<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>sheenaustin.com</title>
	<atom:link href="http://www.sheenaustin.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sheenaustin.com</link>
	<description>my home on the interweb</description>
	<lastBuildDate>Wed, 17 Feb 2010 16:06:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Script to Hot Backup VMWare ESX Virtual Machines</title>
		<link>http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/</link>
		<comments>http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 19:25:01 +0000</pubDate>
		<dc:creator>Sheen</dc:creator>
				<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Script]]></category>
		<category><![CDATA[Virtual Machines]]></category>
		<category><![CDATA[VMWare ESX]]></category>
		<category><![CDATA[vmware-cmd]]></category>

		<guid isPermaLink="false">http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/</guid>
		<description><![CDATA[I was searching for the best way to implement vmware-cmd to snapshot live VMs and then rsync them to another location of my choice and look what I found!
There is a free script called ghettoVCB.sh that does the trick.
The script allows you to backup live virtual machines and also maintains only a selected number of [...]


Related posts:<ol><li><a href='http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/' rel='bookmark' title='Permanent Link: How to Backup and Restore Active Directory'>How to Backup and Restore Active Directory</a></li>
<li><a href='http://www.sheenaustin.com/2009/01/09/using-apc-powerchute-with-vmware-esx/' rel='bookmark' title='Permanent Link: Using APC PowerChute with VMWare ESX'>Using APC PowerChute with VMWare ESX</a></li>
<li><a href='http://www.sheenaustin.com/2009/12/25/using-rsync-in-vmware/' rel='bookmark' title='Permanent Link: Using Rsync in VMWare'>Using Rsync in VMWare</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/04/active-directory-audit-script/' rel='bookmark' title='Permanent Link: Active Directory Audit Script'>Active Directory Audit Script</a></li>
<li><a href='http://www.sheenaustin.com/2009/06/18/exchange-2007-recreate-owa-folders/' rel='bookmark' title='Permanent Link: Exchange 2007 Recreate OWA folders'>Exchange 2007 Recreate OWA folders</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I was searching for the best way to implement vmware-cmd to snapshot live VMs and then rsync them to another location of my choice and look what I found!</p>
<p>There is a free script called <a href="http://communities.vmware.com/docs/DOC-8760" target="_blank">ghettoVCB.sh</a> that does the trick.</p>
<p>The script allows you to backup live virtual machines and also maintains only a selected number of snapshots that you would like to keep. Check it out!</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.sheenaustin.com%2F2010%2F01%2F29%2Fscript-to-hot-backup-vmware-esx-virtual-machines%2F&amp;linkname=Script%20to%20Hot%20Backup%20VMWare%20ESX%20Virtual%20Machines">Share This Post!</a>

<p>Related posts:<ol><li><a href='http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/' rel='bookmark' title='Permanent Link: How to Backup and Restore Active Directory'>How to Backup and Restore Active Directory</a></li>
<li><a href='http://www.sheenaustin.com/2009/01/09/using-apc-powerchute-with-vmware-esx/' rel='bookmark' title='Permanent Link: Using APC PowerChute with VMWare ESX'>Using APC PowerChute with VMWare ESX</a></li>
<li><a href='http://www.sheenaustin.com/2009/12/25/using-rsync-in-vmware/' rel='bookmark' title='Permanent Link: Using Rsync in VMWare'>Using Rsync in VMWare</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/04/active-directory-audit-script/' rel='bookmark' title='Permanent Link: Active Directory Audit Script'>Active Directory Audit Script</a></li>
<li><a href='http://www.sheenaustin.com/2009/06/18/exchange-2007-recreate-owa-folders/' rel='bookmark' title='Permanent Link: Exchange 2007 Recreate OWA folders'>Exchange 2007 Recreate OWA folders</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OCS 2007 Protocol Stack Error Event ID 14517 When Starting Services</title>
		<link>http://www.sheenaustin.com/2010/01/15/ocs-2007-event-id-14517-when-starting-services/</link>
		<comments>http://www.sheenaustin.com/2010/01/15/ocs-2007-event-id-14517-when-starting-services/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 21:03:11 +0000</pubDate>
		<dc:creator>Sheen</dc:creator>
				<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[adsiedit]]></category>
		<category><![CDATA[Errors]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[OCS]]></category>

		<guid isPermaLink="false">http://www.sheenaustin.com/2010/01/15/ocs-2007-event-id-14517-when-starting-services/</guid>
		<description><![CDATA[You may come across this error message when you install Office Communications Server 2007 for the first time in your environment. This error generally is seen after you run through the initial steps and are trying to start the OCS services for the first time.
This event ID will contain the following message:
ERRORS:    [...]


Related posts:<ol><li><a href='http://www.sheenaustin.com/2009/11/18/kb974571-and-ocs-2007/' rel='bookmark' title='Permanent Link: KB974571 and OCS 2007'>KB974571 and OCS 2007</a></li>
<li><a href='http://www.sheenaustin.com/2009/04/30/a-certificate-could-not-be-found-that-can-be-used-with-this-extensible-authentication-protocol/' rel='bookmark' title='Permanent Link: A Certificate could not be found that can be used with this Extensible Authentication Protocol'>A Certificate could not be found that can be used with this Extensible Authentication Protocol</a></li>
<li><a href='http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/' rel='bookmark' title='Permanent Link: How to Backup and Restore Active Directory'>How to Backup and Restore Active Directory</a></li>
<li><a href='http://www.sheenaustin.com/2009/04/28/setting-up-split-brain-dns-in-windows-server/' rel='bookmark' title='Permanent Link: Setting up Split Brain DNS in Windows Server 2003'>Setting up Split Brain DNS in Windows Server 2003</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/01/error-rewriteengine-not-allowed-here/' rel='bookmark' title='Permanent Link: Error: RewriteEngine not allowed here'>Error: RewriteEngine not allowed here</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>You may come across this error message when you install Office Communications Server 2007 for the first time in your environment. This error generally is seen after you run through the initial steps and are trying to start the OCS services for the first time.</p>
<p>This event ID will contain the following message:</p>
<blockquote><p>ERRORS:     <br />Two server roles at FQDN [server.domain.com] have different &#8216;Treat As Authenticated&#8217; options. First server has GUID {58BDE507-1C48-4BA4-BCDF-06FB59ADF9CE} and role &#8216;Enterprise Edition&#8217; (option is set). Second server has GUID {BD77F03B-4451-4171-A035-FC7FB264383D} and role &#8216;A/V Authentication Service&#8217; (option is not set). Two server roles at FQDN [server.domain.com] have different server version numbers. First server has GUID {58BDE507-1C48-4BA4-BCDF-06FB59ADF9CE} and role &#8216;Enterprise Edition&#8217; (version 3). Second server has GUID {BD77F03B-4451-4171-A035-FC7FB264383D} and role &#8216;A/V Authentication Service&#8217; (version 0). Two server roles at FQDN [server.domain.com] have different &#8216;Treat As Authenticated&#8217; options. First server has GUID {58BDE507-1C48-4BA4-BCDF-06FB59ADF9CE} and role &#8216;Enterprise Edition&#8217; (option is set). Second server has GUID {1719A023-DDB4-5170-836D-3299D4F067C6} and role &#8216;Edge Server&#8217; (option is not set). Two server roles at FQDN [server.domain.com] have different server version numbers. First server has GUID {58BDE507-1C48-4BA4-BCDF-06FB59ADF9CE} and role &#8216;Enterprise Edition&#8217; (version 3). Second server has GUID {1719A023-DDB4-5170-836D-3299D4F067C6} and role &#8216;Edge Server&#8217; (version 0). </p>
<p>WARNINGS:     <br />No warnings </p>
<p>Cause: The configuration is invalid and the server might not behave as expected.     <br />Resolution:      <br />Review and correct the errors listed above, then restart the service. You also wish to review any warnings present. </p>
<p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>. </p>
<p>&#160;</p>
</blockquote>
<p>This error can be misleading. The primary reason you see this error is simple – You have had a previous installation of OCS in the domain and there are still a few entries in Active Directory that haven’t been cleaned up even though you did a clean uninstall of OCS.</p>
<p>This is what you need to do to fix the error:</p>
<p> <span id="more-155"></span>
<p>Please Remember – You are following the instructions below at your own risk.</p>
<p>Open up adsiedit.msc and browse to the system configuration partition under Domain –&gt; DC=domain,DC=com –&gt; System –&gt; Microsoft –&gt; RTC Service.</p>
<p>NOTE: This is safe to perform only if you do not have a current working installation of OCS in your domain or forest.</p>
<p>Select and delete everything under this key.</p>
<p>Now go ahead and run the setup again (you will have to run the forest prep again) and you will be all set!</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.sheenaustin.com%2F2010%2F01%2F15%2Focs-2007-event-id-14517-when-starting-services%2F&amp;linkname=OCS%202007%20Protocol%20Stack%20Error%20Event%20ID%2014517%20When%20Starting%20Services">Share This Post!</a>

<p>Related posts:<ol><li><a href='http://www.sheenaustin.com/2009/11/18/kb974571-and-ocs-2007/' rel='bookmark' title='Permanent Link: KB974571 and OCS 2007'>KB974571 and OCS 2007</a></li>
<li><a href='http://www.sheenaustin.com/2009/04/30/a-certificate-could-not-be-found-that-can-be-used-with-this-extensible-authentication-protocol/' rel='bookmark' title='Permanent Link: A Certificate could not be found that can be used with this Extensible Authentication Protocol'>A Certificate could not be found that can be used with this Extensible Authentication Protocol</a></li>
<li><a href='http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/' rel='bookmark' title='Permanent Link: How to Backup and Restore Active Directory'>How to Backup and Restore Active Directory</a></li>
<li><a href='http://www.sheenaustin.com/2009/04/28/setting-up-split-brain-dns-in-windows-server/' rel='bookmark' title='Permanent Link: Setting up Split Brain DNS in Windows Server 2003'>Setting up Split Brain DNS in Windows Server 2003</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/01/error-rewriteengine-not-allowed-here/' rel='bookmark' title='Permanent Link: Error: RewriteEngine not allowed here'>Error: RewriteEngine not allowed here</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.sheenaustin.com/2010/01/15/ocs-2007-event-id-14517-when-starting-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Rsync in VMWare</title>
		<link>http://www.sheenaustin.com/2009/12/25/using-rsync-in-vmware/</link>
		<comments>http://www.sheenaustin.com/2009/12/25/using-rsync-in-vmware/#comments</comments>
		<pubDate>Fri, 25 Dec 2009 12:51:00 +0000</pubDate>
		<dc:creator>Sheen</dc:creator>
				<category><![CDATA[VMWare]]></category>
		<category><![CDATA[rsync]]></category>
		<category><![CDATA[VMWare ESX]]></category>

		<guid isPermaLink="false">http://www.sheenaustin.com/2009/12/25/using-rsync-in-vmware/</guid>
		<description><![CDATA[VMWare ESX runs a modified Linux Kernel. Sometimes, when you are doing basic administration tasks, you might find that there are certain Linux tools that you miss. One of the tools I miss most is the rsync tool. Its a very handy tool when it comes to data transfer. I searched high and low for [...]


Related posts:<ol><li><a href='http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/' rel='bookmark' title='Permanent Link: Script to Hot Backup VMWare ESX Virtual Machines'>Script to Hot Backup VMWare ESX Virtual Machines</a></li>
<li><a href='http://www.sheenaustin.com/2009/01/09/using-apc-powerchute-with-vmware-esx/' rel='bookmark' title='Permanent Link: Using APC PowerChute with VMWare ESX'>Using APC PowerChute with VMWare ESX</a></li>
<li><a href='http://www.sheenaustin.com/2009/07/18/the-winroute-tool/' rel='bookmark' title='Permanent Link: The WinRoute tool'>The WinRoute tool</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>VMWare ESX runs a modified Linux Kernel. Sometimes, when you are doing basic administration tasks, you might find that there are certain Linux tools that you miss. One of the tools I miss most is the rsync tool. Its a very handy tool when it comes to data transfer. I searched high and low for a proper tool to do the job but never found one until now.</p>
<p>The problem with installing a standard Linux package into VMWare ESX is that it will almost certainly mean that you go down the path of installing a whole bunch of dependencies along with it and eventually something might stop working. The best way around this, obviously, is to compile a static package from source with all dependencies included.</p>
<p> <span id="more-153"></span>
<p>Thus, searching around the internet, I found this <a href="http://www.sheenaustin.com/wp-content/uploads/2009/12/rsync-static-stripped.zip">rsync package</a> that was statically compiled to work on VMWare ESX 3.5. on the VMWare communities page <a href="http://communities.vmware.com/message/1096198#1096198">here</a>. I have used it and found it to work without any issues on VMWare ESX 4.0.</p>
<p>Please remember – this is not supported and if you decide to use this, you do so at your own risk.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.sheenaustin.com%2F2009%2F12%2F25%2Fusing-rsync-in-vmware%2F&amp;linkname=Using%20Rsync%20in%20VMWare">Share This Post!</a>

<p>Related posts:<ol><li><a href='http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/' rel='bookmark' title='Permanent Link: Script to Hot Backup VMWare ESX Virtual Machines'>Script to Hot Backup VMWare ESX Virtual Machines</a></li>
<li><a href='http://www.sheenaustin.com/2009/01/09/using-apc-powerchute-with-vmware-esx/' rel='bookmark' title='Permanent Link: Using APC PowerChute with VMWare ESX'>Using APC PowerChute with VMWare ESX</a></li>
<li><a href='http://www.sheenaustin.com/2009/07/18/the-winroute-tool/' rel='bookmark' title='Permanent Link: The WinRoute tool'>The WinRoute tool</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.sheenaustin.com/2009/12/25/using-rsync-in-vmware/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>KB974571 and OCS 2007</title>
		<link>http://www.sheenaustin.com/2009/11/18/kb974571-and-ocs-2007/</link>
		<comments>http://www.sheenaustin.com/2009/11/18/kb974571-and-ocs-2007/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 21:21:00 +0000</pubDate>
		<dc:creator>Sheen</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[OCS]]></category>
		<category><![CDATA[Patch Install]]></category>

		<guid isPermaLink="false">http://www.sheenaustin.com/2010/01/15/kb974571-and-ocs-2007/</guid>
		<description><![CDATA[If you are running OCS 2007 or 2007 R2, do not install the patch KB974571. This patch is known to break OCS 2007 installations. In cases where the Office Communications Server 2007 has this patch, you will not be able to install the server and will get an weird error saying that the time is [...]


Related posts:<ol><li><a href='http://www.sheenaustin.com/2010/01/15/ocs-2007-event-id-14517-when-starting-services/' rel='bookmark' title='Permanent Link: OCS 2007 Protocol Stack Error Event ID 14517 When Starting Services'>OCS 2007 Protocol Stack Error Event ID 14517 When Starting Services</a></li>
<li><a href='http://www.sheenaustin.com/2009/07/18/the-winroute-tool/' rel='bookmark' title='Permanent Link: The WinRoute tool'>The WinRoute tool</a></li>
<li><a href='http://www.sheenaustin.com/2009/06/18/exchange-2007-recreate-owa-folders/' rel='bookmark' title='Permanent Link: Exchange 2007 Recreate OWA folders'>Exchange 2007 Recreate OWA folders</a></li>
<li><a href='http://www.sheenaustin.com/2009/04/30/a-certificate-could-not-be-found-that-can-be-used-with-this-extensible-authentication-protocol/' rel='bookmark' title='Permanent Link: A Certificate could not be found that can be used with this Extensible Authentication Protocol'>A Certificate could not be found that can be used with this Extensible Authentication Protocol</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>If you are running OCS 2007 or 2007 R2, do not install the patch KB974571. This patch is known to break OCS 2007 installations. In cases where the Office Communications Server 2007 has this patch, you will not be able to install the server and will get an weird error saying that the time is not correct or not in sync.</p>
<p>Here is the <a href="http://support.microsoft.com/default.aspx/kb/974571" target="_blank">Microsoft KB</a> article about this error.</p>
<p>Let me know if you have installed this patch and are able to run your OCS 2007 server without issues.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.sheenaustin.com%2F2009%2F11%2F18%2Fkb974571-and-ocs-2007%2F&amp;linkname=KB974571%20and%20OCS%202007">Share This Post!</a>

<p>Related posts:<ol><li><a href='http://www.sheenaustin.com/2010/01/15/ocs-2007-event-id-14517-when-starting-services/' rel='bookmark' title='Permanent Link: OCS 2007 Protocol Stack Error Event ID 14517 When Starting Services'>OCS 2007 Protocol Stack Error Event ID 14517 When Starting Services</a></li>
<li><a href='http://www.sheenaustin.com/2009/07/18/the-winroute-tool/' rel='bookmark' title='Permanent Link: The WinRoute tool'>The WinRoute tool</a></li>
<li><a href='http://www.sheenaustin.com/2009/06/18/exchange-2007-recreate-owa-folders/' rel='bookmark' title='Permanent Link: Exchange 2007 Recreate OWA folders'>Exchange 2007 Recreate OWA folders</a></li>
<li><a href='http://www.sheenaustin.com/2009/04/30/a-certificate-could-not-be-found-that-can-be-used-with-this-extensible-authentication-protocol/' rel='bookmark' title='Permanent Link: A Certificate could not be found that can be used with this Extensible Authentication Protocol'>A Certificate could not be found that can be used with this Extensible Authentication Protocol</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.sheenaustin.com/2009/11/18/kb974571-and-ocs-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Backup and Restore Active Directory</title>
		<link>http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/</link>
		<comments>http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 00:53:00 +0000</pubDate>
		<dc:creator>Sheen</dc:creator>
				<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[Restore]]></category>

		<guid isPermaLink="false">http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/</guid>
		<description><![CDATA[There are many documents written about backing up Active Directory but I didn’t find enough documentation that would help us restore Active Directory. So here is a guide aimed to provide insights into correctly backing up and restoring Active Directory.
Here is my mini how to – I have tried to keep it as simple as [...]


Related posts:<ol><li><a href='http://www.sheenaustin.com/2009/04/28/setting-up-split-brain-dns-in-windows-server/' rel='bookmark' title='Permanent Link: Setting up Split Brain DNS in Windows Server 2003'>Setting up Split Brain DNS in Windows Server 2003</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/04/active-directory-audit-script/' rel='bookmark' title='Permanent Link: Active Directory Audit Script'>Active Directory Audit Script</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/18/get-list-of-machines-by-os-type-from-active-directory/' rel='bookmark' title='Permanent Link: Get list of machines by OS type from Active Directory'>Get list of machines by OS type from Active Directory</a></li>
<li><a href='http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/' rel='bookmark' title='Permanent Link: Script to Hot Backup VMWare ESX Virtual Machines'>Script to Hot Backup VMWare ESX Virtual Machines</a></li>
<li><a href='http://www.sheenaustin.com/2009/06/19/active-directory-password-expiry-reminder-email/' rel='bookmark' title='Permanent Link: Active Directory Password Expiry Reminder Email'>Active Directory Password Expiry Reminder Email</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>There are many documents written about backing up Active Directory but I didn’t find enough documentation that would help us restore Active Directory. So here is a guide aimed to provide insights into correctly backing up and restoring Active Directory.</p>
<p>Here is my mini how to – I have tried to keep it as simple as possible:</p>
<p> <span id="more-162"></span><br />
<h1></h1>
<h6>Backing Up Active Directory</h6>
<p>Active Directory depends on the system state and the NTDS database among other things. So it is important to back these up on your domain controller. It is critically important to ensure that the system state data on a domain controller is backed up regularly since this contains all the core system files that are required to run a domain controller. Manually selecting what needs to be backed up will be extremely complicated and could be error prone – stay away from that path – just backup the entire system state.</p>
<p>What needs to be backed up? – System State</p>
<p>What kind of Backup needs to be run? – Full backup of the system state.</p>
<p>How often is good enough? – Daily &#8211; You will thank me for this <img src='http://www.sheenaustin.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><b>Restoring Active Directory</b> (for experts who just need the short version)</p>
<p>There are two types of restores:</p>
<p>1. <b>Normal Restore</b> – This was also called the Non-Authoritative restore. This is generally performed when you need to restore a domain controller that has failed and there are other domain controllers on the domain. Another option would be to just reinstall the domain controller, clean up the AD metadata of all references to the failed DC and then promote the new server to a DC and replicate. If you are in a situation where you cannot do that, to perform a normal (or Non-Authoritative restore) you would:</p>
<p>a. Boot the domain controller into the Domain Services Restore Mode .</p>
<p>b. Restore system state </p>
<p>c. Reboot into the normal mode.</p>
<p>d. Replicate from other domain controllers.</p>
<p>2. <b>Authoritative Restore</b> – This would be performed in cases where you make a mistake like, say, delete an OU. In this case, a normal restore would not help since the OU that you just restored would get deleted again when you replicate changes with other domain controllers. An authoritative restore would help you undo a big mistake by ensuring that you are taken back to a working copy of AD. However, changes that you made since the last full backup would be lost. (So run your full backups daily!). To perform an authoritative restore:</p>
<p>a. Perform a normal restore.</p>
<p>b. Don’t reboot after the restore.</p>
<p>c. Use ntdsutil to get into the authoritative restore mode.</p>
<p>d. Specify if you want to mark the entire database or just a subtree as authoritative.</p>
<p>e. Quit the utility and reboot the server</p>
<p>3. <b>Primary Restore</b> – This restore is only used when you have a major disaster (read complete meltdown) and you have no working domain controllers. In such a case, you will have restore the entire domain from backups. The working process is very similar to the Normal Restore procedure mentioned above. This is how you would do it:</p>
<p>a. Boot the domain controller into the Domain Services Restore Mode .</p>
<p>b. Restore system state – ensure that the advanced option ‘Mark the restored data as the primary data for all replicas’ is checked.</p>
<p>c. Reboot into the normal mode.</p>
<p><b></b></p>
<p><b></b></p>
<p><b>Restoring Active Directory </b>(for the rest of us)</p>
<p>1. <b>Normal Restore</b> – Here’s the step by step.</p>
<p>a. Reboot Server</p>
<p>b. During startup press F8 and choose, ‘Directory Services Restore Mode (Windows DCs only)</p>
<p>c. Choose the OS to be started, hit enter.</p>
<p>d. Hit OK at the Safe Mode login.</p>
<p>e. Open up the NTBackup utility.</p>
<p>f. Click next on the welcome page.</p>
<p>g. Select ‘Restore Files and Settings’ from the backup or restore page. Click Next.</p>
<p>h. Choose the backup you want to restore from the ‘What to restore’ page. Click Next.</p>
<p>i. Click Finish to start the restore. (Advanced options are best left untouched for a normal restore unless you want to save the backup elsewhere.)</p>
<p>j. Reboot server.</p>
<p>2. <b>Authoritative Restore –</b></p>
<p>a. Perform a normal restore as mentioned before.</p>
<p>b. Do not reboot server after the restore.</p>
<p>c. Click on start -&gt; run -&gt; type ntdsutil.</p>
<p>d. Now type ‘authoritative restore’</p>
<p>e. Now specify the components you want to make authoritative. Enter either ‘restore database’ or ‘restore subtree’ along with the DN of the AD object you want to make authoritative.</p>
<p>f. Confirm your actions when prompted.</p>
<p>g. Type quit until the utility exits.</p>
<p>h. Reboot server.</p>
<p>3. <b>Primary Restore –</b></p>
<p>a. Reboot Server</p>
<p>b. During startup press F8 and choose, ‘Directory Services Restore Mode (Windows DCs only)</p>
<p>c. Choose the OS to be started, hit enter.</p>
<p>d. Hit OK at the Safe Mode login.</p>
<p>e. Open up the NTBackup utility.</p>
<p>f. Click next on the welcome page.</p>
<p>g. Select ‘Restore Files and Settings’ from the backup or restore page. Click Next.</p>
<p>h. Choose the backup you want to restore from the ‘What to restore’ page. Click Next.</p>
<p>i. Click Advanced.</p>
<p>j. Ensure that on the ‘Where to Restore’ page, the default setting ‘Original Location’ is selected. Click Next.</p>
<p>k. On the How to Restore page, ensure that ‘Replace existing files’ is selected. Click Next.</p>
<p>l. On the Advanced Restore Options page – enable the ‘When restoring replicated data sets, mark the restored data as the primary data for all replicas’ option. Click Next.</p>
<p>m. Click Finish to start the primary restore.</p>
<p>n. Reboot server.</p>
<p>o. Go to sleep <img src='http://www.sheenaustin.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#160;</p>
<p>PS: As always, please exercise due diligence when using the instructions in a live environment. Kindly do not blame me if something doesn&#8217;t work if Microsoft decides to change their code.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.sheenaustin.com%2F2009%2F10%2F07%2Fhow-to-backup-and-restore-active-directory%2F&amp;linkname=How%20to%20Backup%20and%20Restore%20Active%20Directory">Share This Post!</a>

<p>Related posts:<ol><li><a href='http://www.sheenaustin.com/2009/04/28/setting-up-split-brain-dns-in-windows-server/' rel='bookmark' title='Permanent Link: Setting up Split Brain DNS in Windows Server 2003'>Setting up Split Brain DNS in Windows Server 2003</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/04/active-directory-audit-script/' rel='bookmark' title='Permanent Link: Active Directory Audit Script'>Active Directory Audit Script</a></li>
<li><a href='http://www.sheenaustin.com/2009/05/18/get-list-of-machines-by-os-type-from-active-directory/' rel='bookmark' title='Permanent Link: Get list of machines by OS type from Active Directory'>Get list of machines by OS type from Active Directory</a></li>
<li><a href='http://www.sheenaustin.com/2010/01/29/script-to-hot-backup-vmware-esx-virtual-machines/' rel='bookmark' title='Permanent Link: Script to Hot Backup VMWare ESX Virtual Machines'>Script to Hot Backup VMWare ESX Virtual Machines</a></li>
<li><a href='http://www.sheenaustin.com/2009/06/19/active-directory-password-expiry-reminder-email/' rel='bookmark' title='Permanent Link: Active Directory Password Expiry Reminder Email'>Active Directory Password Expiry Reminder Email</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.sheenaustin.com/2009/10/07/how-to-backup-and-restore-active-directory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
