Active Directory 樹系修復必要條件Active Directory Forest Recovery Prerequisites

適用於: Windows Server 2016、 Windows Server 2012 和 2012 R2、 Windows Server 2008 和 2008 R2Applies To: Windows Server 2016, Windows Server 2012 and 2012 R2, Windows Server 2008 and 2008 R2

下列文件商討您應該先設計的樹系修復計畫,或嘗試復原熟悉的必要條件。The following document discuss prerequisites that you should be familiar with before devising a forest recovery plan or attempting a recovery.

使用本指南假設Assumptions for Using This Guide

  1. 使用 Microsoft 支援人員過和:You have worked with a Microsoft Support professional and:

    • 判斷樹系失敗的原因。Determine the cause of the forest-wide failure. 本指南不建議失敗的原因或建議任何程序,以避免失敗。This guide does not suggest a cause of the failure or recommend any procedures to prevent the failure.
    • 評估任何可能的救濟權利。Evaluated any possible remedies.
    • 太平洋、 與 Microsoft 支援服務,諮詢在該還原整個樹系狀態失敗之前是復原從失敗的最佳方式。Concluded, in consultation with Microsoft Support, that restoring the whole forest to its state before the failure occurred is the best way to recover from the failure. 很多時候,森林修復應該最後一個選項。In many cases, forest recovery should be the last option.
  2. 您有依照 Microsoft 最佳建議使用 Active Directory – 整合網域名稱系統 」 (DNS)。That you have followed the Microsoft best-practice recommendations for using Active Directory–integrated Domain Name System (DNS). 具體而言,應該是每個 Active Directory domain Active Directory – 整合 DNS 區域。Specifically, there should be an Active Directory–integrated DNS zone for each Active Directory domain. 如果這不是如此,您仍然可以使用基本本指南原則來執行復原樹系。If this is not the case, you can still use the basic principles of this guide to perform forest recovery. 不過,您將需要需要特定措施 DNS 復原根據您自己的環境。However, you will need to take specific measures for DNS recovery based on your own environment. 如需有關如何使用 Active Directory – 整合 DNS 的詳細資訊,請查看建立設計 DNS 基礎架構For more information about using Active Directory–integrated DNS, see Creating a DNS Infrastructure Design.

  3. 本指南做樹系復原一般的輔助,雖然涵蓋可能不是所有的案例。Although this guide is intended as a generic guide for forest recovery, not all possible scenarios are covered. 例如,開始使用 Windows Server 2008,還有 Server Core 版本,也就是完整版本的 Windows Server,但不完整 GUI。For instance, beginning with Windows Server 2008, there is a Server Core version, which is a full version of Windows Server but without a full GUI. 雖然它自然也是可以復原組成只執行 Server Core 網域控制站的樹系,本指南有任何詳細的指示。Although it is certainly possible to recover a forest consisting of just DCs that run Server Core, this guide has no detailed instructions. 不過,依據以下討論指導方針您將無法自行設計所需的命令列動作。However, based on the guidance discussed here you will be able to design the required command-line actions yourself.

!![!NOTE] 本指南的目標是復原樹系和維護或還原完整 DNS 功能,但修復可能會導致變更的組態失敗之前 DNS 設定。Although the objectives of this guide are to recover the forest and maintain or restore full DNS functionality, recovery can result in a DNS configuration that is changed from the configuration before the failure. 樹系復原之後,您可以回復到原始 DNS 設定。After the forest is recovered, you can revert to the original DNS configuration. 本指南建議事項執行告訴您如何設定執行公司命名空間的其他部分的名稱解析 DNS 伺服器,其中有不會儲存在 AD DS DNS 區域。The recommendations in this guide do not describe how to configure DNS servers to perform name resolution of other portions of the corporate namespace where there are DNS zones that are not stored in AD DS.

使用本指南概念Concepts for Using This Guide

規劃區域的 Active Directory 樹系復原您開始之前,您應該熟悉動作:Before you begin planning for recovery of an Active Directory forest, you should be familiar with the following:

  • Active Directory 的基本概念Fundamental Active Directory concepts

  • (也稱為彈性的單一主機操作或 FSMO) 操作主機角色的重要性。The importance of operations master roles (also known as flexible single master operations or FSMO). 這些角色包含下列類型:These roles include the following:

    • 架構主機Schema master

    • 網域命名主機Domain naming master

    • 相關 ID (RID) 主機Relative ID (RID) master

    • 主要網域控制站 (PDC) 模擬器主機Primary domain controller (PDC) emulator master

    • 基礎結構主機Infrastructure master

    此外,您應該已經備份與還原 AD DS 和 SYSVOL 定期測試環境中。In addition, you should have backed up and restored AD DS and SYSVOL in a lab environment on a regular basis. 如需詳細資訊,請查看「 資料備份系統狀態執行未授權的 Active Directory Domain Services 還原For more information, see Backing up the System State data and Performing a nonauthoritative restore of Active Directory Domain Services.

後續步驟Next Steps