Mistakes and disasters happen.
Your AD environment can be damaged when an administrator accidentally deletes something or makes a mass update that goes wrong. This can impact your productivity for hours or even days, and as a result, cost your company revenue and its reputation. When it happens, you need a disaster recovery plan and Active Directory backup tools to restore your AD environment and get your AD back up and running quickly. Recovery Manager for Active Directory helps you do exactly that, all while reducing recovery time and costs to reduce user impact. With Recovery Manager, you’ll know what happened, who is impacted and what to fix.
Recovery Manager is built for modern threats
Of data breaches caused by insiders
AD accounts under attack daily
Another ransomware attack occurs
Knowledge Center
Get started now
FAQ
Windows Server 2008 R2 included a particularly welcome enhancement, AD Recycle Bin restore, which enables restore of some recently deleted Active Directory objects. To facilitate object recovery in cloud-based environments, Microsoft provides the Entra ID Recycle Bin, which offers similar but not identical functionality to its on-premises sibling.
The Active Directory and Entra ID Recycle Bins are extremely valuable in certain situations. If an AD object, such as a user account, has been mistakenly deleted, for instance, you might be able to restore the object from the AD or Entra ID Recycle Bin. However, the Microsoft Recycle Bin is not, and was never intended to, replace Active Directory backup tools.
To ensure comprehensive protection against data loss, it's crucial to implement a robust backup strategy that includes regular full backups, incremental backups, and offsite storage. This approach, combined with encryption and archiving practices, provides a more complete backup and recovery solution for your Active Directory environment.
Testing your Active Directory backup software and recovery plan is critical for maintaining business continuity. Here's when you should conduct testing:
Minimum recommendation: At least twice per year
Additional testing recommended after:
- Major infrastructure or system changes
- Data loss or corruption incidents
- Implementation of new backup/recovery technologies
- Significant business operation changes
- Disruptive events (cyberattacks, natural disasters, power outages)
Regular testing ensures your recovery procedures remain effective and your team stays prepared for potential disruptions.
Routine Active Directory backup and recovery is designed for smaller incidents, such as when individual domain controllers are affected or specific objects need restoration. This approach addresses day-to-day operational issues and mistakes.
Active Directory disaster recovery, by contrast, is comprehensive and handles catastrophic scenarios requiring entire forest, operating system, and schema recovery. A robust disaster recovery solution should provide multiple restoration options, including clean OS restore capabilities and bare metal recovery for complete system rebuilding.
Before installing Recovery Manager for Active Directory, ensure that your system meets the following minimum hardware and software requirements.
NOTE
- Recovery Manager for Active Directory supports only IPv4 or mixed IPv4/IPv6 networks.
Processor
Minimum: 2.0 GHz
Recommended: 2.0 GHz or faster
CPU Cores
Minimum: 2 CPU cores
Recommended: 4 CPU cores
Memory
Minimum: 4 GB
Recommended: 8 GB
These figures apply only if the Active Directory domains managed by Recovery Manager for Active Directory include 1 million objects or less. Increase RAM size by 512 MB for every additional 1 million objects.
Hard Disk Space
Full installation including the prerequisite software: 2.7 GB of free disk space
In case all the prerequisite software is already installed: 260 MB of free disk space
NOTE Additional storage space is required for a backup repository, at least the size of the backed-up Active Directory database file (Ntds.dit) and the SYSVOL folder plus 40MB for the transaction log files.
Operating System
- Machine that hosts the Recovery Manager for Active Directory console must have same or higher version of Windows operating system than the processed domain controllers. Otherwise, the online compare and object search in a backup during the online restore operation may fail.
- 32-bit operating systems are not supported.
Installation
- Microsoft Windows Server® 2025, 2022, 2019, and 2016
Targets for backup, restore, or compare operations
- Microsoft Windows Server® 2025, 2022, 2019, and 2016 (including Server Core installation)
Microsoft .NET Framework
Microsoft .NET Framework version 4.8 or higher is needed on the console system.
NOTE: Microsoft .NET 4.8 is not required to be installed on the systems where the Forest Recovery and Backup agents are to be installed. The Secure Storage Agent does use .NET and it is recommended to install 4.8 on the Secure Storage system, but the agent will work with older versions.
Microsoft Windows PowerShell
Microsoft Windows PowerShell version 5.0 or later
Integration with Change Auditor for Active Directory
Supported versions of Change Auditor for Active Directory: from 6.x to 7.x.
If any prerequisite software is not installed, the Setup program automatically installs it for you before installing Recovery Manager for Active Directory. If the prerequisite software to be installed is not included in this release package, it is automatically downloaded.
Continuous recovery: From version 10.0.1, Recovery Manager for Active Directory together with Change Auditor can restore the deleted object(s) and continuously restores the last change (if any) that was made to the object attributes after creating the backup, using the data from the Сhange Auditor database.
Antivirus software that is supported for backup antimalware checks
The anti-virus checks are performed on the Forest Recovery Console machine running Windows Server 2016 or higher by means of antivirus software installed on the machine.
- Microsoft Defender
- Symantec Endpoint Protection 14.x
- Broadcom Endpoint Security (former name: Symantec Endpoint Protection 15)
Supported server management systems
- Integrated Dell Remote Access Controller (iDRAC) 8 and 9
- HP ProLiant iLO Management Engine (iLO) 3, 4 and 5
- VMware vCenter/ESX Server 6.0, 6.5, 6.7, 7.0 and 8.0
- Microsoft Hyper-V Server 2016 or higher
Memory
1 GB (2 GB recommended)
Hard disk space
2 GB or more
Operating System
One of the following operating systems:
Microsoft Windows Server® 2025, 2022, 2019, and 2016 (including Server Core installation)
Secure Storage Server
Processor
Minimum: 2.0 GHz
Recommended: 2.0 GHz or faster
CPU Cores
Minimum: 2 CPU cores
Recommended: 4 CPU cores
Memory
Minimum: 4 GB
Recommended: 8 GB
- Operating system: Microsoft Windows 2016 or higher
- A stand-alone server to be used as your Secure Storage server. This server should be a workgroup server and not joined to an Active Directory domain.
- An account that will be used to deploy the Storage Agent on the Secure Storage server. This account must also be a local Administrator on the Secure Storage server.
- Physical access to the Secure Storage server. Once the server is hardened access with regular methods will be disabled.
- Sufficient storage space on the Secure Storage server for all backup files. For one backup file, the space required is at least the size of the backed-up Active Directory database file (Ntds.dit) and the SYSVOL folder plus 40MB for the transaction log files.
Cloud Storage
- Internet access available on the Recovery Manager for Active Directory console. A standard outbound HTTPS port 443 is used to upload data to Azure Blob and Amazon Web Services S3 Storage.
- Azure and Amazon Web Services subscription(s) to create and manage Azure and Amazon Web Services S3 Storage accounts and containers.
- A method of creating and managing Azure and Amazon S3 Storage accounts, containers, and policies for the storage account (lifecycle, immutability and replication policies).
VMware vCenter® / VMware ESX® Server 6.0, 6.5, 6.7, 7.0 and 8.0
- VMware vCenter® Converter™ 6.2 must be installed in your environment using the Client-Server installation setup option.
- If the TLS 1.0 protocol is disabled on VMware vCenter® Converter™ and VMware vCenter® servers, then switch to TLS 1.2. For more details on TLS 1.2, see the following KB article:
You can only use the Password and SIDHistory Recoverability Tool if Microsoft's Active Directory Recycle Bin is not enabled in your environment.
Recovery Manager for Active Directory Disaster Recovery Edition is upgradeable from version 10.1 or later.