ééããªããå€ãã®äººããã®ãããªåé¡ã«ç¹°ãè¿ãééããŠããŸã-ãŠãŒã¶ãŒã¢ã«ãŠã³ããåé€ãããŸããã ã¢ã«ãŠã³ãã®å埩ã«é¢ããå€ãã®èšäºããããããããæé«ã®ãã®ã¯Microsoftã«ãã£ãŠæžãããŠããŸããããããã¯ãã¹ãŠå¯èŠæ§ã«æ¬ ããŠããŸãã ã¢ã«ãŠã³ãã埩å ããæé ãç°¡åãªæé ã«æžããããšã§ããã®æ¬ ç¹ãå æããããšããŸãã
ãåãã®ããã«ããªããžã§ã¯ãã¯ããŸããŸãªæ¹æ³ã§åŸ©å ã§ããŸãããããããç¹å®ã®ç¶æ³ã«æé©ã§ãã
ãã®å Žåãå»æ£ãªããžã§ã¯ãããã®å埩ãæãŸããã§ãã ããã«ã¯ããã€ãã®çç±ããããŸãã
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒããªãã©ã€ã³ã«ããå¿ èŠã¯ãããŸããïŒãã¹ãŠæ©èœããäœãç¡å¹ã«ãªã£ãŠããŸããïŒ
- åé€æžã¿ãªããžã§ã¯ãã®æ°ããããŒãžã§ã³ãåã«åäœæããããããå»æ£ïŒtombstoneïŒãå埩ããæ¹ãã¯ããã«è¯ã
å±æ§ã®äžéšã¯ãªããžã§ã¯ãã®åé€ãšãšãã«åé€ãããŸã-ãããã¯ãã¯ã埩å ã§ããŸããã ããšãã°ãã»ãã¥ãªãã£ã°ã«ãŒãã®ã¡ã³ããŒã·ããã
ãªããžã§ã¯ããåäœæããå Žåããªããžã§ã¯ãã«ã¯åžžã«æ°ããobjectGUIDããã³objectSidå±æ§ãèšå®ãããŸãïŒãŠãŒã¶ãŒãªã©ã®ã»ãã¥ãªãã£ããªã·ãŒã®ã¡ã³ããŒã§ããå ŽåïŒã ãã®çµæãACLãªã©ã®å€éšãªããžã§ã¯ãåç §ã¯ãæ°ãããªããžã§ã¯ãèå¥åãåæ ããããã«æŽæ°ããå¿ èŠããããŸãã ããã¯éåžžã«å€§ããªåé¡ã«ãªãå¯èœæ§ããããŸãã
ãããã£ãŠããã®æçš¿ã§ã¯ãæåã«å»æ£ãªããžã§ã¯ãã䜿çšããæ¹æ³ãæ€èšããæåŸã«åŒ·å¶ãªã«ããªã«é¢ããæ å ±ã®ã¿ãæäŸããŸãã æçš¿ã®æåŸã§ãNetWrix Active Directoryãªããžã§ã¯ã埩å ãŠã£ã¶ãŒãã®æ©èœã«ã€ããŠèª¬æããŸãã æçš¿ã®æ å ±ã¯ãNetWrixãäœæããããã¥ã¡ã³ããActive Directoryãªããžã§ã¯ãã®åŸ©å ïŒã¹ã¯ãªããã®ã³ã¬ã¯ã·ã§ã³ãããååŸããŸããã èå³ã®ããæ¹ã¯ç«ãæè¿ããŸã
埩å ããå¿ èŠããããã®ïŒäŸ
äžããããïŒ
Olegã¢ã«ãŠã³ããšDmitryã¢ã«ãŠã³ããããã³Sergeyã¢ã«ãŠã³ããé 眮ãããŠããåã蟌ã¿OU管çè ãå«ãOU Finance_Departmentãacme.comãã¡ã€ã³ããåé€ããŸããã
ãã£ã¬ã³ãžïŒ
ãã¹ãŠã®ã¡ã³ããŒïŒãã¹ããããOUãå«ãïŒããã³ã¢ã«ãŠã³ãå±æ§ã«OUã埩å ããŸãã
ãããŠããã®ã¿ã¹ã¯ã¯ãã¹ãŠã®å¯èœãªæ¹æ³ã§è§£æ±ºãããŸãã
1. ldp.exeã䜿çšããŠãªããžã§ã¯ãã埩å ãã
æç¶ã
1ïŒã³ã³ãœãŒã«ã§ã®ãªã¢ãŒããªããžã§ã¯ãã®è¡šç€ºããªã³ã«ããŸãïŒCN = Deleted ObjectsïŒ
ãŸããåé€ããããªããžã§ã¯ãã衚瀺ãããŠããããšã確èªããå¿ èŠããããŸãïŒããã©ã«ãã§ã¯CN = Deleted Objectsã³ã³ããã¯è¡šç€ºãããŸãããActiveDirectoryã§ldp.exeã䜿çšããŸãïŒDomain Adminsã®ã¡ã³ããŒã·ãããå¿ èŠã§ãïŒã
1. ldp.exeãå®è¡ããŸãã ïŒ ã¹ã¿ãŒã-å®è¡-ldp.exe ïŒ
2. [ ãªãã·ã§ã³ ]ã¡ãã¥ãŒã§ã[ ã³ã³ãããŒã« ]ãéžæããŸã
3.衚瀺ããããã€ã¢ãã°ããã¯ã¹ã§ã[ äºåå®çŸ©ãããã¡ãã¥ãŒãèªã¿èŸŒã ]ãéžæãã[ åé€ããããªããžã§ã¯ããè¿ã ]ãéžæããŠã[ OK ]ãã¯ãªãã¯ããŸãã
4.åé€ããããªããžã§ã¯ãã®ã³ã³ãããŒã®è¡šç€ºæ¹æ³ã確èªããŸãã
aã Active Directoryç°å¢ãã©ã¬ã¹ãã®ã«ãŒããã¡ã€ã³ããããµãŒããŒã«æ¥ç¶ããŠãã€ã³ãããã«ã¯ã[ æ¥ç¶ ]ã»ã¯ã·ã§ã³ã§[ æ¥ç¶ ]ãéžæãã[ ãã€ã³ã ]ãã¯ãªãã¯ããŸãã
bã [ åç §]ãã¯ãªãã¯ããŠ[ æ§é ]ãéžæãã[ èå¥åïŒDNïŒ]ãã£ãŒã«ãã«DC =ãDC =ãšå ¥åããŸãã
cã ã³ã³ãœãŒã«ããªãŒã§ãã«ãŒããã¡ã€ã³ã®èå¥åïŒDNïŒãããã«ã¯ãªãã¯ããã³ã³ããCN =åé€æžã¿ãªããžã§ã¯ããDC = acmeãDC = comãèŠã€ããŸãã
ãªããžã§ã¯ãã埩å ããŸãã
OU Finance_Departmentã®äžéšã§ããOlegã¢ã«ãŠã³ãã®äŸã䜿çšããå埩ãæ€èšããŠãã ããã
1ïŒldp.exeãå®è¡ããŸã
2ïŒ[ æ¥ç¶]ã»ã¯ã·ã§ã³ã§ã[ æ¥ç¶-ãã€ã³ã]ãéžæããActive Directoryç°å¢ãã©ã¬ã¹ãã®ã«ãŒããã¡ã€ã³ãååšãããµãŒããŒã«æ¥ç¶ããŠãã€ã³ãããŸãã
3ïŒã³ã³ãœãŒã«ããªãŒã§ãã³ã³ãããŒCN = Deleted Objectsã«ç§»åããŸã ïŒäŸãšããŠãã¡ã€ã³ã®DC = acmeãDC = comãèšè¿°ããŸãïŒã
æ€çŽ¢çµæ
4ïŒ CN = Deleted Objectsã³ã³ããã®ã¹ãããã€ã³ã§åŸ©å ãããªããžã§ã¯ããèŠã€ããå³ã¯ãªãã¯ããŠ[å€æŽ]ã¢ã€ãã ãéžæããŸãã
5ïŒ å€æŽãŠã£ã³ããŠã§ã次ã®ãã©ã¡ãŒã¿ãå€æŽããŸã
aã å±æ§ã®[ ãšã³ããªã®ç·šé]ãã£ãŒã«ãã«isDeletedãšå ¥åããŸã
bã [ å€]ãã£ãŒã«ãã¯ç©ºçœã®ãŸãŸã«ããŸãã
cã [ æäœ]ã»ã¯ã·ã§ã³ã§ã[ åé€]ãéžæãã EnterããŒãæŒããŸãã
dã [ ãšã³ããªå±æ§ã®ç·šé]ãã£ãŒã«ãã«ã distinguishedNameãšå ¥åããŸãã
eã [ å€]ãã£ãŒã«ãã«ããã®Active Directoryãªããžã§ã¯ãã®åæèå¥åïŒDNïŒãå ¥åããŸãã
fã [ æäœ]ã»ã¯ã·ã§ã³ã§ã[ 眮æ]ãéžæããŸãã
gã æ¡åŒµãã©ã°ãèšå®ãã EnterããŒãæŒããŠã å®è¡ããŸãã
ã¢ã«ãŠã³ãã¯åŸ©å ãããŸããããç¡å¹åãããŸããã æåã§æå¹ã«ããå¿ èŠããããŸãã ãŸããã°ã«ãŒãã¡ã³ããŒã·ãããæåã§åŸ©å ãããã¹ã¯ãŒãããªã»ããããå¿ èŠããããŸãã
æ®ãã®ãªããžã§ã¯ãã«å¯ŸããŠåãã¢ã¯ã·ã§ã³ãç¹°ãè¿ããŸãã
OU Finance_Department
OU管çè
ããããªãŒã¢ã«ãŠã³ã
ã¢ã«ãŠã³ãã»ã«ã²ã€
çµæïŒ
ãªããžã§ã¯ãã埩å ããåã«ãå€ãã®äœæ¥ãè¡ãå¿ èŠããããŸãã
åé€ããããªããžã§ã¯ãããšã«ãã¹ãŠã®ã¢ã¯ã·ã§ã³ãç¹°ãè¿ãå¿ èŠããããŸãã
2. ADRESTOREã䜿çšãã
LDPã䜿çšããå¢ç³ã®åŸ©å ã¯ç°¡åã§ãã ããããäžå¿«ã§é·ãã ãããã®ç®çã®ããã«ãADãªããžã§ã¯ãã®åŸ©å å°çšã«èšèšãããADRESTOREããããŸãã
ãŠãŒãã£ãªãã£ã¯2ã€ã®ã¢ãŒãã§åäœããŸãã
⢠ãã©ã¡ãŒã¿ãªãã§éå§ããŸã ã ããã¯ãããã©ã«ããã¡ã€ã³ã®CN = Deleted Objectsã³ã³ããã«ãããã¹ãŠã®ãã¥ãŒã ã¹ããŒã³ããªã¹ãããŸãã ã³ãã³ãã©ã€ã³ã§æ€çŽ¢æååãè¿œå ããŠã衚瀺ãããªããžã§ã¯ããéžæã§ããŸãã
C:\> adrestore Finance_Department
CNãŸãã¯OUå±æ§ã«æååãFinance_Departmentããå«ãCN = Deleted Objectsã³ã³ããå ã®ãã¹ãŠã®ãªããžã§ã¯ãã衚瀺ãããŸã-LDAPæ€çŽ¢ãã£ã«ã¿ãŒcn = * Finance_Department *ããã³ou = * Finance_Department *ã䜿çšãããŸãã 次ã®ç»åã¯ãADRESTOREã«ãã£ãŠè¿ãããæ€çŽ¢ã®çµæã瀺ããŠããŸãã
⢠ãªããžã§ã¯ãã®å埩
åè¬ãªããžã§ã¯ãã埩å ããã ãã§ãªãã埩å ããå Žåã¯ã次ã®ããã«ã-rãã©ã¡ãŒã¿ãŒãšè¿œå ã®è¡ãæå®ããå¿ èŠããããŸãã
C:\> adrestore âr Finance_Department
ã¢ã«ãŠã³ãã埩å ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
C:\> adrestore âr Oleg C:\> adrestore âr Dmitry C:\> adrestore âr Admins C:\> adrestore âr Sergey
ããŒã ã¯ãæ¡ä»¶ãæºããååè¬ãªããžã§ã¯ãã埩å ããããšãææ¡ããŸãã ãªããžã§ã¯ãã¯ã ãã¥ãŒã ã¹ããŒã³ã®lastKnownParentå±æ§ã§æå®ãããã³ã³ãããŒã«åŸ©å ãããŸãïŒãã®ä»ã¯åŸ©å ãããŸããïŒã
ãã®ã³ãã³ãã¯ãé©åãªååè¬ãªããžã§ã¯ãã埩å ããããšãæäŸããŸãã ADRESTOREã¯ããã¥ãŒã ã¹ããŒã³ã®lastKnownParentå±æ§ã§æå®ãããã³ã³ããã«åžžã«ãªããžã§ã¯ãã埩å ããŸã;å¥ã®ã³ã³ãããæå®ããæ¹æ³ã¯ãããŸããã
çµæïŒ
ADRESTOREã¯ãLDPããã䜿ããããã§ãã
ãã®ãŠãŒãã£ãªãã£ã䜿çšãããšããªããžã§ã¯ããæ¯èŒçãã°ãã埩å ã§ããŸãããå¿ èŠãªå±æ§ããªããŠãã°ã«ãŒãã¡ã³ãã·ãããšãã¹ã¯ãŒããæåã§åŸ©å ããå¿ èŠããããŸãã ãªããžã§ã¯ãã埩å ããæãäžè¬çãªæ¹æ³ã®1ã€ã
3. ADãã¿ç®±ã®äœ¿çšïŒWindows Server 2008 R2ïŒ
Active Directoryã®ãã¿ç®±ïŒAD RBïŒã Windows Server 2008 R2ã«ç»å Žãããããã¢ã¯ãã£ãã«ããã«ã¯ããã©ã¬ã¹ãã¬ãã«ãšããŠWindows Server 2008 R2ãå¿ èŠã§ãã AD RBã¯éåžžã®Windowsã®ãã¿ç®±ã«äŒŒãŠããŸã-誀ã£ãŠåé€ããããªããžã§ã¯ãã¯ããã¹ãŠã®å±æ§ã§ãã°ãã埩å ã§ããŸãã ããã«ãAD RBãã埩å ããããªããžã§ã¯ãã¯ããã¹ãŠã®å±æ§ãããã«åãåããŸãã ããã©ã«ãã§ã¯ãAD RBã®ãªã¢ãŒããªããžã§ã¯ãã®ãã©ã€ãã¿ã€ã ãã¯180æ¥ã§ãããã®åŸããã¿ç®±ã®ã©ã€ãã¿ã€ã ç¶æ ã«ãªããå±æ§ã倱ããããã°ãããããšå®å šã«åé€ãããŸãã
æãåçŽãªå Žåããªããžã§ã¯ãã¯Powershellã³ãã³ãã¬ããGet-ADObjectããã³Restore-ADObjectã䜿çšããŠåŸ©å ãããŸãïŒåŸ©å ããå¿ èŠããããã®ãæ£ç¢ºã«ããã£ãŠããå ŽåïŒã Get-ADObjectã³ãã³ãã¬ããã¯ããªã¢ãŒããªããžã§ã¯ããååŸããããã«äœ¿çšããã Restore-ADObjectã³ãã³ãã¬ããã«ãã€ããããŸãã
1. Windows PowerShellã®Active Directoryã¢ãžã¥ãŒã«ãšããŠç®¡çè ãšããŠå®è¡ããŸãã
2. Windows PowerShellã³ãã³ãããã³ããã®Active Directoryã¢ãžã¥ãŒã«ã§ã次ã®ã³ãã³ããå ¥åããŸãã
PS C:\> Get-ADObject -Filter {displayName -eq "user"} -IncludeDeletedObjects | Restore-ADObject
ãã®äŸã§ã¯
-Filter {displayName -eqâ userâ}ã¯ãADãªããžã§ã¯ãã«é¢ããæ å ±ïŒãã®äŸã§ã¯ã衚瀺ãŠãŒã¶ãŒåããuserãã®ãªããžã§ã¯ãã«é¢ããæ å ±ïŒãååŸããããšã瀺ããŸãã
-IncludeDeletedObjectsã¯ãæ€çŽ¢ããªã¢ãŒããªããžã§ã¯ãã§å®è¡ãããããšãæå³ããŸã
Restore-ADObjectã¯ãADãªããžã§ã¯ãã®åŸ©å ãçŽæ¥å®è¡ããŸãã
åé€ããããªããžã§ã¯ããæ€çŽ¢ãã
1.管çè ãšããŠWindows PowerShellã®Active Directoryã¢ãžã¥ãŒã«ãšããŠå®è¡ããŸãã
2. Windows PowerShellã®ã³ãã³ãã©ã€ã³Active Directoryã¢ãžã¥ãŒã«ã§ã次ã®ã³ãã³ããå ¥åããŠå¿ èŠãªæ å ±ãååŸããŸãã
acme.comã§åé€ããããªããžã§ã¯ãããªã¹ããã
Get-ADObject -SearchBase "CN=Deleted Objects,DC=acme,DC=com" âIncludeDeletedObjects
ãªã¢ãŒããŠãŒã¶ãŒãå±ããŠããOUã«é¢ããæ å ±ãååŸãã
Get-ADObject -SearchBase "CN=Deleted Objects,DC=acme,DC=com" -ldapFilter:"(msDs-lastKnownRDN=User)" âIncludeDeletedObjects âProperties lastKnownParent
Userã¯ãŠãŒã¶ãŒã®è¡šç€ºåã§ã
ãã®çµæãæå®ããããŠãŒã¶ãŒã®OUã¡ã³ããŒã·ããã«é¢ããæ å ±ãååŸããŸãïŒ -Properties lastKnownParentã䜿çšïŒ
ãã®OUã«ãã£ããã¹ãŠã®åé€ããããªããžã§ã¯ããæ€çŽ¢ããŸã
äŸãšããŠãåã®ã³ãã³ãã¬ããïŒFinance_Department \\ 0ADELïŒe954edda-db8c-41be-bbbd-599bef5a5f2aïŒã®å®è¡åŸã«ååŸãããèå¥åOU Finance_DepartmentãåãäžããŸãã
Get-ADObject âSearchBase "CN=Deleted Objects,DC=acme,DC=com" -Filter {lastKnownParent -eq 'OU=Finance_Department\\0ADEL:e954edda-db8c-41be-bbbd-599bef5a5f2a,CN=Deleted Objects,DC=acme,DC=com'} -IncludeDeletedObjects -Properties lastKnownParent | ft
泚æïŒ OUããã¹ããããŠããå Žåãæäžäœã®éå±€ã¬ãã«ããå埩ãå®è¡ãããŸãã ãã®å Žåãããã¯OU = Finance_Departmentã§ãã
ãªããžã§ã¯ãã®å埩
1. Windows PowerShellçšã®Active Directoryã¢ãžã¥ãŒã«ãèµ·åãã
2.ã³ãã³ãã©ã€ã³ã§æ¬¡ã®ã³ãã³ããå®è¡ããŠãFinance_DepartmentãŠãããã埩å ããŸãã
Get-ADObject -ldapFilter:"(msDS-LastKnownRDN=Finance_Department)" âIncludeDeletedObjects | Restore-ADObject
3. OU Finance_Departmentã®çŽæ¥ã®åã§ããã¢ã«ãŠã³ããšOUã埩å ããŸãïŒãã®æ®µéã§ãèå¥åFinance_Departmentã¯æ¢ã«OU = Finance_DepartmentãDC = acmeãDC = comã«åŸ©å ãããŠããããšã«æ³šæããŠãã ããïŒ
Get-ADObject -SearchBase "CN=Deleted Objects,DC=acme,DC=com" -Filter {lastKnownParent -eq "OU=Finance_Department,DC=acme,DC=com"} -IncludeDeletedObjects | Restore-ADObject
ãªãã·ã§ã³ïŒãã¹ããããOUã埩å ïŒ
4.ãµãOUã«å«ãŸããã¢ã«ãŠã³ãã埩å ããŸãïŒããšãã°ãOU財åéšéã®äžéšã§ããOU Adminsããã®äŸã®èå¥åã¯ãOU = AdminsãOU = Finance_DepartmentãDC = acmeãDC = comã«åŸ©å ãããŸããïŒ
Get-ADObject -SearchBase "CN=Deleted Objects,DC=acme,DC=com" -Filter {lastKnownParent -eq "OU=Admins,OU=Finance_Department,DC=acme,DC=com"} -IncludeDeletedObjects | Restore-ADObject
Get-Help Get-ADObjectãªã©ã®Get-Helpã³ãã³ãã¬ãããåŒã³åºãããšã«ãããã³ãã³ãã¬ãããšãã®ãã©ã¡ãŒã¿ãŒã«é¢ãã詳现ãªãã«ã
çµæïŒ
ãªããžã§ã¯ãã¯ããã¹ãŠã®å±æ§ãšãšãã«å ã®åœ¢åŒã«åŸ©å ãããŸãã
ãã ããã芧ã®ãšãããå€æ°ã®ãªããžã§ã¯ããæäœããå¿ èŠãããå Žåããã®æ¹æ³ã¯éåžžã«è€éã§ãã
ãŸãããã©ã¬ã¹ãå ã®ãã¹ãŠã®ãµãŒããŒãWindows 2008 R2ã§ããå¿ èŠããããŸãã
äžèšã®LDPããã³AdRestoreããŒã«ã䜿çšããŠãADãã±ããããªã³ã«ããŠå±æ§ãæã€ãªããžã§ã¯ãã埩å ã§ããŸãã
4. NTDSUTILã䜿çšãã匷å¶å埩
æšæºã®æ¹æ³ïŒãã ããæé©ã§ã¯ãããŸããïŒã¯ã ãã£ã¬ã¯ããªãµãŒãã¹åŸ©å ã¢ãŒãã§ããã¯ã¢ãããã匷å¶çã«åŸ©å ããããšã§ãã ããã«ã¯é倧ãªæ¬ ç¹ããããŸãããµãŒããŒãåèµ·åãã次ã«ã·ã¹ãã ã®ç¶æ ãããã¯ã¢ãããã埩å ããè€è£œããã»ã¹ã«ãã£ãŠäžæžããããªããªããžã§ã¯ããããŒã¯ããå¿ èŠããããŸãã
å埩ã¯ã NTDSUTILã³ãã³ãã©ã€ã³ãŠãŒãã£ãªãã£ã䜿çšããŠå®è¡ãããŸã ã AD DSã®åœ¹å²ãã€ã³ã¹ããŒã«ãããšããŠãŒãã£ãªãã£ã䜿çšå¯èœã«ãªããŸãã ããã䜿çšãããšããã¹ãŠã®ã³ã³ãã³ããæã€OUãšåå¥ã®ãªããžã§ã¯ãã®äž¡æ¹ã埩å ã§ããŸãã
ãã®ãŠãŒãã£ãªãã£ã¯ãVSSãµãŒãã¹ã䜿çšããŠäœæãããActive Directoryã®ã¹ãããã·ã§ããïŒã¹ãããã·ã§ããïŒã«åºã¥ããŠããŸãã
泚æïŒ AD匷å¶å埩äžã埩å ããããªããžã§ã¯ãã®å éšããŒãžã§ã³çªå·ãå¢å ããŸãã ãã¡ã€ã³ã³ã³ãããŒã©ããããã¯ãŒã¯ã«æ¥ç¶ããããšããããã®ãªããžã§ã¯ãã¯ãã¡ã€ã³å šäœã«è€è£œããã埩å ãããããŒãžã§ã³ã¯ã°ããŒãã«ã«æå¹ã«ãªããŸãã
æç¶ã
1. acme.comããOU Finance_Departmentã埩å ããå¿ èŠããããŸã
2. DSRMã¢ãŒãã§ããŒããïŒããŒãã¡ãã¥ãŒã§F8ããŒãæŒããšåŒã³åºãããŸãïŒã Dcpromoã®æäœäžã«èšå®ããããã¹ã¯ãŒãDSRMã§ç»é²ããŸãã ADã¯ããŒãããããããŒã¿ããŒã¹ã¯ãªãã©ã€ã³ã«ãªããŸãã
泚æïŒ NTDS ADãServer 2008ãã¡ã€ã³ã³ã³ãããŒã©ãŒä»¥äžã§åæ¢ããŠããå Žåãå埩ãå®è¡ã§ããŸããã
3.äºæ ã®åã«äœæãããããã¯ã¢ããããã·ã¹ãã ç¶æ ã埩å ããŸãã
泚æïŒ ã³ã³ãã¥ãŒã¿ãŒãåèµ·åããªãã§ãã ããã
ntdsutilã¹ãããã·ã§ããã«ã¯ããªããžã§ã¯ããšãã®å±æ§ã®äž¡æ¹ãå«ãŸããŠããŸãã ã€ã¡ãŒãžã¯ããªããžã§ã¯ãããšã¯ã¹ããŒãããä»®æ³LDAPãµãŒããŒãšããŠããŠã³ãããã³ããŠã³ãã§ããŸãã ntdsutilãéå§ããŸã ã
> ntdsutil ntdsutil: snapshot
å©çšå¯èœãªåçã®ãªã¹ãã確èªããŸãã
: list all
1ïŒ2009/04/22ïŒ23:18 {8378f4fe-94c2-4479-b0e6-ab46b2d88225}
2ïŒCïŒ{732fdf7f-9133-4e62-a7e2-2362227a8c8e}
3ïŒ2009/04/23ïŒ00ïŒ19 {6f7aca49-8959-4bdf-a668-6172d28ddde6}
4ïŒCïŒ{cd17412a-387b-47d1-9d67-1972f49d6706}
çªå·ãŸãã¯{ID}ã§ããŠã³ãã³ãã³ããããŠã³ãããŸãã
: mount 4 {cd17412a-387b-47d1-9d67-1972f49d6706} C:\$SNAP_200904230019_VOLUMEC$\
åçãããŠã³ããããŸãã
4.ã³ãã³ããå®è¡ãã
Finance_Departmentãåæ§ç¯ããã«ã¯
> ntdsutil "authoritative restore" "restore subtree ou=Finance_Department,dc=acme,dc=com" qq
ãã®çµæãOU Finance_Departmentã¯ãããã«å«ãŸããã¢ã«ãŠã³ããšãã¹ããããOU Adminsã§åŸ©å ãããŸã
ããšãã°ã衚瀺åãOlegã®åã ã®ã¢ã«ãŠã³ãã埩å ããã«ã¯
> ntdsutil "authoritative restore" "restore object cn=Oleg,ou=Finance_Department,dc=acme,dc=com" qq
5.å®å šèŠåã確èªããŸãã ãã®åŸãå³3ã«ç€ºããããªã¡ãã»ãŒãžã衚瀺ãããŸãããçæãããããã¹ããšLDIFãã¡ã€ã«ã«æ³šæããŠãã ããã
éåžžã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®èµ·åã¢ãŒãã§DCãåèµ·åããŸãã
7. DCã«ãã°ãªã³ããŠãã³ãã³ãããã³ãããéããŸãã ã³ãã³ããå®è¡ããŠãæé 5ã§ãšã¯ã¹ããŒãããLDIFãã¡ã€ã«ãã€ã³ããŒãããŸã
ldifde -i -f ar_20110221-151131_links_contoso.com.ldf
ããã§ãar_20110221-151131_links_contoso.com.ldfã¯ãäœæãããLDIFãã¡ã€ã«ã®ååã§ãã
8.ãã®çµæã埩å ããããªããžã§ã¯ãã®é¢é£å±æ§ïŒã°ã«ãŒãã¡ã³ããŒã·ãããªã©ïŒã®å€ãã€ã³ããŒããããŸãã
泚æïŒ ãã©ã¬ã¹ãã«è€æ°ã®ãã¡ã€ã³ãå«ãŸããå Žåãæé 6ã§ãšã¯ã¹ããŒãããããã¹ããã¡ã€ã«ã䜿çšããŠãä»ã®ãã¡ã€ã³ã®ããŒã«ã«ã°ã«ãŒãã®ã¡ã³ããŒã·ããã埩å ããå¿ èŠããããŸãã
çµæïŒ
ã¢ã«ãŠã³ããšãªããžã§ã¯ãã¯åŸ©å ãããŸããããActive DirectoryããŒã¿ããŒã¹ã¯äžå®æéå©çšã§ããŸããã§ããã ãŸãããã®å埩æ¹æ³ã«äŸåããŠãçŸåšã®ADããŒã¿ããŒã¹ã®å¯çšæ§ã«ãäŸåããŸãã
5. NetWrix Active Directoryãªããžã§ã¯ã埩å ãŠã£ã¶ãŒã
NetWrix Active Directoryãªããžã§ã¯ã埩å ãŠã£ã¶ãŒãã䜿çšãããšããªããžã§ã¯ãã®åŸ©å ããã»ã¹ãå€§å¹ ã«ç°¡çŽ åã§ããŸãã
ç§ãã¡ã®äŒç€Ÿã«ã¯ãADãªããžã§ã¯ããåé€ãã管çè ãã絶ããé£çµ¡ãããããããã埩å ãããããšã«æ³šæããŠãã ããã ç§ãã¡ãææ¡ãããœãªã¥ãŒã·ã§ã³-NetWrix Active Directory Object Restore Wizard-ãªããžã§ã¯ãã埩å ããããã»ã¹ãç°¡åã«ããŸããïŒããšãã°ããã¹ãŠã®ãªããžã§ã¯ããšãã®å±æ§ãæ°åã¯ãªãã¯ããã ãã§OUã埩å ããŸãïŒãããã§ãåäœããŸããADã¹ãããã·ã§ããã ãããã£ãŠãèšäºãèªãã åŸãããã°ã©ã ãåäœãããããšããå§ãããŸãïŒéå»4æ¥éã®å埩æéãæã€ç¡æçããããŸãïŒã次åãªããžã§ã¯ãã埩å ããéã«ãã®ãããªåé¡ãçºçããªãããã«ããŸãã
ãã®ãŠãŒãã£ãªãã£ã䜿çšãããšãåé€ããããªããžã§ã¯ããæ°åã¯ãªãã¯ããã ãã§å埩ã§ãããã¡ã€ã³å ã®ãªããžã§ã¯ããåé€ããåã«ããã°ã©ã ãæ©èœããå Žåããã¹ãŠã®å±æ§ã§åŸ©å ãè¡ãããŸãã ãã®çµæãçµç¹ã«æ·±å»ãªæ··ä¹±ãäžããããšãªããæ°åã§è¿åãããã¢ã«ãŠã³ããååŸã§ããŸãã ãŸããããã°ã©ã ã䜿çšãããšãåé€ãããã¡ãŒã«ããã¯ã¹ãå埩ã§ããããšã«æ³šæããŠãã ããã
ããã°ã©ã ã§ã®äœæ¥ã¯ã次ã®æé ã«åæžãããŸãã
1. NetWrix Active Directoryãªããžã§ã¯ã埩å ãŠã£ã¶ãŒããèµ·åããŸãã
2.埩æ§ã¢ãŒããéžæãããŠããŸãïŒ
â¢å»æ£ãªããžã§ã¯ãããã®ã¿ïŒããã°ã©ã ããã¡ã€ã³ã«ä»¥åã«ã€ã³ã¹ããŒã«ãããŠããªãå ŽåïŒ
â¢ã¹ãããã·ã§ããã䜿çšããå埩ïŒããã°ã©ã ãã€ã³ã¹ããŒã«ãããå°ãªããšã1ã€ã®ã¹ãããã·ã§ãããäœæãããå ŽåïŒ
3.åæçµæã«åºã¥ããŠãåé€ããããªããžã§ã¯ããšãã®åæéå±€ããã³ãªããžã§ã¯ãã®ãªã¹ãã衚瀺ãããŸã
4.埩å ããOUãŸãã¯ãªããžã§ã¯ããéžæãã[次ãž]ãã¯ãªãã¯ããŸãã
5.ããã°ã©ã ã以åã«ã€ã³ã¹ããŒã«ããããã©ããã«å¿ããŠïŒ
â¢ãŸã ãæã¡ã§ãªãå Žåã¯ãã°ã«ãŒãã¡ã³ããŒã·ãããšãŠãŒã¶ãŒãã¹ã¯ãŒããæåã§åŸ©å ããå¿ èŠããããŸã
â¢ããã°ã©ã ãã€ã³ã¹ããŒã«ãããŠããã°ã埩å ã¯å®äºããäœãèµ·ãããªãã£ãããã«ãã¹ãŠãæ©èœããŸãã
ã芧ã®ãšããããªããžã§ã¯ãã®å埩ã«ãããæéã¯ãéåžžã®Active Directoryãªããžã§ã¯ãå埩ããŒã«ã䜿çšãããããã¯ããã«çããªããŸãã
ãã ãããªããžã§ã¯ãã®åŸ©å ã¯ããã°ã©ã ã®1ã€ã®åŽé¢ã«ãããŸããã ãªããžã§ã¯ãã«å¯Ÿããå€æŽãããŒã«ããã¯ããããšãã§ããŸã-1ã€ã®å±æ§ã®å€ãŸã§-ããã°ã©ã ã¯ãã®ããã«èšèšãããŠããŸãã
çµæïŒ
å±æ§ã䜿çšããŠãªããžã§ã¯ãã埩å ããã«ã¯ãããã€ãã®ç°¡åãªæé ãå¿ èŠã§ãã ãªããžã§ã¯ãã埩å ããã ãã§ãªããäžéšã®å€ã®ã¿ãããŒã«ããã¯ããããšãã§ããŸãã
ããããã¹ãŠã®å埩æ¹æ³ã¯ããADãªããžã§ã¯ãã埩å ããããã®å¿æ¥åŠçœ®ããããã§èª¬æãããŠããã åœç€Ÿã®Webãµã€ãããããŠã³ããŒãã§ããŸãã