Skip to main content
Solved

Commvault's new Active Directory Forest-level recovery support

  • November 7, 2024
  • 4 replies
  • 406 views

Forum|alt.badge.img+6

I found this video: 

 
It seems very intresting to us, has anyone seen any documentation about this new feature?

I could not find any.

Best answer by Mohamed Ramadan

Hi @Kim Andre 

While the AD IDA agent in Commvault backs up individual objects, it's not ideal for full forest recovery.
https://documentation.commvault.com/2024/essential/active_directory_01.html

In case of a major disaster, you'll want to use the pre-defined "Active Directory Forest Restore" workflow to restore multiple domain controllers (DCs), including their system state data.
https://documentation.commvault.com/2023e/expert/predefined_workflow_restoring_domain_controllers_in_active_directory_forest.html
 

Here's what I experienced at a customer site (different approach, but with the same goal):


I used a combination of the File System IDA and AD IDA agents on the DC. This captures both file system data and AD objects.

  • Install a new DC with the same OS and patches.
  • Install the Commvault File System agent on the new DC.
  • Use Commvault to perform a complete in-place restore, selecting "Primary" in the SYSVOL options.
  • Prepare the environment for Commvault's 1-Touch Bare Metal Recovery.
  • This allows you to boot from an ISO and recover the other DCs directly, skipping the steps of installing the OS, patches, and the Commvault agent.

Once the recovery is complete, you'll need to check and verify several things:

Let me know if this aligns with what you were looking for! If not, please share your thoughts. I'm happy to discuss further.

Best Regards,
Mohamed Ramadan
Data Protection Specialist

View original
Did this answer your question?

4 replies

Mohamed Ramadan
Forum|alt.badge.img+11

Hi @Kim Andre 

While the AD IDA agent in Commvault backs up individual objects, it's not ideal for full forest recovery.
https://documentation.commvault.com/2024/essential/active_directory_01.html

In case of a major disaster, you'll want to use the pre-defined "Active Directory Forest Restore" workflow to restore multiple domain controllers (DCs), including their system state data.
https://documentation.commvault.com/2023e/expert/predefined_workflow_restoring_domain_controllers_in_active_directory_forest.html
 

Here's what I experienced at a customer site (different approach, but with the same goal):


I used a combination of the File System IDA and AD IDA agents on the DC. This captures both file system data and AD objects.

  • Install a new DC with the same OS and patches.
  • Install the Commvault File System agent on the new DC.
  • Use Commvault to perform a complete in-place restore, selecting "Primary" in the SYSVOL options.
  • Prepare the environment for Commvault's 1-Touch Bare Metal Recovery.
  • This allows you to boot from an ISO and recover the other DCs directly, skipping the steps of installing the OS, patches, and the Commvault agent.

Once the recovery is complete, you'll need to check and verify several things:

Let me know if this aligns with what you were looking for! If not, please share your thoughts. I'm happy to discuss further.

Best Regards,
Mohamed Ramadan
Data Protection Specialist


Forum|alt.badge.img+6
  • Author
  • Byte
  • 33 replies
  • November 8, 2024

@Mohamed Ramadan 

 

Many thanks for a detailed answer, much appreciated! :)


Onno van den Berg
Commvault Certified Expert
Forum|alt.badge.img+19
  • Commvault Certified Expert
  • 1249 replies
  • November 11, 2024

@Kim Andre if I recall correctly this enhanced AD forest recovery option is still to be released and is planned for the next release planned to arrive somewhere next month. They just released, as part of the CPR2024E release, the first iteration of the improved AD agent. See for more info this post → 

Still the steps from @Mohamed Ramadan for full forst recovery are correct, it unfortunately is a lengthy process if you would have to recover it following these steps. Recovering it via VM-level backups is also possible and might even be a faster route. 


Damian Andre
Vaulter
Forum|alt.badge.img+23
  • Vaulter
  • 1301 replies
  • November 11, 2024

Correct, still to be released. There is no date as yet, but this calendar year seems unlikely from what I know.


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings