Re: backup FSMO roles
- From: "Steve - MO" <no@xxxxxxxxxxxxx>
- Date: Tue, 28 Aug 2007 16:15:55 -0500
Jorge, I appreciate your time and patience with this. I can find no
one that will discuss it other than to say "that's not supported".
KB875495 really only says that whatever backup/restore you use must
be active directory aware, which NTBackup is. On identical hardware
this KB article and others to me says what I propose is valid.
I have a controlled environment, and I trust the only person that
would be dealing with a restore (myself). It seems in such an event, it
is easier to be careful with the details of what I suggest, than it is
to go through seizing the roles on another DC, and forceably demoting
the original before bringing it back up.
It seems either way you must be careful, so why not choose the simpler
of the two? It even seems that 2003 SP1 introduced some additional
safeguards for dealing with USN Rollback's and such.
I can't justify why imaging + system state wouldn't work in a
controlled environment if you know what you're doing. You really have
to know what you are doing to forceably demote a domain controller and
clean up it's references, as you do for seizing FSMO roles.
I also assume this discussion has been had in Altiris True Image and
Symantec's Ghost support sites as well, which I may try to take a look
at.
Again, thank you for your comments.
"Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx> wrote in
news:uCVlhQb6HHA.5740@xxxxxxxxxxxxxxxxxxxx:
The KB 875495 explains why you shouldn't use these methods to bk the
AD. The problem is that with imaging the AD has no way to see that a
restore was made (unless you do it manually,and you must know what
you're doing otherwise you can be very sorry, no need to do invent
when you can have a safe solution).
Any DC can by FSMO owner at any given time, that's the bewety of
multimaster replication.
If a given DC (FSMO owner) fails for some reason and it's
unrecoverable for some reason, you have the option to seixe the
role(s) to another DC (careful if you seize roles, the failed DC must
not be connected again to the forest or you may end up with a broken
forest, to connect the failed DC again to the forest you must manually
remove AD from that DC).
.
- Follow-Ups:
- Re: backup FSMO roles
- From: Jorge Silva
- Re: backup FSMO roles
- From: Mathieu CHATEAU
- Re: backup FSMO roles
- References:
- backup FSMO roles
- From: Steve - MO
- Re: backup FSMO roles
- From: Jorge Silva
- Re: backup FSMO roles
- From: Steve - MO
- Re: backup FSMO roles
- From: Jorge Silva
- backup FSMO roles
- Prev by Date: Re: View Distinguished Name from object Properties in ADUC
- Next by Date: Re: backup FSMO roles
- Previous by thread: Re: backup FSMO roles
- Next by thread: Re: backup FSMO roles
- Index(es):
Relevant Pages
|