Exchange server in an AD backup/restore scenario

%3CLINGO-SUB%20id%3D%22lingo-sub-1480509%22%20slang%3D%22en-US%22%3EExchange%20server%20in%20an%20AD%20backup%2Frestore%20scenario%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480509%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20like%20to%20know%20the%20best%20practices%20and%20approach%20to%20the%20below%20situation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EOne%20Domain%20Controller%20in%20the%20environment%20with%20Two%20Exchange%202013%20servers%3C%2FLI%3E%3CLI%3EDue%20to%20a%20failure%2C%20the%20domain%20controller%20needs%20to%20be%20restored%20from%20a%20backup%20(30%20days%20older)%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlan%20will%20be%20to%20restore%20the%20AD%20from%20a%2030%2B%20day%20old%20backup.%20This%20is%20a%20must%20and%20noway%20to%20change.%20Due%20to%20the%2030%2B%20days%2C%20i%20believe%20there%20will%20be%20a%20trust%20relationship%20error%20when%20I%20try%20to%20connect%20the%20existing%20Exchange%20to%20the%20restored%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20Is%20it%20recommended%20and%20supported%20by%20Microsoft%20to%20reset%20computer%20account%20and%20rejoin%20Exchange%20server%20in%20case%20trust%20relationship%20issue%20comes%20up%3C%2FP%3E%3CP%3E2)%20What%20options%20are%20there%20in%20such%20a%20situation%20to%20get%20back%20Exchange%20on-track%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1480509%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3E2013%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1485308%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20server%20in%20an%20AD%20backup%2Frestore%20scenario%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1485308%22%20slang%3D%22en-US%22%3EHello%20JudeCP%2C%3CBR%20%2F%3E%3CBR%20%2F%3EApart%20from%20the%20trust%20relationship%20there%20is%20another%20problem%2C%20AD%20holds%20sequence%20numbers%20to%20keep%20track%20of%20all%20the%20updates%20done%20to%20an%20account.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20Exchange%20Server%20holds%20a%20backup%20of%20the%20Global%20Catalog%20but%20when%20you%20restore%20the%20DC%20I'm%20not%20sure%20if%20the%20AD%20accounts%20in%20the%20AD%20will%20get%20the%20updates%20from%20the%20Exchange%20Server.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20think%20the%20best%20way%20solve%20this%20is%20creating%20a%20new%20domain%20and%20Exchange%20server%2C%20this%20of%20course%20will%20require%20a%20lot%20of%20time.%3CBR%20%2F%3EYou%20will%20need%20to%20recreate%20all%20the%20users%2C%20groups%2C%20OU's%2C%20mailboxes%20etc.%3CBR%20%2F%3EThen%20copy%20the%20Exchange%20database%20from%20the%20old%20Exchange%20Server%2C%20mount%20it%20as%20a%20restore%20database%20and%20restore%20all%20mailbox%20data%20into%20the%20new%20Exchange%20Server.%3CBR%20%2F%3E%3CBR%20%2F%3EA%20broken%20domain%20is%20one%20of%20the%20hardest%20things%20to%20fix%20and%20of%20course%20the%20advice%20would%20be%20to%20create%202%20DC's%20in%20the%20future.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1485344%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20server%20in%20an%20AD%20backup%2Frestore%20scenario%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1485344%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F706541%22%20target%3D%22_blank%22%3E%40JudeCP%3C%2FA%3E%26nbsp%3BFrom%20an%20architecture%20point%20of%20view%20it%20is%20very%20unusual%20to%20have%20only%20one%20DC%20in%20an%20environment%2C%20no%20matter%20how%20small%20the%20environment%20is.%20It's%20okay%20to%20have%20one%20DC%20for%20LAB%20environment%20where%20you%20do%20not%20care%20to%20recover%20anything.%3C%2FP%3E%3CP%3EIf%20you%20had%20two%20DCs%20in%20your%20domain%2C%20in%20this%20case%20you%20just%20could%20have%20built%20a%20new%20DC%20in%20the%20existing%20domain.%20Now%20that%20you%20have%20lost%20your%20only%20DC%20of%20the%20domain%20and%20the%20backup%20you%20have%20is%20older%20than%2030%20days%2C%20you%20do%20not%20have%20any%20other%20choice!%20I%20would%20restore%20the%20DC%20and%20try%20rebooting%20the%20Exchange%20servers%20first.%20If%20still%20they%20are%20out%20of%20the%20domain%2C%20you%20have%20to%20dis-join%20and%20rejoin%20them%20again.%20Even%20if%20your%20Exchange%20severs%20start%20talking%20to%20the%20domain%20from%20windows%20perspective%2C%20you%20may%20face%20various%20issues%20with%20exchange.%20Good%20luck!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor

Hello everyone,

 

I would like to know the best practices and approach to the below situation.

 

  • One Domain Controller in the environment with Two Exchange 2013 servers
  • Due to a failure, the domain controller needs to be restored from a backup (30 days older)

 

Plan will be to restore the AD from a 30+ day old backup. This is a must and noway to change. Due to the 30+ days, i believe there will be a trust relationship error when I try to connect the existing Exchange to the restored AD.

 

1) Is it recommended and supported by Microsoft to reset computer account and rejoin Exchange server in case trust relationship issue comes up

2) What options are there in such a situation to get back Exchange on-track

 

Thank you.

2 Replies
Highlighted
Hello JudeCP,

Apart from the trust relationship there is another problem, AD holds sequence numbers to keep track of all the updates done to an account.

The Exchange Server holds a backup of the Global Catalog but when you restore the DC I'm not sure if the AD accounts in the AD will get the updates from the Exchange Server.

I think the best way solve this is creating a new domain and Exchange server, this of course will require a lot of time.
You will need to recreate all the users, groups, OU's, mailboxes etc.
Then copy the Exchange database from the old Exchange Server, mount it as a restore database and restore all mailbox data into the new Exchange Server.

A broken domain is one of the hardest things to fix and of course the advice would be to create 2 DC's in the future.
Highlighted

@JudeCP From an architecture point of view it is very unusual to have only one DC in an environment, no matter how small the environment is. It's okay to have one DC for LAB environment where you do not care to recover anything.

If you had two DCs in your domain, in this case you just could have built a new DC in the existing domain. Now that you have lost your only DC of the domain and the backup you have is older than 30 days, you do not have any other choice! I would restore the DC and try rebooting the Exchange servers first. If still they are out of the domain, you have to dis-join and rejoin them again. Even if your Exchange severs start talking to the domain from windows perspective, you may face various issues with exchange. Good luck!