USN Rollbacks - Best Practice
I was talking best practices the other day with a customer with regards to what Backup Software to use and the use of Virtualized hosting environments. I recommended to the customer to utilise backup software that uses the Microsoft APIs, or the Software that uses the Microsoft Volume Shadow Copy APIs. If you use Active Directory aware backup programs that use these APIs, then the invocation I.D. is reset before the Active Directory is restarted. Because of this, the "restored" Domain Controller identifies itself as a new Domain Controller . This will prompt the other Domain Controllers to bring the "restored" domain controller up-to-date.
If this best practice is not followed then you could be in the situation of having to deal with USN Rollbacks. This is a condition that occurs when the Active Directory Domain Controller has not correctly reset its Invocation I.D. before the Active Directory starts. The Active Directory uses a combination of USN,s and invocation I.D.s to track changes to the Active Directory that need to be replicated.
What is the Invocation I.D.?
Well this ID identifies the version of the Directory Database. If a domain controller is restored from a system state backup then all is well and the i.d. is reset and will trigger replication from its partner DCs; however the situations highlighted below do not do this as a matter of course, and this is where potential problems can occur. (This was extracted from the Kb article 885875 that I recommend to be read to learn more about USN Rollbacks and how to recover from them.)
Software and methodologies that cause USN rollbacks
When the following environments, programs, or subsystems are used, administrators can bypass the checks and validations that Microsoft has designed to occur when the domain controller system state is restored:
•Virtualized hosting environments, including but not limited to Microsoft Virtual Server 2005 and EMC VMWARE
•Software that backs up and restores an Active Directory operating system installation or a hard disk volume that contains that installation
Note Such software includes but is not limited to Norton Ghost.
•Advanced disk subsystems that can selectively copy a volume that contains an Active Directory operating system installation that was saved in the past
The following operations are not supported:
1.Starting an Active Directory domain controller whose operating system was restored to a hard disk by using an imaging program such as Norton Ghost
2.Starting an Active Directory domain controller whose operating system resides in a virtualized hosting environment such as Microsoft Virtual PC, Microsoft Virtual Server 2005, or EMC VMWARE
3.Starting an Active Directory domain controller that is located on a volume where the disk subsystem loads using previously saved images of the operating system without requiring a system state restoration of Active Directory.
So recommendation is,
Thoroughly evaluate your re.tore strategy and software to ensure it follows recommended Best Practice, and utilises the Microsoft APIs,
Comments
Anonymous
January 01, 2003
PingBack from http://www.keyongtech.com/2859843-move-active-directory-to-newAnonymous
July 01, 2015
The comment has been removedAnonymous
July 23, 2015
http://www.screencast.com/t/gAX1ovxR9Z
https://www.rebelmouse.com/WatchDarkPlacesOnline/
http://www.screencast.com/t/UtQ9csdg
https://www.facebook.com/WatchTed2OnlineNow
https://www.rebelmouse.com/WatchPaperTownsOnline/
https://www.rebelmouse.com/WatchMaxOnline/
http://www.screencast.com/t/HhfTcWzVT
https://www.linkedin.com/grp/post/6971553-6011498080841510914
https://www.linkedin.com/grp/post/6973703-6017392948025507843
https://www.rebelmouse.com/WatchTed2Online/
https://www.rebelmouse.com/WatchHitmanAgent47Online/
http://www.screencast.com/t/iDwnAz9uCX
http://www.screencast.com/t/7HJHoJAX3Zdh
https://www.facebook.com/WatchRickiAndTheFlashOnline
https://www.rebelmouse.com/WatchAmyOnline/
https://www.linkedin.com/grp/post/6981021-6017293164958732291
http://www.screencast.com/t/IXgnchZvJ5Qi
http://www.screencast.com/t/sd6SU3y6X
https://www.facebook.com/WatchTheVisitOnline
https://www.linkedin.com/grp/post/6975089-6015035619363807236
https://www.rebelmouse.com/WatchMagicMikeXXLOnline/
https://www.linkedin.com/grp/post/8337129-6017937517842567170
https://www.rebelmouse.com/WatchAntmanOnline/
https://www.facebook.com/WatchMinionsOnlineNow
https://www.rebelmouse.com/WatchRegressionOnline/
https://www.linkedin.com/grp/post/6980115-6017735463568158724
https://www.rebelmouse.com/MazeRunner2TheScorchTrials/
https://www.rebelmouse.com/WatchAmericanUltraOnline/
https://www.rebelmouse.com/MissionImpossible5RogueNation/
https://www.rebelmouse.com/WatchSouthpawOnline/
https://www.facebook.com/WatchSouthpawOnline
http://www.screencast.com/t/KBqVeCR8
https://www.rebelmouse.com/WatchSelflessOnline/
https://www.facebook.com/WatchMaxOnline
https://www.facebook.com/WatchTheGallowsOnline
http://www.screencast.com/t/TvvvXobmy
https://www.rebelmouse.com/WatchTheManFromUncleOnline/
https://www.linkedin.com/grp/post/8338032-6017247400261926914
https://www.linkedin.com/grp/post/8338032-6017243258827141124
http://www.screencast.com/t/Bq3Crb0cMJXo
http://www.screencast.com/t/tzQwd7gc
https://www.facebook.com/WatchTheManFromUncleOnline
https://www.rebelmouse.com/WatchBlackMassOnline/
http://www.screencast.com/t/vEPTLb3hZyA
https://www.linkedin.com/grp/post/8337129-6017929691594260480
https://www.facebook.com/WatchAmyOnline
http://www.screencast.com/t/1tvetqjg
https://www.linkedin.com/grp/post/6980115-6017745897104883716
http://www.screencast.com/t/8e9fKhj56
http://www.screencast.com/t/K2c4nAMnAnonymous
September 16, 2015
https://www.pinterest.com/pin/84583299228836034/
https://www.pinterest.com/pin/350647520966520566/
https://www.pinterest.com/pin/442830575838906399/
https://www.facebook.com/1491549824497510
https://www.pinterest.com/pin/503840277041035125/
http://www.screencast.com/t/Uvgv9VQMk
https://www.pinterest.com/pin/442830575838892404/
http://www.screencast.com/t/IN2G7JkE
http://www.screencast.com/t/O9ipuey2PEw6
https://www.pinterest.com/pin/160511174196348390/
http://www.screencast.com/t/H5A2Leg1
https://www.facebook.com/1483738308615435
https://www.facebook.com/1483378001984799
https://www.pinterest.com/pin/50665564535280885/
http://www.screencast.com/t/iog3Tzgyt8c
http://www.screencast.com/t/2vDNVGIPpv
http://www.screencast.com/t/3mgzI5fBio
https://www.facebook.com/1491489597836866
https://www.facebook.com/1490740151245423
https://www.facebook.com/1488520981470758
https://www.pinterest.com/pin/160511174196343301/
https://www.pinterest.com/pin/160511174196343360/
https://www.facebook.com/1485688141756108
http://www.screencast.com/t/wXIlLTGvEE
https://www.pinterest.com/pin/442830575838892602/
http://www.screencast.com/t/3kcwgMAHc
https://www.pinterest.com/pin/350647520966531111/
http://www.screencast.com/t/Jo0fbIEQW3sY
http://www.screencast.com/t/OiTS966mMqzb
https://www.facebook.com/1493076994343973
http://www.screencast.com/t/rwd99TuHEuah
http://www.screencast.com/t/3qBTI1UhP
https://www.pinterest.com/pin/350647520966521281/
http://www.screencast.com/t/pSq6ogUZq
https://www.pinterest.com/pin/160511174196344179/
http://www.screencast.com/t/MPmPqUn2m
http://www.screencast.com/t/XLfXOOaI
https://www.pinterest.com/pin/503840277041035380/
http://www.screencast.com/t/kn74ku2uBGA
https://www.facebook.com/1491477197838106
https://www.facebook.com/1493388580979481
http://www.screencast.com/t/iHzKLbLEs
https://www.facebook.com/1488561881466668
https://www.pinterest.com/pin/160511174196347899/
https://www.facebook.com/1493803650941448
https://www.pinterest.com/pin/160511174196344036/
https://www.facebook.com/1485803235077932
https://www.facebook.com/1488529198136603
http://www.screencast.com/t/hTxOoXf9B
https://www.facebook.com/1488508034805386Anonymous
December 01, 2015
http://msry.org/%D8%B5%D9%88%D8%B1-%D8%AD%D8%B2%D9%86.html