Three ways to recover data

  
                

As an internal network administrator, it is inevitable that there will be accidents in the daily maintenance of the AD Active Directory. How to solve this inevitable accident? Avoid the loss for the current production environment, internal network management The first time you can restore the lost user data, this tutorial will explain to you how to recover the data:

Method 1 (unauthorized restore): use the ntbackup tool by pre-backing up system state data Restore all user accounts and OUs.

Method 2 (authorized restore): Restore the deleted user accounts using the ntbackup tool by using the system state data backed up in advance, and then use Ntdsutil to perform the authoritative restore.
< The Ntdsutil syntax is as follows (refer to the Microsoft Knowledge Base):

ntdsutil "authoritative restore" "restore object

For example, to delete a user in the Mayberry OU of the Contoso.com domain JohnDoe performs an authoritative restore using the following command:

ntdsutil "authoritative restore" "restore object cn=John Doe,ou=Mayberry,dc=contoso,dc=com" qq

To perform an authoritative restore of the deleted security group ContosoPrintAccess in the Mayberry OU of the Contoso.com domain, use the following command:

ntdsutil "authoritative restore" "restore object cn=ContosoPrintAccess,ou=Mayberry,dc=contoso,dc=com" qq

For example, to delete the Mayberry OU in the Contoso.com domain User JohnDoe performs an authoritative restore using the following command:

ntdsutil "authoritative restore" "restore object cn=JohnDoe,ou=Mayberry,dc=contoso,dc=com" qq

To perform an authoritative restore of the deleted security group ContosoPrintAccess in the Mayberry OU of the Contoso.com domain, use the following command:

ntdsutil "authoritative restore" "restore object cn=ContosoPrintAccess,ou=Mayberry,dc =contoso,dc=com" qq

Method 3 (Restore with third-party tools without backing up the system state):

Using the adrestore.exe tool Now:

Step 1: Download the adrestore tool

Step 2: At the command prompt on the DC, type: "drestore the first letter of the username " to see the missing user The data.

Step 3: Continue to use the first letter of the "drestore -r username on the DC" to restore

*Note* This restore method is restored back The user is disabled, you need to reset the password to patch the login name, and cancel the disable to use normally. So it is recommended that you do a backup of the system state. Use the official authorization method.

Add a reset restore mode administrator Password method:

Log in using the administrator on the DC and enter the command prompt.

Step 1: Ntdsutil

Step 2: set dsrm password

Step 3: reset password . server server name

In enterprises that use domain environment for IT management, the data of AD Active Directory is crucial. For this reason, whether you are an internal network or not Administrators should take a good look at the number of recoveries in this tutorial. Method.

Copyright © Windows knowledge All Rights Reserved