Main Navigation Section
Complete AD disaster recovery at the object, directory and OS level across the entire forest.
External Id
1129
PD_Domain
Platform Management
PD_SolutionArea
Management
PD_Segment
Management
PD_ProductFamily
RMAD / FE
Productline
Recovery Manager
ProductType
Product
SalesOpsSfdcId
a0v1O00000K2rkrQAB
SalesOpsProuctGroupSfdicId
a0t30000001APRNAA4
ProductHierarchyId
a0u30000000z0KjAAI

The leader in hybrid AD cyber resilience and modernization

Quest is the market leader in hybrid Active Directory (AD) security, recovery, migration and modernization, empowering 130,000 customers with unrivaled cyber resilience solutions. Only with Quest do you get:

  • Comprehensive AD and Entra ID threat prevention, detection and response
  • Automated disaster recovery, significantly reducing ransomware recovery costs
  • 24x7 support and incident response that can scale across the globe
group2

By downloading, you are registering to receive marketing email from us. To opt-out, follow steps described in our Privacy Policy.

reCAPTCHA protects this site. See Google's Privacy Policy and Terms of Use.

Quest: Leading the way in migration and cyber resilience for hybrid active directory

Quest experience and leadership

You won’t find this platform coverage anywhere else. The numbers don’t lie about our experience and leadership. There are a lot of point solutions out there that claim a lot of things, but Quest is the only single-vendor provider that delivers comprehensive solutions for:

  • Active Directory, Entra ID & Microsoft 365
  • Identity Threat Detection & Response (ITDR)
  • Disaster recovery
  • Migration and modernization

What our customers say about us

Bell Canada

When you’re the largest telecom in Canada, everybody knocks on your door. But no other vendor has been able to offer us anything nearly as good as what we already have with Quest...

Phillip Palha Senior Manager for Active Directory Delivery, Bell Canada

Energy Company

We did a bake-off between two competitors, and Quest was the clear winner. We were quite impressed by the quality and reliability of Recovery Manager for Active Directory, which offers both forest-level disaster recovery and easy granular recovery.

Lead IT Architect, Energy Company

Oil and Gas Company

After meeting with the other vendor a second time and asking questions, neither my boss or I are comfortable with the size of the other vendor’s support team.

Lead Systems Engineer, Oil and Gas Company
    Superior technology
    Long-term assurance
    R&D innovation
    Global 24x7 support
    Incident response
    Microsoft partnership
    Gartner validation

    We offer the most comprehensive AD and Entra ID security and cyber resilience solutions, trusted for over 25 years. Our one-stop shop covers everything from identity modernization to threat prevention, detection, response, and disaster recovery. With our superior technology, we provide greater value, assurance, and efficiency when it matters most. Let us show you why thousands of IT pros prefer our market-leading capabilities.

    • Over 25 years of trusted experience in AD and Entra ID security
    • Unique one-stop shop for identity modernization, ITDR and disaster recovery
    • Microsoft Partner for 25+ years

    Quest, a nearly 40-year-old company, is a trusted and financially stable vendor for hybrid identity infrastructure, serving a vast global client base. Quest is a portfolio company of Clearlake Capital Group, a leading investment firm founded in 2006 with more than $72B of assets under management.

    • Employs nearly 4,000 people globally
    • Serves more than 130,000 customers and 15,000 partners worldwide
    • Includes 95% of Fortune 500 companies as clients

    Our unrivaled experience has placed us at the forefront of identity modernization and security innovations. We’ve pioneered several firsts, including AD-specific recovery and automated Entra ID device modernization solutions and the first unified, AD-specific security assessment and ITDR solution. With over 300 experts in R&D, we continue to invest heavily in hybrid identity security and modernization, while leading in Microsoft migrations.

    • Frictionless and reliable identity modernization
    • Preventative identity protection, detection, and response
    • Advanced AI analytics and integration with Microsoft Security Copilot

    Our global support team is available 24/7/365, with over 180 AD experts ready to assist you. We boast a 95% customer satisfaction rate and offer a maximum response time of 1 hour for Severity Level 1 issues. With Premier Support, you’ll get even faster response times, direct access to senior engineers, and a dedicated Success Manager to guide you.

    • 24/7/365 global support with over 180 AD experts
    • 95% customer satisfaction and 1-hour max response for critical issues
    • Highly skilled product and domain experts who interact at your skill level

    We have over 500 experts across our Professional Services, Customer Success, Tech Support, and R&D teams, allowing us to scale incident response services more effectively than smaller vendors. We offer planning, installation, configuration, testing, and knowledge transfer, recovery as a service, along with monthly checkups to ensure your team is prepared for any incident and can recover directory services swiftly.

    • Over 500 experts ready to scale incident response
    • Comprehensive Recovery as a Service package with monthly checkups
    • Critical incident response services for swift directory recovery

    We are a Gold Certified Microsoft Partner and six-time Partner of the Year award winner. We’ve also been selected for two strategic Microsoft Azure Marketplace partner programs, highlighting our commitment to securing and modernizing identity infrastructures worldwide. Our new Microsoft Security Copilot Plugin integrates Security Guardian with Microsoft AI to defend against identity threats at machine speed.

    • Selected for the Microsoft Security Copilot Partner Private Preview
    • Launched a Microsoft Security Copilot plug-in
    • Participating in multiparty Professional Services private offer programs

    At Quest, we’re proud to be named an example vendor for ITDR/AD Defense in Gartner’s IAM Best Practices for Active Directory research, listed in 11 categories—more than double any other vendor. This recognition underscores our unique focus on identity-centered security and our comprehensive AD solutions. With Quest, you can modernize and secure your IT environment effectively.

    • Listed in 11 categories in Gartner’s IAM Best Practices for Active Directory
    • Unique focus on identity-centered security with comprehensive AD solutions
    • Proven leader in AD migration, management, security, and disaster recovery

    Critical questions to ask when evaluating AD vendors

    Quest is extremely mindful of the increased attacks on supply chains and takes great lengths to protect it, with mature supply chain risk management practices and an airgap-secured assembly process that exceeds industry standards. Quest performs no development in countries of security concern.

    While other vendors may advertise being cyber-first, be sure to validate supply chain risk management practices, and ensure that your leadership is comfortable with the locations/countries where development is performed.

    We provide both automated disaster recovery and granular, object-level recovery within a single solution, ensuring comprehensive protection. Be careful of vendors who pitch automated remediation (which is really just rollback) as a replacement for granular recovery.
    We provide a transparent and visible recovery plan with specific, proven steps, progress indicators, and detailed difference reports to ensure effective communication and swift recovery.
    Some vendors suggest that clean OS recovery is good enough on its own and that malware detection is not needed to prevent malware re-introduction. But that’s not enough. We ensure AD backups are protected from compromise and malware reinfection with secure storage, clean and efficient backup files, and robust malware detection and removal.
    We provide multiple secure storage options for AD backups, recommend air-gapped or immutable storage, and ensure backups can be retrieved without relying on AD authentication.
    Make sure your vendor omits boot files in their AD backups, since they present a high risk of malware reinfection. We enhance backup efficiency and minimize malware risks by omitting boot files and other extraneous components from our AD backups.
    Some vendors merely react to unauthorized modifications (i.e. rollback approach). We provide proactive AD Object Protection, blocking unauthorized changes to sensitive objects, ensuring security even against privileged or rogue users.
    We offer the most comprehensive solution for governing GPOs, with automated management, in-depth auditing, and granular recovery, ensuring complete protection and restoration without needing to restore your entire AD.
    Confirm whether vendors provide audit coverage for key infrastructure applications like Exchange, SharePoint, Microsoft 365 or file systems. This will enable you to detect what an attacker does after they’ve compromised a network.
    We offer award-winning technical support with 24/7/365 availability, 1-hour response times for Level 1 cases, and a Premier Support option to reduce SLA times by half.

    Get started now

    Experience our Active Directory security solutions

    Recovery Manager for Active Directory Disaster Recovery Edition

    Automate and accelerate Active Directory recovery. Ransomware is today's most disruptive cyber threat, and Active Directory is increasingly in its crosshairs. Quest® Recovery Manager for Active Directory Disaster Recovery Edition slashes AD forest recovery time from days or weeks to just hours, giving you peace of mind that an AD disaster will not become a business disaster. 

    Hero CTAs (up to 3)
    Recovery Manager for Active Directory Disaster Recovery Edition

    Active Directory is a prime attack target

    69%

    of organizations impacted by ransomware

    21days

    Average downtime due to ransomware

    25B

    attempted attacks on Azure AD accounts

    Fast and secure Active Directory forest recovery is vital following a cyberattack. The longer AD is down, the longer your business is down. “The restore process from many well-documented ransomware attacks has been hindered by not having an intact AD restore process," according to Gartner, which also states that you can “accelerate recovery from attacks by adding a dedicated tool for backup and recovery of Microsoft Active Directory.” 

    With Recovery Manager for Active Directory Disaster Recovery Edition, you can restore AD at least five times faster than the manual Active Directory forest recovery process, according to ESG Research. One reason for that is due to extensive automation, which reduces the risk of human error and having to start over as the result of those errors. Recovery Manager also protects your AD backups from compromise and eliminates the risk of malware reinfection. It’s like an insurance policy for AD that you can’t afford not to have.

    Accelerates Recovery from Cyberattacks

    This comprehensive backup software solution is ideal for helping you rapidly recover from cyberattacks that impact AD. It offers a range of recovery options, including system state restore and full server backup capabilities, providing flexibility in addressing various disaster scenarios. Recovery Manager goes beyond traditional system state backup by offering granular recovery of identity directory services, allowing you to restore specific AD components without resorting to a full domain or forest recovery.

    In the case of a cyberattack, Recovery Manager proves invaluable for recovering compromised user accounts and service accounts. The solution can recover impacted accounts from pre-attack backups, even allowing for the reset of privileged account passwords to mitigate potential security breaches. This granular approach to recovery extends to deleted objects as well, enabling the restoration of specific AD objects without necessitating a complete forest or domain restore.

    Recovery Manager’s versatility is evident in its multiple recovery methods, including phased recovery and the ability to restore AD to a clean operating system. This flexibility is crucial when dealing with complex ransomware scenarios that may have affected multiple domain controllers across different geographical locations. The solution's Secure Storage server feature provides air-gapped storage for AD backups, ensuring that backups remain uncorrupted and inaccessible to ransomware. Additionally, Recovery Manager can scan servers for malware before they are used in recovery and offers the option to restore AD to a Microsoft Azure virtual machine, further enhancing security during the recovery process. These advanced features, combined with its ability to perform various types of restores — from bare metal recovery to reinstalling AD on existing hardware — make Recovery Manager a powerful tool in your organization’s ransomware defense strategy.

    "Accelerate recovery from attacks by adding a dedicated tool for backup and recovery of Microsoft Active Directory." - Gartner

    Key Benefits

    Adaptable to any disaster

    Handle any Active Directory disaster recovery scenario, from attribute changes to SYSVOL corruption to full AD forest disasters.

    Automated AD forest recovery

    Automate the Active Directory forest recovery process, including the 40+ steps outlined in Microsoft's AD forest recovery best practices.

    Flexibility and choice

    Choose the best method for your situation, whether that’s phased recovery, restoring AD to a clean OS or bare metal recovery.

    Clean, malware-free recovery

    Eliminate the risk of malware re-infection throughout your AD forest recovery, scanning for malware and minimizing its hiding places.

    Secure AD backups

    Ensure backups are always available with multiple options for secure physical and cloud storage.

    Battle-tested

    Quest has specialized in AD disaster recovery as long as AD has been around, helping thousands of customers, including 50% of the Fortune 100.

    Streamlined Active Directory Disaster Recovery

    Recovery Manager simplifies, automates and accelerates Active Directory forest recovery with unmatched security, flexibility and options to meet the needs of your business continuity and disaster recovery plans.

    Efficient and reliable AD backups

    Back up exactly what you need to recover AD. By omitting extraneous and risky components like boot files and the IIS Metabase, Recovery Manager reduces backup bloat, makes the backup process more efficient and minimizes the places where malware can hide.

    Secure storage

    Protect AD backups from malware infection with Secure Storage, a hardened server that is isolated according to IPSec rules with regular checks to confirm backup integrity. Even if you lose your DCs, Tier 1 storage and even your Recovery Manager server, you still have the Secure Storage backup that is hardened and secure to withstand the ransomware attack.

    AD backups in the cloud

    Recovery Manager ensures that your AD backups are always available in case of disaster with the flexibility to store backups in secure cloud locations such as immutable Azure Blob Storage and Amazon Web Services (AWS) S3 storage. 

    Phased recovery to shorten RTO

    After you back up Active Directory, you can shorten recovery time objectives with a phased Active Directory recovery approach. Quickly restore key DCs, enabling sign-in and business-critical functions as soon as possible. Then dramatically accelerate recovery of remaining DCs with automated repromotion methods.

    Flexible AD recovery options

    Choose the AD disaster recovery method that works best in a given situation, whether that’s phased recovery, restoring to a clean OS to minimize the risk of malware reinfection or bare metal recovery. You can restore AD to a clean OS on any machine, whether it’s a physical machine, on-prem virtual machine or a cloud-hosted VM.

    Clean OS recovery to the cloud

    During an attack, you need to restore to a new machine you can trust. Quickly and easily create Microsoft Azure resources including virtual machines during an AD forest recovery. This enables you to recover AD to a readily available, secure and cost-effective machine that you can trust is clean from malware.

    Malware detection and removal

    Eliminate the risk of malware re-infection throughout your AD disaster recovery process with regular checks for viruses after the backup file is created, during storage when updates are added and before a restore is started with integrated Microsoft’s Defender capabilities. If needed, you can safely pause your recovery to quarantine or remove corrupted files. 

    Operating system recovery

    Quickly restore your domain controller’s operating system without depending on others. Recovery Manager gives AD admins more control of the recovery process, saving time and resources by eliminating dependencies on cross-departmental teams.

    Insurance group slashes Active Directory recovery time

    With native tools, a restore would take days or weeks; with Quest, we can be fully operational again in hours.

    Krist Cappelle Information Security Program Manager, P&V Group

    Telefónica España slashes AD recovery time with Recovery Manager

    Being able to restore an AD forest in hours instead days is priceless. Now I can sleep peacefully.

    IT Manager

    Top 5 Global Petroleum Producer ensures seamless business continuity

    With Recovery Manager, we have always passed the annual AD recovery audits, maintaining the strong reputation and market valuation of both the energy company and TCS.

    Suhas Pawar Associate Consultant, Tata Consultancy Services

      Additional Features

      Online granular restore

      Restore individual attributes, such as account settings, group memberships and binary attributes, even when the object itself has not been deleted. This enables you to restore only the required attributes without restarting domain controllers.

      Comparison reporting

      Highlight changes made since the last backup by comparing the online state of AD with its backup or by comparing multiple backups. Accelerate recovery by quickly pinpointing deleted or changed objects or attributes. And with Change Auditor you can easily identify who made the changes.

      AD management and health validation

      Inspect AD for warning signs of possible issues before they become disasters by checking DC accessibility, replication, trusts and user authentication.

      Recovery console fault tolerance

      With Recovery Manager, you can share persistent configuration data between several instances of your recovery consoles so that you can quickly resume the last restore operation in case it was unexpectedly interrupted.

      Recovery roadmap

      After you back up Active Directory, you can generate a detailed recovery process report, including an overview of every stage of the recovery, to gain a better understanding and more control over the project.

      Hybrid AD and Azure Active Directory recovery

      A solid on-premises Active Directory recovery plan alone isn’t sufficient since so many organizations are making greater use of cloud-only objects such as Azure AD groups, Azure B2B/B2C accounts, conditional access policies and more. With On Demand Recovery, you can quickly and securely back up and recover Azure AD.

      AD Disaster and Forest Recovery Services

      Quest Professional Services ensure your Active Directory recovery plan is in place quickly and validates your forest recovery model. Whether your team lacks the technical expertise, does not have the manpower or just does not have time to configure, test and deploy your solution, our subject matter experts help you through this process using our tested implementation methodology.

      • Verify backup and recovery plans aligned with industry best practices
      • Test and document recovery plans for domain controllers, full forest and crisis scenarios
      • Participate in a scheduled recovery exercise, ensuring full integration with other disaster recovery and business continuity plans

      FAQs – Active Directory Disaster Recovery

      Active Directory Recovery is the process of restoring Active Directory (AD) services and data after a catastrophic failure or cyberattack, such as ransomware. It involves rebuilding domain controllers, restoring AD databases, and reestablishing forest-wide services to bring the AD environment back to a functioning state. Active Directory recovery is critical because AD is the backbone of most organizations' IT infrastructure and identity services, controlling user authentication, access to resources, and application functionality.

      Effective AD recovery requires careful planning, secure backups, and a rapid recovery solution like Recovery Manager to automate and accelerate the process. Manual recovery can be extremely time-consuming and error-prone, often taking days or weeks to complete. Purpose-built solutions like Recovery Manager for Active Directory Disaster Recovery Edition can significantly reduce recovery time to hours, minimize the risk of malware reinfection, and provide flexible recovery options such as phased recovery or restoring to a clean operating system. Given the increasing threat of ransomware and other cyberattacks targeting AD, having a robust and tested AD recovery plan is essential for maintaining business continuity.

      Active Directory recovery encompasses several types of operations, ranging from granular object restoration to full forest recovery. For minor issues, online granular restore allows you to recover individual attributes or objects without restarting domain controllers. This is useful for correcting accidental changes or deletions. For more severe scenarios, there are multiple options for full recovery: Bare metal recovery (BMR) allows you to recover all volumes of a domain controller to new or different hardware; restore to clean OS enables you to restore AD onto a new Windows Server while reducing the risk of reinfection; and phased recovery lets you prioritize the restoration of critical domain controllers to get essential services running quickly.

      Other recovery types include installing Active Directory on new servers to replace compromised DCs, uninstalling and reinstalling AD on existing servers, and repromotion of remaining DCs in a partially recovered forest. The choice of recovery method depends on the extent of the damage, the risk of malware persistence, and the organization's specific needs. Solutions like Recovery Manager for Active Directory Disaster Recovery Edition provide flexibility in choosing the most appropriate recovery method for a given situation, whether it's restoring to on-premises hardware, virtual machines, or even cloud-hosted VMs in Microsoft Azure.

      With Microsoft-provided tools and manual processes, Active Directory forest recovery is a difficult, time-consuming and error-prone process. In fact, Microsoft’s “Active Directory Forest Recovery Guide” outlines 40 high-level steps that must be performed correctly and in the proper sequence — on each DC. In addition, many of the steps aren’t operations that AD administrators are familiar with; they are tedious, often command-line based steps, so it’s very easy to make mistakes that can re-corrupt your directory and require you to start over. Quest reduces risk by automating every one of these manual steps. In fact, ESG Research validated that Recovery Manager can restore AD at least five times faster than the manual AD forest recovery process.

       

      Bare metal recovery (BMR) is a crucial capability  of your Active Directory recovery arsenal because it allows you to recover not just the Active Directory data, but also the entire domain controller's operating system in the event of a catastrophic failure. This is especially important in rare scenarios where more than just Active Directory needs to be recovered. With BMR, you can restore a domain controller to its previous state on entirely new hardware, ensuring that all configurations, settings, and data are preserved.

      Furthermore, BMR provides a more comprehensive and efficient recovery solution compared to traditional enterprise and Windows methods. It eliminates the need to manually reinstall the operating system and reconfigure the domain controller, which can be time-consuming and error-prone. By restoring both the operating system and Active Directory simultaneously, BMR significantly reduces downtime and ensures that your Active Directory infrastructure can be brought back online quickly and accurately, even in the most severe disaster scenarios. Quest allows you to restore AD to a clean OS on any machine, including physical machines, on-premises virtual machines or cloud-hosted virtual machines.

      VM snapshots are no substitute for an enterprise AD disaster recovery solution. Using snapshots for forest recovery will almost always result in data consistency problems that are difficult to resolve. Since the data on DCs is constantly being updated and the replication process takes time, snapshots of different DCs almost always contain inconsistent information. Snapshots can also include malware, which gets restored with everything else on the DC. Plus, if you store your VM snapshots in the default location, they’re an obvious target for ransomware encryption, which can render them useless. There’s also a logistical issue. Usually, control over VM snapshots resides with the virtualization operations team, which complicates the AD team’s job during the recovery operation. Finally, the virtualization team might not even know that the AD snapshots are an essential part of the organization’s disaster recovery strategy, so they might not protect them appropriately.
      An immutable backup is a duplicate copy of data that cannot be altered or removed for a specified timeframe. It’s another method your organization can use to protect valuable data from threats ranging from cyberattacks to accidental removal. When it comes to Active Directory security, Quest solutions provide multiple storage locations for AD backups, with many organizations choosing to have a dedicated backup location for their identity team that does not rely on traditional backup teams (since traditional backup teams often rely upon Active Directory for authentication). While some organizations can choose to store backups inside enterprise backup storage, you should validate that there are authentication capabilities to retrieve those backups that do not require Active Directory. Because we’ve seen physical destruction, as well as loss of connectivity to the internet, we recommend that your backups are air-gapped or on immutable storage.
      Most data protection tools simply do not suffice for AD disaster recovery. As noted above, in an AD forest recovery, you must coordinate the configuration effort across multiple DCs. Failure to do so can run the risk of USN rollback, RID bubbles, RID re-use, lingering objects in the Global Catalog and other issues that can cause serious issues with Active Directory functionality. But most traditional data protection solutions simply focus on getting individual DCs to a “healthy” state — and leave all the coordination work to you.

      Tour

      Flexible recovery methods
      Bare metal backup
      Malware detection
      Progress monitor
      Recovery project plan

      Flexible recovery methods

      Flexible recovery methods include restoring AD to a clean OS and a Microsoft-compliant bare metal recovery.

      Bare metal backup

      Automatically restore from bare metal and follow up with your most current Active Directory backup.

      Malware detection

      Implement the added safety of regularly checking files for viruses with integrated Microsoft’s Defender capabilities.

      Progress monitor

      Monitor your progress to ensure complete Active Directory forest recovery for server data and operating system.

      Recovery project plan

      Automatically document your entire Active Directory recovery plan.

      Specifications

      Before installing Recovery Manager for Active Directory, ensure that your system meets the following minimum hardware and software requirements.

      NOTE

      • Recovery Manager for Active Directory supports only IPv4 or mixed IPv4/IPv6 networks.
      • Recovery Manager for Active Directory Forest Edition can backup and restore domain controllers that are running on virtual machines in Amazon Web Services (AWS) or Microsoft Azure. Note that such domain controllers cannot be restored with the Bare Metal Active Directory Recovery method because there is no way to boot them from an ISO image.
      Processor

      Minimum: 2.0 GHz

      Recommended: 2.0 GHz or faster

      CPU Cores

      Minimum: 2 CPU cores

      Recommended: 4 CPU cores

      Memory

      Minimum: 4 GB

      Recommended: 8 GB

      These figures apply only if the Active Directory domains managed by Recovery Manager for Active Directory include 1 million objects or less. Increase RAM size by 512 MB for every additional 1 million objects.

      Hard Disk Space

      Full installation including the prerequisite software: 2.7 GB of free disk space

      In case all the prerequisite software is already installed: 260 MB of free disk space

      NOTE Additional storage space is required for a backup repository, at least the size of the backed-up Active Directory database file (Ntds.dit) and the SYSVOL folder plus 40MB for the transaction log files.

      Operating System
      • Machine that hosts the Recovery Manager for Active Directory console must have same or higher version of Windows operating system than the processed domain controllers. Otherwise, the online compare and object search in a backup during the online restore operation may fail.
      • 32-bit operating systems are not supported.

      Installation

      • Microsoft Windows Server® 2022, 2019, and 2016
      • Microsoft Windows 11, 10 x64, 8.1 x64

      Targets for backup, restore, or compare operations

      • Microsoft Windows Server® 2022, 2019, and 2016 (including Server Core installation
      Microsoft .NET Framework

      Microsoft .NET Framework version 4.8 or higher is needed on the console system.

      NOTE: Microsoft .NET 4.8 is not required to be installed on the systems where the Forest Recovery and Backup agents are to be installed. The Secure Storage Agent does use .NET and it is recommended to install 4.8 on the Secure Storage system, but the agent will work with older versions.

      Microsoft SQL Server and its components

      Microsoft SQL Server versions

      Microsoft SQL Server® is required for the following Recovery Manager for Active Directory features: Comparison Reporting and Forest Recovery Persistence.

      Supported SQL Server versions:

      • Microsoft SQL Server® 2022, 2019, 2017, 2016, and 2014 (Enterprise, Business Intelligence, Standard, Express, Web, or Developer Edition)

      Microsoft SQL Server components

      Microsoft System CLR Types for SQL Server® 2014

      If this component is not installed, it will be installed automatically by the RMAD setup.

      Microsoft SQL Server Reporting Services

      To display reports, Recovery Manager for Active Directory can integrate with Microsoft SQL Server® Reporting Services (SRSS) 2016, 2017, 2019, and 2022.

      Microsoft Windows PowerShell

      Microsoft Windows PowerShell version 5.0 or later

      Integration with Change Auditor for Active Directory

      Supported versions of Change Auditor for Active Directory: from 6.x to 7.x.

      If any prerequisite software is not installed, the Setup program automatically installs it for you before installing Recovery Manager for Active Directory. If the prerequisite software to be installed is not included in this release package, it is automatically downloaded.

      Continuous recovery: From version 10.0.1, Recovery Manager for Active Directory together with Change Auditor can restore the deleted object(s) and continuously restores the last change (if any) that was made to the object attributes after creating the backup, using the data from the Сhange Auditor database.

      Antivirus software that is supported for backup antimalware checks

      The anti-virus checks are performed on the Forest Recovery Console machine running Windows Server 2016 or higher by means of antivirus software installed on the machine.

      • Microsoft Defender
      • Symantec Endpoint Protection 14.x
      • Broadcom Endpoint Security (former name: Symantec Endpoint Protection 15)
      Supported server management systems
      • Integrated Dell Remote Access Controller (iDRAC) 8 and 9
      • HP ProLiant iLO Management Engine (iLO) 3, 4 and 5
      • VMware vCenter/ESX Server 6.0, 6.5, 6.7 and 7.0
      • Microsoft Hyper-V Server 2012 or higher
      Memory

      1 GB (2 GB recommended)

      Hard disk space

      2 GB or more

      Operating System

      One of the following operating systems:

      • Microsoft Windows Server® 2022, 2019, and 2016 (including Server Core installation)

       

      Secure Storage Server

      Processor

      Minimum: 2.0 GHz

      Recommended: 2.0 GHz or faster

      CPU Cores

      Minimum: 2 CPU cores

      Recommended: 4 CPU cores

      Memory

      Minimum: 4 GB

      Recommended: 8 GB

      • Operating system: Microsoft Windows 2016 or higher
      • A stand-alone server to be used as your Secure Storage server. This server should be a workgroup server and not joined to an Active Directory domain.
      • An account that will be used to deploy the Storage Agent on the Secure Storage server. This account must also be a local Administrator on the Secure Storage server.
      • Physical access to the Secure Storage server. Once the server is hardened access with regular methods will be disabled.
      • Sufficient storage space on the Secure Storage server for all backup files. For one backup file, the space required is at least the size of the backed-up Active Directory database file (Ntds.dit) and the SYSVOL folder plus 40MB for the transaction log files.
      Cloud Storage
      • Internet access available on the Recovery Manager for Active Directory console. A standard outbound HTTPS port 443 is used to upload data to Azure Blob and Amazon Web Services S3 Storage.
      • Azure and Amazon Web Services subscription(s) to create and manage Azure and Amazon Web Services S3 Storage accounts and containers.
      • A method of creating and managing Azure and Amazon S3 Storage accounts, containers, and policies for the storage account (lifecycle, immutability and replication policies).

      You can only use the Password and SIDHistory Recoverability Tool if Microsoft's Active Directory Recycle Bin is not enabled in your environment.

      Recovery Manager for Active Directory Disaster Recovery Edition is upgradeable from version 10.0 or later.

      Get Started Now

      Be prepared to quickly recover from any AD disaster.

      Support & Services

      Product Support

      Self-service tools will help you to install, configure and troubleshoot your product.

      Support Offerings

      Find the right level of support to accommodate the unique needs of your organization.

      Professional Services

      Search from a wide range of available service offerings delivered onsite or remote to best suit your needs.