Forum Discussion
How to Backup Active Directory (recovery when have Ransomware)
Currently we only backup system state root and child, is this backup method enough (We want can restore Active Directory in case all server have Ransomware from backup )?
wbadmin start systemstatebackup -backuptarget:<targetDrive>:
please anyone help here
1 Reply
System State backup is an important part of Active Directory recovery, but I would not consider one System State backup per domain a complete ransomware-recovery strategy.
Microsoft's forest-recovery guidance recommends regularly backing up at least two writable domain controllers in each domain, so you have multiple known-good recovery points available.
For a ransomware scenario I would maintain:
System State backups of multiple writable DCs per domain.
Backup copies that are offline, immutable or otherwise isolated from normal administrative credentials.
DSRM credentials and forest-recovery documentation stored securely.
Documentation of DNS, FSMO roles, sites and critical dependencies.
Regular recovery tests in an isolated environment.
Your wbadmin start systemstatebackup approach is valid for creating the System State backup itself.
During a forest compromise, you also need to determine which backup predates the compromise. Restoring the newest backup blindly can simply restore compromised data. Microsoft additionally includes resetting the krbtgt password twice as part of forest-recovery procedures.
So: keep System State backups, but add multiple DC backups, isolation/immutability and a tested forest-recovery plan.