dear all, sorry to "bomb" the list with queries, but was hoping to get a heads up on 
this issue of authoritative restore subsequent to a directory modification using ADC 

we are testing the procedure of rollback of a domain that has been modified using an 
ADC connection agreement

i have a backup set taken prior to the processing of the ADC CA and can confirm the 
successful restore of a DC to the prior state. (no email address in the user objects 
no CA objects etc) 

despite the fact that this data is restored authoritatively as soon as the restored DC 
is attached to the network with its DS started the data prior to the CA processing is 
overwritten with the data from an another server 

have followed what seems to be a simple process of auth restore; 

1. boot into DS restore 
2. restore system state and c: using the original location / always overwrite 
3. restart
4. boot into DS restore mode
5. run ntdsutil  / authoritative restore / restore database 

my first thought was that the ADC has created that many chages that the default 
version increment of auth restore (7000000) is not enough for the restored DC to have 
higher USN than the server that is left online 

have tried auth restore with the verinc value of 10000000 but still the old data gets 
overwritten 

any clues ??

GT 





List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to