Skip to main content
AD Academy
Day-to-day administration of AD
Beginner14 minLast updated: Topic 4 of 4

Backup and Restore of Active Directory

System State, Authoritative Restore, and AD Recycle Bin.

Not read

What you will learn here

  • What to back up in AD (System State)
  • Normal vs Authoritative restore
  • How AD Recycle Bin saves a deleted object

Worth reading first:Password policy and Fine-Grained Password Policy

Accidental deletion of an entire OU happens. Three safety nets: Recycle Bin for quick restore, System State backup for full restore, and DSRM for disaster scenarios.

# Enable Recycle Bin (one-time, irreversible action)
Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target "lab.local"

# Restore deleted object
Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "*Levi*"' -IncludeDeletedObjects |
  Restore-ADObject

# System State Backup (including NTDS.dit database)
wbadmin start systemstatebackup -backuptarget:E: -quiet
powershell
Architecture and Theory — Under the Hood

backup is not just the NTDS file — it is System State: NTDS.dit, SYSVOL, Registry, IIS Metabase, COM+, Certificate Services. Windows Server Backup (WSB) knows how to back up and restore this as standard.

  • Non-Authoritative Restore — DC restores itself, then receives updates from other up-to-date DCs.
  • Authoritative Restore — Marks an object (e.g., an accidentally deleted OU) as 'the correct version' so it replicates to everyone.
  • Recycle Bin — Solves 95% of accidental deletions without the need for a true Restore (180-day default window).
  • IFM (Install From Media) — Setting up a new DC from a backup, without replicating the entire domain over the network.
Practical Configuration (PowerShell / GUI)
# Installation
Install-WindowsFeature Windows-Server-Backup

# Full System State backup to external drive
wbadmin start systemstatebackup -backupTarget:E: -quiet

# Display backups
wbadmin get versions

# Authoritative restore of a deleted OU (Safe Mode / DSRM)
ntdsutil
  activate instance ntds
  authoritative restore
  restore subtree "OU=IT,DC=corp,DC=local"
  quit
  quit

# Quick restore from Recycle Bin (Bin enabled)
Get-ADObject -Filter {Deleted -eq $true -and Name -like '*Marketing*'} -IncludeDeletedObjects |
  Restore-ADObject
powershell
Real-world Scenarios in an Organization
  • Accidental OU deletion → Recycle Bin (if enabled) → Restore-ADObject.
  • Hardware failure of a single DC → Raise a new DC with IFM from up-to-date media, seize FSMO roles if needed.
  • Ransomware — Restore from offline backup and isolate DCs until recovery.
Troubleshooting
  • After restore: dcdiag /v and repadmin /replsummary — to ensure replication has resumed.
  • If we restore DC and the result is USN Rollback → identify in event 2095, isolate and rebuild.
  • Recycle Bin not available → check Get-ADOptionalFeature.
Glossary and Quick Command Line
  • System State = everything needed for DC.
  • IFM = setting up a new DC without replicating from scratch.
  • seize FSMO = forced takeover when the original DC is dead.
  • Recycle Bin enabled = mandatory in every modern domain.

Check yourself

What does a DC's System State backup contain?

Was this page helpful?