下面的文档链接以获取有关配置一个Active Directory服务和注意事项的详细信息: -
https://learn.microsoft.com/en-us/windows-server/windows-server/indity/endity/ad-ds/manage/ad-forest-forest--forest--恢复确定性 - 回归
• As DSRM is a Windows Server and AD role specific in-built utility, it by default uses the backup utility, i.e., Windows Server Backup or wbadmin role configuration for restoring the AD services on a domain controller. Its only condition is that atleast system state backup must be enabled for the DC to be able to restore the server to its former state. Thus, in DSRM mode, only Windows Server Backup utility works and no others. So, once the AD services are restored using the DSRM utility, I would recommend you restore the other configurations of AD through a backup utility specific for AD, i.e., Manageengine’s Active Directory Backup and Recovery tool. For more details on its setup, please refer to the details below: -
https://www.manageengine.com/ad-recovery-manager/active-directory-backup-tool.html
• When DSRM (Directory Services Restore Mode) is enabled, the domain controller goes in offline mode, i.e., its network interface card is disabled by default due to which, it is unable to access any backup file remotely. Thus, in this case, you should place the latest and recent unaltered backup file containing the ‘NTDS.dit’ file on a drive location locally on the domain controller itself by booting it up normally and accessing the remote network location where the concerned file is stored and copying/moving it onto the domain controller on a suitable accessible drive/directory location locally. Then, going into the DSRM mode and accessing the backup file and restoring it again on the domain controller will surely help you bring back the AD services live again.
• Also, during DSRM mode, the domain controller is taken offline and is considered as a member server due to which if DNS role is also installed on it, then it becomes difficult for the DC to search for another remote location on the network due to DNS service being unaccessible. In this case, you can use the IP address of the gateway/router to browse through the network for any location of the backup file.
• For detailed steps to restore the AD services during the DSRM mode, kindly refer to the below link: -
https://redmondmag.com/articles/2015/08/12/restore-active-directory-system-states.aspx
Also, please refer to the official documentation link below for details on recovering the Active Directory services and considerations while configuring one: -
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/ad-forest-recovery-determine-how-to-recover