USN Rollbacks – Best Practice


I was talking best practices the other day with a customer with regards to what Backup Software to use and the use of Virtualized hosting environments. I recommended to the customer to utilise backup software that uses the Microsoft APIs, or the Software that uses the Microsoft Volume Shadow Copy APIs. If you use Active Directory aware backup programs that use these APIs, then the invocation I.D. is reset before the Active Directory is restarted. Because of this, the “restored” Domain Controller identifies itself as a new Domain Controller . This will prompt the other Domain Controllers to bring the “restored” domain controller up-to-date. 


If this best practice is not followed then you could be in the situation of having to deal with USN Rollbacks. This is a condition that occurs when the Active Directory Domain Controller has not correctly reset its Invocation I.D. before the Active Directory starts. The Active Directory uses a combination of USN,s and invocation I.D.s to track changes to the Active Directory that need to be replicated.


What is the Invocation I.D.?


Well this  ID identifies the version of the Directory Database. If a domain controller is restored from a system state backup then all is well and the i.d. is reset and will trigger replication from its partner DCs; however the situations highlighted below do not do this as a matter of course, and this is where potential problems can occur. (This was extracted from the Kb article 885875 that I recommend to be read to learn more about USN Rollbacks and how to recover from them.)


Software and methodologies that cause USN rollbacks

When the following environments, programs, or subsystems are used, administrators can bypass the checks and validations that Microsoft has designed to occur when the domain controller system state is restored:

•Virtualized hosting environments, including but not limited to Microsoft Virtual Server 2005 and EMC VMWARE

•Software that backs up and restores an Active Directory operating system installation or a hard disk volume that contains that installation
Note Such software includes but is not limited to Norton Ghost.

•Advanced disk subsystems that can selectively copy a volume that contains an Active Directory operating system installation that was saved in the past

The following operations are not supported:

1.Starting an Active Directory domain controller whose operating system was restored to a hard disk by using an imaging program such as Norton Ghost

2.Starting an Active Directory domain controller whose operating system resides in a virtualized hosting environment such as Microsoft Virtual PC, Microsoft Virtual Server 2005, or EMC VMWARE

3.Starting an Active Directory domain controller that is located on a volume where the disk subsystem loads using previously saved images of the operating system without requiring a system state restoration of Active Directory.

So recommendation is,

Thoroughly evaluate your re.tore strategy and software to ensure it follows recommended Best Practice, and utilises the Microsoft APIs,

Comments (5)

  1. ssddfdf says:

    http://www.screencast.com/t/gAX1ovxR9Z
    https://www.rebelmouse.com/WatchDarkPlacesOnline/
    http://www.screencast.com/t/UtQ9csdg
    https://www.facebook.com/WatchTed2OnlineNow
    https://www.rebelmouse.com/WatchPaperTownsOnline/
    https://www.rebelmouse.com/WatchMaxOnline/
    http://www.screencast.com/t/HhfTcWzVT
    https://www.linkedin.com/grp/post/6971553-6011498080841510914
    https://www.linkedin.com/grp/post/6973703-6017392948025507843
    https://www.rebelmouse.com/WatchTed2Online/
    https://www.rebelmouse.com/WatchHitmanAgent47Online/
    http://www.screencast.com/t/iDwnAz9uCX
    http://www.screencast.com/t/7HJHoJAX3Zdh
    https://www.facebook.com/WatchRickiAndTheFlashOnline
    https://www.rebelmouse.com/WatchAmyOnline/
    https://www.linkedin.com/grp/post/6981021-6017293164958732291
    http://www.screencast.com/t/IXgnchZvJ5Qi
    http://www.screencast.com/t/sd6SU3y6X
    https://www.facebook.com/WatchTheVisitOnline
    https://www.linkedin.com/grp/post/6975089-6015035619363807236
    https://www.rebelmouse.com/WatchMagicMikeXXLOnline/
    https://www.linkedin.com/grp/post/8337129-6017937517842567170
    https://www.rebelmouse.com/WatchAntmanOnline/
    https://www.facebook.com/WatchMinionsOnlineNow
    https://www.rebelmouse.com/WatchRegressionOnline/
    https://www.linkedin.com/grp/post/6980115-6017735463568158724
    https://www.rebelmouse.com/MazeRunner2TheScorchTrials/
    https://www.rebelmouse.com/WatchAmericanUltraOnline/
    https://www.rebelmouse.com/MissionImpossible5RogueNation/
    https://www.rebelmouse.com/WatchSouthpawOnline/
    https://www.facebook.com/WatchSouthpawOnline
    http://www.screencast.com/t/KBqVeCR8
    https://www.rebelmouse.com/WatchSelflessOnline/
    https://www.facebook.com/WatchMaxOnline
    https://www.facebook.com/WatchTheGallowsOnline
    http://www.screencast.com/t/TvvvXobmy
    https://www.rebelmouse.com/WatchTheManFromUncleOnline/
    https://www.linkedin.com/grp/post/8338032-6017247400261926914
    https://www.linkedin.com/grp/post/8338032-6017243258827141124
    http://www.screencast.com/t/Bq3Crb0cMJXo
    http://www.screencast.com/t/tzQwd7gc
    https://www.facebook.com/WatchTheManFromUncleOnline
    https://www.rebelmouse.com/WatchBlackMassOnline/
    http://www.screencast.com/t/vEPTLb3hZyA
    https://www.linkedin.com/grp/post/8337129-6017929691594260480
    https://www.facebook.com/WatchAmyOnline
    http://www.screencast.com/t/1tvetqjg
    https://www.linkedin.com/grp/post/6980115-6017745897104883716
    http://www.screencast.com/t/8e9fKhj56
    http://www.screencast.com/t/K2c4nAMn

  2. qweeqw says:

    https://www.pinterest.com/pin/84583299228836034/
    https://www.pinterest.com/pin/350647520966520566/
    https://www.pinterest.com/pin/442830575838906399/
    https://www.facebook.com/1491549824497510
    https://www.pinterest.com/pin/503840277041035125/
    http://www.screencast.com/t/Uvgv9VQMk
    https://www.pinterest.com/pin/442830575838892404/
    http://www.screencast.com/t/IN2G7JkE
    http://www.screencast.com/t/O9ipuey2PEw6
    https://www.pinterest.com/pin/160511174196348390/
    http://www.screencast.com/t/H5A2Leg1
    https://www.facebook.com/1483738308615435
    https://www.facebook.com/1483378001984799
    https://www.pinterest.com/pin/50665564535280885/
    http://www.screencast.com/t/iog3Tzgyt8c
    http://www.screencast.com/t/2vDNVGIPpv
    http://www.screencast.com/t/3mgzI5fBio
    https://www.facebook.com/1491489597836866
    https://www.facebook.com/1490740151245423
    https://www.facebook.com/1488520981470758
    https://www.pinterest.com/pin/160511174196343301/
    https://www.pinterest.com/pin/160511174196343360/
    https://www.facebook.com/1485688141756108
    http://www.screencast.com/t/wXIlLTGvEE
    https://www.pinterest.com/pin/442830575838892602/
    http://www.screencast.com/t/3kcwgMAHc
    https://www.pinterest.com/pin/350647520966531111/
    http://www.screencast.com/t/Jo0fbIEQW3sY
    http://www.screencast.com/t/OiTS966mMqzb
    https://www.facebook.com/1493076994343973
    http://www.screencast.com/t/rwd99TuHEuah
    http://www.screencast.com/t/3qBTI1UhP
    https://www.pinterest.com/pin/350647520966521281/
    http://www.screencast.com/t/pSq6ogUZq
    https://www.pinterest.com/pin/160511174196344179/
    http://www.screencast.com/t/MPmPqUn2m
    http://www.screencast.com/t/XLfXOOaI
    https://www.pinterest.com/pin/503840277041035380/
    http://www.screencast.com/t/kn74ku2uBGA
    https://www.facebook.com/1491477197838106
    https://www.facebook.com/1493388580979481
    http://www.screencast.com/t/iHzKLbLEs
    https://www.facebook.com/1488561881466668
    https://www.pinterest.com/pin/160511174196347899/
    https://www.facebook.com/1493803650941448
    https://www.pinterest.com/pin/160511174196344036/
    https://www.facebook.com/1485803235077932
    https://www.facebook.com/1488529198136603
    http://www.screencast.com/t/hTxOoXf9B
    https://www.facebook.com/1488508034805386