Procedure for Disaster Recovery Plan
Procedure Disaster Recovery Plan
Name
Versi Approv Owner Date Review Next Comments
on ed By Last Frequen Review
Updat cy
ed
Classification: Confidential
This document should be restricted to those with a specific need.
Disaster Recovery Plan for Domain Controller using Veeam
Backup and Restore
Objective
Ensure the rapid restoration of the Domain Controller (DC) in the event of
failure, minimizing downtime and data loss.
1. Pre-Implementation Steps
1. Evaluate the Environment
Identify the Domain Controller(s) and their roles (e.g., FSMO
roles).
Assess storage, network configurations, and dependencies.
2. Install and Configure Veeam Backup & Restore
Deploy Veeam on a dedicated server or virtual machine.
Configure Veeam Backup & Replication with sufficient storage
space for backups.
3. Prepare Backup Storage
Use a redundant and secure backup storage solution (e.g.,
NAS, cloud repository).
Enable immutability for backups to protect against
ransomware.
2. Backup Strategy for the Domain Controller
1. Create a Backup Job
Select the Domain Controller VM or physical machine as the
target.
Choose an incremental backup method with periodic full
backups.
Enable Application-Aware Processing to ensure consistent
backups of Active Directory databases.
2. Schedule and Retention
Schedule backups during off-peak hours to minimize impact.
Retain daily backups for 7 days, weekly backups for 4 weeks,
and monthly backups for 6 months.
3. Test Backups
Perform regular restore tests to validate the integrity of
backups.
3. Restoration Procedure
1. Identify the Issue
Diagnose the failure (hardware failure, corruption, or
ransomware).
Verify whether a full restore or granular recovery is needed.
2. Restore Options
Full VM Restore: Restore the entire Domain Controller VM to
the same or a new host.
Bare Metal Recovery: For physical DCs, use Veeam
Recovery Media to restore the system.
Granular Recovery: Use Veeam Explorer for Active Directory
to restore specific objects (e.g., users, OUs).
3. Post-Restoration Validation
Verify Active Directory functionality, including replication and
FSMO roles.
Confirm DNS and DHCP services if they run on the DC.