Recovering on premises Server 2016 Domain Controller

%3CLINGO-SUB%20id%3D%22lingo-sub-148030%22%20slang%3D%22en-US%22%3ERecovering%20on%20premises%20Server%202016%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148030%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20(had)%20a%20single%20on%20premises%20domain%20controller%20built%20on%20Server%202016.%20The%20server%20was%20backed%20up%20to%20the%20Azure%20Recovery%20Services%20Vault.%20The%20on%20premises%20domain%20controller%20was%20the%20primary%20domain%20controller%20for%20my%20domain.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20server%20has%20been%20rebuilt%2C%20but%20I%20have%20not%20yet%20joined%20it%20back%20to%20the%20domain%20as%20I%20am%20uncertain%20exactly%20what%20steps%20need%20to%20be%20taken%20to%20restore%20this%20and%20maintain%20the%20integrity%20of%20the%20existing%20AD.%20I%20have%20looked%20around%20online%2C%20but%20I%20have%20not%20been%20successful%20in%20finding%20a%20definitive%20guide%20to%20completing%20this%20restore%20operation.%3C%2FP%3E%0A%3CP%3ECan%20anyone%20please%20point%20me%20to%20an%20appropriate%20documentation%20set%20to%20guide%20me%20through%20this%20process.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20am%20also%20open%20the%20thought%20that%20perhaps%20this%20is%20an%20opportune%20time%20to%20migrate%20my%20AD%20control%20to%20an%20Azure%20VM%20and%20would%20be%20interested%20in%20thoughts%20on%20taking%20this%20approach.%3C%2FP%3E%0A%3CP%3EI%20thank%20you%20all%20in%20advance%20for%20your%20kind%20assistance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-148030%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Backup%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Essentials%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Site%20Recovery%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148947%22%20slang%3D%22en-US%22%3ERe%3A%20Recovering%20on%20premises%20Server%202016%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148947%22%20slang%3D%22en-US%22%3ELink%20for%20system%20state%20recovery%20if%20you%20just%20used%20a%20local%20agent.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fbackup%2Fbackup-azure-restore-system-state%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fbackup%2Fbackup-azure-restore-system-state%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148945%22%20slang%3D%22en-US%22%3ERe%3A%20Recovering%20on%20premises%20Server%202016%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148945%22%20slang%3D%22en-US%22%3EThe%20basic%20of%20AD%20restore%20have%20not%20really%20changed%2C%20its%20unfortunate%20that%20its%20a%20physical%20server.%3CBR%20%2F%3EHow%20was%20the%20server%20backed%20up%2C%20direct%20agent%20or%20through%20DPM%20-%20More%20info%20would%20help%20explain%20what%20restore%20options%20you%20have.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20just%20used%20the%20mars%20agent%20and%20backed%20up%20the%20system%20state%2C%20then%20you%20reinstall%20the%20server%20and%20then%20the%20agent%2C%20then%20restore%20the%20system%20state.%20the%20problem%20her%20is%20that%20you%20have%20to%20insure%20that%20windows%20has%20the%20same%20update%20level%20as%20before%20or%20you%20will%20encounter%20problems.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20used%20DPM%20or%20protected%20in%20such%20a%20manner%20that%20you%20could%20restore%20it%20as%20a%20VM%2C%20i%20would%20deploy%20the%20Hyper-V%20role%20to%20you%20server%20and%20restore%20the%20entire%20DC.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148925%22%20slang%3D%22en-US%22%3ERe%3A%20Recovering%20on%20premises%20Server%202016%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148925%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20reply%20Kent.%20The%20failed%20server%20is%20a%20physical%20on%20premises%20domain%20server.%20It%20was%20used%20as%20the%20basis%20for%20building%20the%20rest%20of%20the%20domain.%20It%20has%20been%20backed%20up%20to%20the%20Azure%20environment%20but%20is%20the%20only%20AD%20domain%20server.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20had%20a%20look%20at%20the%20link%20you%20sent.%20It%20appears%20that%20this%20document%20refers%20to%20Server%202003.%20As%20the%20server%20is%20a%202016%20server%20operating%20in%20an%20Azure%20infrastructure%2C%20I%20would%20have%20thought%20there%20would%20be%20a%20be%20recovery%20mechanism%20based%20on%20modern%20AD%20constructs%20and%20drawing%20on%20the%20data%20stored%20in%26nbsp%3B%20Azure.%20Am%20I%20incorrect%20in%20this%20assumption%20and%20the%20approach%20as%20outlined%20in%20your%20document%20still%20stands%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148683%22%20slang%3D%22en-US%22%3ERe%3A%20Recovering%20on%20premises%20Server%202016%20Domain%20Controller%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148683%22%20slang%3D%22en-US%22%3E%3CP%3Eis%20it%20a%20virtual%20server%20%3F%3CBR%20%2F%3EAs%20you%20have%20lost%20your%20only%20DC%2C%20exactly%20what%20domain%20are%20your%20referring%20to%20when%20you%20say%20join%20it%20back%20to%3F%3CBR%20%2F%3E%3CBR%20%2F%3Ethis%20link%20covers%20all%20recovery%20scenarios%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fcc535164.aspx%3Ff%3D255%26amp%3BMSPPError%3D-2147217396%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fcc535164.aspx%3Ff%3D255%26amp%3BMSPPError%3D-2147217396%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegarding%20the%20Azure%20VM%26nbsp%3B%20approach%2C%20i%20would%20still%20suggest%202%20DC's.%3C%2FP%3E%0A%3CP%3Ebut%20you%20could%20have%201%20on-prem%20and%201%20in%20Azure%20over%20VPN.%3C%2FP%3E%0A%3CP%3EOnce%20you%20recover%20you%20current%20DC%2C%20you%20can%20start%20a%20new%20VM%20in%20Azure%20and%20promote%20it%20to%20a%20DC%2C%20remeber%20to%20define%20sites%20in%20your%20topology%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

I have (had) a single on premises domain controller built on Server 2016. The server was backed up to the Azure Recovery Services Vault. The on premises domain controller was the primary domain controller for my domain. 

The server has been rebuilt, but I have not yet joined it back to the domain as I am uncertain exactly what steps need to be taken to restore this and maintain the integrity of the existing AD. I have looked around online, but I have not been successful in finding a definitive guide to completing this restore operation.

Can anyone please point me to an appropriate documentation set to guide me through this process. 

I am also open the thought that perhaps this is an opportune time to migrate my AD control to an Azure VM and would be interested in thoughts on taking this approach.

I thank you all in advance for your kind assistance.

4 Replies

is it a virtual server ?
As you have lost your only DC, exactly what domain are your referring to when you say join it back to?

this link covers all recovery scenarios: https://technet.microsoft.com/en-us/library/cc535164.aspx?f=255&MSPPError=-2147217396

 

Regarding the Azure VM  approach, i would still suggest 2 DC's.

but you could have 1 on-prem and 1 in Azure over VPN.

Once you recover you current DC, you can start a new VM in Azure and promote it to a DC, remeber to define sites in your topology

Thanks for the reply Kent. The failed server is a physical on premises domain server. It was used as the basis for building the rest of the domain. It has been backed up to the Azure environment but is the only AD domain server.

 

I had a look at the link you sent. It appears that this document refers to Server 2003. As the server is a 2016 server operating in an Azure infrastructure, I would have thought there would be a be recovery mechanism based on modern AD constructs and drawing on the data stored in  Azure. Am I incorrect in this assumption and the approach as outlined in your document still stands?

The basic of AD restore have not really changed, its unfortunate that its a physical server.
How was the server backed up, direct agent or through DPM - More info would help explain what restore options you have.

If you just used the mars agent and backed up the system state, then you reinstall the server and then the agent, then restore the system state. the problem her is that you have to insure that windows has the same update level as before or you will encounter problems.

If you used DPM or protected in such a manner that you could restore it as a VM, i would deploy the Hyper-V role to you server and restore the entire DC.