recovery manager for ad

Recovery Manager for Active Directory

Maintain cyber resilience with comprehensive Active Directory (AD) backup software. Backing up AD and restoring object and attribute levels is a lot easier when you have the right AD backup tools. Quest® Recovery Manager for Active Directory is like an insurance plan for your AD environment. It not only enables you to back up AD at the object and attribute level, but also helps you pinpoint changes to your AD environment at the same granular level. Perfect for routine recovery needs (for comprehensive forest-wide disaster recovery solutions, we've got you covered too).

Mistakes and disasters happen.

Your AD environment can be damaged when an administrator accidentally deletes something or makes a mass update that goes wrong. This can impact your productivity for hours or even days, and as a result, cost your company revenue and its reputation. When it happens, you need a disaster recovery plan and Active Directory backup tools to restore your AD environment and get your AD back up and running quickly. Recovery Manager for Active Directory helps you do exactly that, all while reducing recovery time and costs to reduce user impact. With Recovery Manager, you’ll know what happened, who is impacted and what to fix. 

text image recovery manager for ad

Recovery Manager is built for modern threats

55
%

Of data breaches caused by insiders

95
M

AD accounts under attack daily

14
sec

Another ransomware attack occurs

Key Benefits

SVG

Reduce downtime

Restore any object with this Active Directory backup tool and get affected users back to work quickly without restarting domain controllers.
SVG

Accelerate recovery

Quickly pinpoint deleted or changed objects or attributes using point-in-time recovery.
SVG

Granular restore

Restore only the required attributes without restarting domain controllers with Active Directory backup tools that give you deep restore flexibility.

Highlighted Features

SVG
Comprehensive recovery
Back up Active Directory fast, restore any object, and eliminate downtime without restarting domain controllers.
SVG
Flexible backup strategies for optimal data protection
Quest's Recovery Manager offers flexible Active Directory backup tool options — full, incremental, cloud, or on-premises — for continuity with zero disruption.
SVG
Hybrid AD and Entra ID recovery
Quest On Demand Recovery protects hybrid and cloud-only Entra ID objects, with one dashboard for seamless backup and restore.
SVG
Comparison reporting
Compare AD backups, pinpoint deleted or changed objects fast, and identify who made changes with Change Auditor.
SVG
Recovery console fault tolerance
Share configuration data across recovery consoles to quickly resume interrupted restore operations without losing progress.
SVG
Recovery roadmap
Generate detailed recovery reports covering every stage, giving you full visibility and control over your Active Directory backup software process.

Knowledge Center

Body

Get started now

FAQ

Windows Server 2008 R2 included a particularly welcome enhancement, AD Recycle Bin restore, which enables restore of some recently deleted Active Directory objects. To facilitate object recovery in cloud-based environments, Microsoft provides the Entra ID Recycle Bin, which offers similar but not identical functionality to its on-premises sibling.

The Active Directory and Entra ID Recycle Bins are extremely valuable in certain situations. If an AD object, such as a user account, has been mistakenly deleted, for instance, you might be able to restore the object from the AD or Entra ID Recycle Bin. However, the Microsoft Recycle Bin is not, and was never intended to, replace Active Directory backup tools.

To ensure comprehensive protection against data loss, it's crucial to implement a robust backup strategy that includes regular full backups, incremental backups, and offsite storage. This approach, combined with encryption and archiving practices, provides a more complete backup and recovery solution for your Active Directory environment.

Testing your Active Directory backup software and recovery plan is critical for maintaining business continuity. Here's when you should conduct testing:

Minimum recommendation: At least twice per year

Additional testing recommended after:     

  • Major infrastructure or system changes
  • Data loss or corruption incidents
  • Implementation of new backup/recovery technologies
  • Significant business operation changes
  • Disruptive events (cyberattacks, natural disasters, power outages)

Regular testing ensures your recovery procedures remain effective and your team stays prepared for potential disruptions.

Routine Active Directory backup and recovery is designed for smaller incidents, such as when individual domain controllers are affected or specific objects need restoration. This approach addresses day-to-day operational issues and mistakes.

Active Directory disaster recovery, by contrast, is comprehensive and handles catastrophic scenarios requiring entire forest, operating system, and schema recovery. A robust disaster recovery solution should provide multiple restoration options, including clean OS restore capabilities and bare metal recovery for complete system rebuilding.

Before installing Recovery Manager for Active Directory, ensure that your system meets the following minimum hardware and software requirements.

NOTE

  • Recovery Manager for Active Directory supports only IPv4 or mixed IPv4/IPv6 networks.

Processor

Minimum: 2.0 GHz

Recommended: 2.0 GHz or faster

CPU Cores

Minimum: 2 CPU cores

Recommended: 4 CPU cores

Memory

Minimum: 4 GB

Recommended: 8 GB

These figures apply only if the Active Directory domains managed by Recovery Manager for Active Directory include 1 million objects or less. Increase RAM size by 512 MB for every additional 1 million objects.

Hard Disk Space

Full installation including the prerequisite software: 2.7 GB of free disk space

In case all the prerequisite software is already installed: 260 MB of free disk space

NOTE Additional storage space is required for a backup repository, at least the size of the backed-up Active Directory database file (Ntds.dit) and the SYSVOL folder plus 40MB for the transaction log files.

Operating System

  • Machine that hosts the Recovery Manager for Active Directory console must have same or higher version of Windows operating system than the processed domain controllers. Otherwise, the online compare and object search in a backup during the online restore operation may fail.
  • 32-bit operating systems are not supported.

Installation

  • Microsoft Windows Server® 2025, 2022, 2019, and 2016

Targets for backup, restore, or compare operations

  • Microsoft Windows Server® 2025, 2022, 2019, and 2016 (including Server Core installation)

Microsoft .NET Framework

Microsoft .NET Framework version 4.8 or higher is needed on the console system.

NOTE: Microsoft .NET 4.8 is not required to be installed on the systems where the Forest Recovery and Backup agents are to be installed. The Secure Storage Agent does use .NET and it is recommended to install 4.8 on the Secure Storage system, but the agent will work with older versions.

Microsoft Windows PowerShell

Microsoft Windows PowerShell version 5.0 or later

Integration with Change Auditor for Active Directory

Supported versions of Change Auditor for Active Directory: from 6.x to 7.x.

If any prerequisite software is not installed, the Setup program automatically installs it for you before installing Recovery Manager for Active Directory. If the prerequisite software to be installed is not included in this release package, it is automatically downloaded.

Continuous recovery: From version 10.0.1, Recovery Manager for Active Directory together with Change Auditor can restore the deleted object(s) and continuously restores the last change (if any) that was made to the object attributes after creating the backup, using the data from the Сhange Auditor database.

Antivirus software that is supported for backup antimalware checks

The anti-virus checks are performed on the Forest Recovery Console machine running Windows Server 2016 or higher by means of antivirus software installed on the machine.

  • Microsoft Defender
  • Symantec Endpoint Protection 14.x
  • Broadcom Endpoint Security (former name: Symantec Endpoint Protection 15)

Supported server management systems

  • Integrated Dell Remote Access Controller (iDRAC) 8 and 9
  • HP ProLiant iLO Management Engine (iLO) 3, 4 and 5
  • VMware vCenter/ESX Server 6.0, 6.5, 6.7, 7.0 and 8.0
  • Microsoft Hyper-V Server 2016 or higher

Memory

1 GB (2 GB recommended)

Hard disk space

2 GB or more

Operating System

One of the following operating systems:

Microsoft Windows Server® 2025, 2022, 2019, and 2016 (including Server Core installation)

Secure Storage Server

Processor

Minimum: 2.0 GHz

Recommended: 2.0 GHz or faster

CPU Cores

Minimum: 2 CPU cores

Recommended: 4 CPU cores

Memory

Minimum: 4 GB

Recommended: 8 GB

  • Operating system: Microsoft Windows 2016 or higher
  • A stand-alone server to be used as your Secure Storage server. This server should be a workgroup server and not joined to an Active Directory domain.
  • An account that will be used to deploy the Storage Agent on the Secure Storage server. This account must also be a local Administrator on the Secure Storage server.
  • Physical access to the Secure Storage server. Once the server is hardened access with regular methods will be disabled.
  • Sufficient storage space on the Secure Storage server for all backup files. For one backup file, the space required is at least the size of the backed-up Active Directory database file (Ntds.dit) and the SYSVOL folder plus 40MB for the transaction log files.

Cloud Storage

  • Internet access available on the Recovery Manager for Active Directory console. A standard outbound HTTPS port 443 is used to upload data to Azure Blob and Amazon Web Services S3 Storage.
  • Azure and Amazon Web Services subscription(s) to create and manage Azure and Amazon Web Services S3 Storage accounts and containers.
  • A method of creating and managing Azure and Amazon S3 Storage accounts, containers, and policies for the storage account (lifecycle, immutability and replication policies).

VMware vCenter® / VMware ESX® Server 6.0, 6.5, 6.7, 7.0 and 8.0

  • VMware vCenter® Converter™ 6.2 must be installed in your environment using the Client-Server installation setup option.
  • If the TLS 1.0 protocol is disabled on VMware vCenter® Converter™ and VMware vCenter® servers, then switch to TLS 1.2. For more details on TLS 1.2, see the following KB article:

Microsoft Security Advisory 2960358

You can only use the Password and SIDHistory Recoverability Tool if Microsoft's Active Directory Recycle Bin is not enabled in your environment.

Recovery Manager for Active Directory Disaster Recovery Edition is upgradeable from version 10.1 or later.