AD Forest Recovery - Performing an authoritative synchronization of DFSR-replicated SYSVOL

Applies To: Windows Server 2016, Windows Server 2012 and 2012 R2, Windows Server 2008 and 2008 R2

There are different ways to perform an authoritative restore of SYSVOL. You can either edit the msDFSR-Options attribute or perform a system state restore using wbadmin –authsysvol. If you have the option to restore a system state backup (that is, you are restoring AD DS to the same hardware and operating system instance) then using wbadmin –authsysvol is simpler. But if you need to perform a bare metal restore, then you need to edit the msDFSR-Options attribute.

Use the following steps to perform an authoritative synchronization of SYSVOL (if it is replicated using DFSR) by editing the msDFSR-Options attribute. If SYSVOL is replicated using FRS, see article 290762.

To perform an authoritative synchronization of DFSR-replicated SYSVOL

  1. Open Active Directory Users and Computers.

  2. Click View, and then select Users, Contacts, Groups, and Computers as containers and Advanced Features.

    SYSVOL

  3. In the tree-view, click Domain Controllers, the name of the DC you restored, DFSR-LocalSettings, and then Domain System Volume.

    SYSVOL

  4. In the Details pane, right-click SYSVOL Subscription, click Properties, and click Attribute Editor.

    SYSVOL

  5. Click msDFSR-Options, click Edit, type 1, and click OK

    SYSVOL

  6. Click OK to close the Attribute Editor.

Next Steps