CaryvaneHelp
/

Active Directory backup

An App-consistent job for Active Directory captures the directory database (ntds.dit), its logs and SYSVOL on a domain controller through the NTDS writer, so the copy is consistent rather than a snapshot of files mid-write.

Create the job #

  1. Jobs → New Job → App-consistent, choose the domain controller, workload Active Directory (NTDS, on a domain controller).
  2. Discover on machine confirms the NTDS writer is present; there is one component, the directory.
  3. Destination and schedule. Daily is usual; keep version history on, because the copy you need after a bad change is the one from before it.

What a run uploads #

ntds.dit, the edb*.log transaction logs and checkpoint file, and the SYSVOL tree (group policy, scripts), under <destination>/vss/ActiveDirectory/<drive>/<original path>. The writer freezes the directory for the snapshot instant and the DC keeps serving throughout.

Restore #

Restoring a directory is a Directory Services Restore Mode operation and Microsoft's procedure applies: boot the DC into DSRM, put the files back with a Restore job (or from the bucket), then use ntdsutil to mark objects or subtrees authoritative if you are undoing a deletion, and reboot. For a whole-domain rebuild, restore the files to the last surviving DC first. Caryvane gets you the consistent files; the directory tools do the rest.

USN rollback

Never restore ntds.dit onto a DC that has been running since the copy was taken without going through DSRM and the proper non-authoritative/authoritative steps. Replication partners will refuse a DC that appears to have gone back in time.

If the DC is a VM #

Back it up as a Hyper-V VM as well: the VM capture gives you a whole machine to bring back; the NTDS capture gives you the directory files on their own for a targeted recovery. They are not alternatives.