Application protection for Active Directory domain controllers
Data Protection for VMware provides back up and restore protection for VMs that host Microsoft Active Directory Domain Controllers in both stand-alone and clustered environments. A clustered environment contains multiple domain controllers that participate in Active Directory.
Non-authoritative restore recovers the Active Directory (or domain controller) to the version taken at the time of the backup. When the recovered Active Directory (or domain controller) is restored, it is updated with information from the other domain controllers through the existing replication process.
Environment requirements
Data Protection for VMware protects Windows VM guests that host Active Directory Domain Controllers. The following guest versions that host Active Directory Domain Controllers are supported:
Microsoft
Windows Server 2012
A current version of VMware Tools must be installed and must be running on
the VM guest at the time that it is backed up. This VM guest must be powered on for Data Protection for VMware to detect Active Directory. Otherwise, Active
Directory will not be detected and restore protection will be unavailable.
Active Directory on Microsoft
Windows Server versions 2016 and later require no special
support.
Restriction:
When a VM guest contains Active Directory or a domain controller, ensure that Windows NT Directory Services (NTDS) is running so that the
VSS backups and domain controller discovery can function correctly. You cannot use application
protection for domain controllers to complete these tasks:
- Run a file restore of Active Directory objects
- Back up and restore VMs that run Active Directory Lightweight Directory Services (AD LDS)
- Recover expired Active Directory tombstone objectsTip: To help prevent Active Directory objects from expiring, run backups more frequently than the default tombstone life of 60 days.
- Run a full VM instant restore operation