Last Update: Sep 17, 2024 | Published: Jan 06, 2009
Backing up Active Directory is essential to maintain the proper health of the Active Directory database. You can backup Active Directory by using the NTBACKUP tool that comes built-in with Windows Server 2003, or use any 3rd-party tool that supports this feature. Backing up the Active Directory is done on one or more of your Active Directory domain Controllers (or DCs), and is performed by backing up the System State on those servers. The System State contains the local Registry, COM+ Class Registration Database, the System Boot Files, certificates from Certificate Server (if it’s installed), Cluster database (if it’s installed), NTDS.DIT, and the SYSVOL folder.
To ensure your ability to actually use this backup, you must be aware of the tombstone lifetime. By default, the tombstone is 60 days (for Windows 2000/2003 DCs), or 180 days (for Active Directory based upon Windows Server 2003 SP1 DCs).
Note: Longer tombstone lifetime decreases the chance that a deleted object remains in the local directory of a disconnected DC beyond the time when the object is permanently deleted from online DCs. The tombstone lifetime is not changed automatically when you upgrade to Windows Server 2003 with SP1, but you can change the tombstone lifetime manually after the upgrade. New forests that are installed with Windows Server 2003 with SP1 have a default tombstone lifetime of 180 days. Read my “Changing the Tombstone Lifetime Attribute in Active Directory” article for more info on that.
Any backup older than 60/180 days is not a good backup and cannot be used to restore any DC. You do not need to backup all your DCs’ System States, usually backing up the first DC in the Forest + the first DCs in each domain is enough for most scenarios.
You need a current, verified, and reliable backup to:
All these are reasons to have good working and reliable backups.
Note: One of the Active Directory features that was introduced in Windows Server 2003 with Service Pack 1 was the Directory Service Backup Reminders. With this reminder, a new event message, event ID 2089, provides the backup status of each directory partition that a domain controller stores. This includes application directory partitions and Active Directory Application Mode (ADAM) partitions. If halfway through the tombstone lifetime a partition has not been backed up, this event is logged in the Directory Service event log and continues daily until the partition is backed up.
Note: You can only back up the System State data on a local computer. You cannot back up the System State data on a remote computer.
Next, you need to properly label and secure the backup file/tape and if possible, store a copy of it on a remote and secure location.
You can use the command line version of NTBACKUP in order to perform backups from the Command Prompt.
For example, to create a backup job named “System State Backup Job” that backs up the System State data to the file D:system_state_backup.bkf, type:
ntbackup backup systemstate /J "System State Backup Job" /F "D:system_state_backup.bkf"
For Microsoft’s official documentation on Active Directory backups, see: Active Directory Operations Guide – Active Directory Backup and Restore