Active Directory full forest recovery - Doubts about obscure sentence in MS documentationWindows Active Directory naming best practices?Promoting Active Directory external forest trust to full forest trustActive Directory disaster recovery with DPMDomain Controller DNS Best Practice/Practical Considerations for Domain Controllers in Child DomainsActive Directory Domain Controller in Multiple Sites - Server 2012Naming a new Active Directory forest - why is split-horizon DNS not recommended?one of the single dc per domain DCs has suffered USN rollbackAllowing LDAP authentication from DMZ to Active Directory. Is my idea secure?Active Directory migration from Windows 2003 to Windows 2016Active Directory Domain same as web domain
Pass variable to cat
Side by side histograms
How to connect an offset point symbol to its original position in QGIS?
Does any lore text explain why the planes of Acheron, Gehenna, and Carceri are the alignment they are?
Why is Colorado so different politically from nearby states?
Applicants clearly not having the skills they advertise
What are the words for people who cause trouble believing they know better?
What are the words for people who cause trouble believing they know better?
How much water is needed to create a Katana capable of cutting flesh, bones and wood?
PhD student with mental health issues and bad performance
Does the growth of home value benefit from compound interest?
Is it a problem that pull requests are approved without any comments
Did Darth Vader wear the same suit for 20+ years?
Diet Coke or water?
Can a magnetic field of an object be stronger than its gravity?
Is the decompression of compressed and encrypted data without decryption also theoretically impossible?
Align text within align
Is there any word or phrase for negative bearing?
Accidentally cashed a check twice
Personalization conditions switching doesn`t work in Experience Editor (9.1.0, Initial Release)
Regarding eBGP Multipath
Is it legal in the UK for politicians to lie to the public for political gain?
How were concentration and extermination camp guards recruited?
What happens if you do emergency landing on a US base in middle of the ocean?
Active Directory full forest recovery - Doubts about obscure sentence in MS documentation
Windows Active Directory naming best practices?Promoting Active Directory external forest trust to full forest trustActive Directory disaster recovery with DPMDomain Controller DNS Best Practice/Practical Considerations for Domain Controllers in Child DomainsActive Directory Domain Controller in Multiple Sites - Server 2012Naming a new Active Directory forest - why is split-horizon DNS not recommended?one of the single dc per domain DCs has suffered USN rollbackAllowing LDAP authentication from DMZ to Active Directory. Is my idea secure?Active Directory migration from Windows 2003 to Windows 2016Active Directory Domain same as web domain
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I am trying to apply and test best practices about Active Directory full forest recovery as warmly advised in “Best Practices for Implementing Schema Updates or : How I Learned to Stop Worrying and Love the Forest Recovery” and thoroughly explained in “AD Forest Recovery Guide”.
However, this note is to me really obscure: “Caution: Perform an authoritative (or primary) restore operation of SYSVOL only for the first DC to be restored in the forest root domain. Incorrectly performing primary restore operations of the SYSVOL on other DCs leads to replication conflicts of SYSVOL data.” (https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/ad-forest-recovery-perform-initial-recovery)
What are the motivations of not to perform an authoritative restore of SYSVOL once per domain but only once per forest (in the root domain)? SYSVOL isnt’it replicated just at the domain level? So, wouldn’t it be correct to perform an authoritative restore of one only SYSVOL for each domain of the forest (the one of the recovered DC for each domain of the forest) instead that just on the root domain? The conflict shouldn’t arise just only if I set as authoritative the SYSVOL folder in more than one DC in the same domain?
It is only a Microsoft typo (less likely but possible) or am I missing something (surely more likely)?
Thanks, Diego
active-directory disaster-recovery best-practices
add a comment |
I am trying to apply and test best practices about Active Directory full forest recovery as warmly advised in “Best Practices for Implementing Schema Updates or : How I Learned to Stop Worrying and Love the Forest Recovery” and thoroughly explained in “AD Forest Recovery Guide”.
However, this note is to me really obscure: “Caution: Perform an authoritative (or primary) restore operation of SYSVOL only for the first DC to be restored in the forest root domain. Incorrectly performing primary restore operations of the SYSVOL on other DCs leads to replication conflicts of SYSVOL data.” (https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/ad-forest-recovery-perform-initial-recovery)
What are the motivations of not to perform an authoritative restore of SYSVOL once per domain but only once per forest (in the root domain)? SYSVOL isnt’it replicated just at the domain level? So, wouldn’t it be correct to perform an authoritative restore of one only SYSVOL for each domain of the forest (the one of the recovered DC for each domain of the forest) instead that just on the root domain? The conflict shouldn’t arise just only if I set as authoritative the SYSVOL folder in more than one DC in the same domain?
It is only a Microsoft typo (less likely but possible) or am I missing something (surely more likely)?
Thanks, Diego
active-directory disaster-recovery best-practices
add a comment |
I am trying to apply and test best practices about Active Directory full forest recovery as warmly advised in “Best Practices for Implementing Schema Updates or : How I Learned to Stop Worrying and Love the Forest Recovery” and thoroughly explained in “AD Forest Recovery Guide”.
However, this note is to me really obscure: “Caution: Perform an authoritative (or primary) restore operation of SYSVOL only for the first DC to be restored in the forest root domain. Incorrectly performing primary restore operations of the SYSVOL on other DCs leads to replication conflicts of SYSVOL data.” (https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/ad-forest-recovery-perform-initial-recovery)
What are the motivations of not to perform an authoritative restore of SYSVOL once per domain but only once per forest (in the root domain)? SYSVOL isnt’it replicated just at the domain level? So, wouldn’t it be correct to perform an authoritative restore of one only SYSVOL for each domain of the forest (the one of the recovered DC for each domain of the forest) instead that just on the root domain? The conflict shouldn’t arise just only if I set as authoritative the SYSVOL folder in more than one DC in the same domain?
It is only a Microsoft typo (less likely but possible) or am I missing something (surely more likely)?
Thanks, Diego
active-directory disaster-recovery best-practices
I am trying to apply and test best practices about Active Directory full forest recovery as warmly advised in “Best Practices for Implementing Schema Updates or : How I Learned to Stop Worrying and Love the Forest Recovery” and thoroughly explained in “AD Forest Recovery Guide”.
However, this note is to me really obscure: “Caution: Perform an authoritative (or primary) restore operation of SYSVOL only for the first DC to be restored in the forest root domain. Incorrectly performing primary restore operations of the SYSVOL on other DCs leads to replication conflicts of SYSVOL data.” (https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/ad-forest-recovery-perform-initial-recovery)
What are the motivations of not to perform an authoritative restore of SYSVOL once per domain but only once per forest (in the root domain)? SYSVOL isnt’it replicated just at the domain level? So, wouldn’t it be correct to perform an authoritative restore of one only SYSVOL for each domain of the forest (the one of the recovered DC for each domain of the forest) instead that just on the root domain? The conflict shouldn’t arise just only if I set as authoritative the SYSVOL folder in more than one DC in the same domain?
It is only a Microsoft typo (less likely but possible) or am I missing something (surely more likely)?
Thanks, Diego
active-directory disaster-recovery best-practices
active-directory disaster-recovery best-practices
asked May 18 at 21:22
Diego ADiego A
83
83
add a comment |
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f967915%2factive-directory-full-forest-recovery-doubts-about-obscure-sentence-in-ms-docu%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f967915%2factive-directory-full-forest-recovery-doubts-about-obscure-sentence-in-ms-docu%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown