Disaster REcovery AD

N

Nico

I have been doing disaster recovery testing in a test
environent in a worst-case senario instants. All of our
servers our distroyed and I need to recover our whole
domain from backup. I am using like equipment for the
domain controller. The first pass was a complete success,
but now I cannot recreate it.

My plan is to rebuild the first domain controller. promote
a second domain controller and then build my exchange
server using the disasterrecovery option.

I have rebuild my dc and then booted to ad repaire mode
and restored from backup the c: drive and the system state
marking the sysvol as primary. I am doing a non-
authoritative restore. After the restore is complete I
am getting SAM and DNS errors.

Error: 16650. The account-allocator failed to initialize
and it will deny account creation.

I don't know how repair this. I why this happened. Should
I be doing an Autoritative Restore if I am rebuilding my
domain from scatch?

Thanks.
 
M

Matjaz Ladava [MVP]

This is, because RID master could not replicate with other DC's in a domain.
SP4 changed this and now after you restore AD from backup, RID master tries
to sync with all DC's in a domain before it can come online. use repadmin
/showreps on restored DC to see al replication partners. If they are not all
online, then RID master won't come online. Remove other DC's from your AD
(if this is a test) using
http://support.microsoft.com/default.aspx?scid=kb;en-us;216498,
otherwise you have to bring all DC's back online .

--
Regards

Matjaz Ladava, MCSE, MCSA, MCT, MVP
Microsoft MVP - Active Directory
(e-mail address removed), (e-mail address removed)
http://ladava.com
 
G

Guest

This worked. Thanks
-----Original Message-----
This is, because RID master could not replicate with other DC's in a domain.
SP4 changed this and now after you restore AD from backup, RID master tries
to sync with all DC's in a domain before it can come online. use repadmin
/showreps on restored DC to see al replication partners. If they are not all
online, then RID master won't come online. Remove other DC's from your AD
(if this is a test) using
http://support.microsoft.com/default.aspx?scid=kb;en-us% 3b216498,
otherwise you have to bring all DC's back online .

--
Regards

Matjaz Ladava, MCSE, MCSA, MCT, MVP
Microsoft MVP - Active Directory
(e-mail address removed), (e-mail address removed)
http://ladava.com




.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top