Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell NetWorker 19.9 Administration Guide

Performing post-recovery tasks for Active Directory services

Perform the offline recovery of the DISASTER_RECOVERY:\ component save sets if there is a non-authoritative domain controller. If a non-authoritative recovery is wanted, then no additional steps are required. However, if you must perform an authoritative recovery, follow these steps.

  1. To exit the wizard so that you can start into Directory Services Restore Mode (DSRM), on the System Recovery Results screen of the NetWorker Bare Metal Recovery wizard, select Exit.
    NOTE:Do not select Reboot in the wizard. Failure to start into DSRM mode results in a non-authoritative recovery. If you select Reboot, perform one of the following:
    • On restart, start the system in the WinPE operating system instead of the restored operating system.
    • Run the Windows BMR wizard again and ensure that you select Exit.
    The WinPE command prompt appears.
  2. At the WinPE command prompt, type the following bcdedit commands.
    1. To force the system to start into DSRM, add a boot loader entry:
      bcdedit /copy {default} /d “Directory Service Repair Mode”

      A message similar to the following appears:

      The entry was successfully copied to {00000000-0000-0000-0000-000000000000}

      The numbers and dashes in the previous message form a Globally Unique Identifier (GUID) that identifies a new entry. In this example, the GUID is for illustration purposes only. The actual GUID that is generated when you run the command is unique.

    2. To set the safeboot option for the bootloader entry in the BCD store, type the following command using the generated GUID:

      bcdedit /set {GUID_value} safeboot dsrepair

      where GUID_value is the GUID displayed by the previous bcdedit command.

    3. To restart the system, exit the WinPE command prompt.
      NOTE:Failure to start into DSRM results in a non-authoritative recovery.
  3. (Optional) If you have a WINDOWS ROLES AND FEATURES:\ Active Directory subcomponent save set that is newer than the DISASTER_RECOVERY:\ save set used in the preceding BMR, you can recover the save set in DSRM through the NetWorker User program.
  4. From the WinPE command prompt, run the Windows ntdsutil utility.

    The ntdsutil prompt appears. The ntdsutil utility is a command interface similar to the NetWorker recover interface. For help with the ntdsutil utility, type:

    NTDSUTIL: ?

  5. At the ntdsutil prompt, type:

    NTDSUTIL: activate instance ntds
    NTDSUTIL: authoritative restore

  6. To perform an authoritative recovery of a subtree or individual object, type:

    NTDSUTIL: restore subtree “distinguished_name”

    For example:

    NTDSUTIL: restore subtree “OU=engineering,DC=Seattle,DC=jupiter,DC=com”
    NTDSUTIL: restore subtree “CN=mars,CN=users,DC=Seattle,DC=jupiter,DC=com”

    The Microsoft Windows Server Resource Kit documentation on Active Directory provides information.

  7. Exit the ntdsutil utility by typing quit at each successive ntdsutil prompt until the command prompt appears.
  8. Type the following command at the WinPE command prompt so that the host does not start into DSRM mode on restart.

    bcdedit /deletevalue safeboot

  9. Restart the domain controller in normal mode, log in, and then verify that the authoritative changes are replicated to the Active Directory replication partners.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\