Cyber-First Disaster Recovery for Active Directory

Active Directory Forest Recovery

Reduce time to recover AD after a cyberattack by up to 90%.

Fast, malware-free AD forest recovery

Widespread attacks that exploit Active Directory can cripple your organization. When a ransomware or wiper attack takes out domain controllers, recovering your AD forest can drag on for days or even weeks, risking malware re-infection in the process. But with Semperis Active Directory Forest Recovery (ADFR), you’ll be back in business in minutes or hours rather than days or weeks.

Cut downtime

Restore AD in 5 clicks with automated, multi-forest recovery.

Eliminate malware

Avoid reintroducing malware by recovering AD to a known-secure state.

Automate resilient backups

Automate backups to immutable Azure storage and restore to any virtual or physical hardware.

Speed forensics

Accelerate post-breach forensics to prevent follow-on attacks.

“We see increased phishing attacks, every day there’s billions of threats, and we’re just trying to find ways to circumvent that.”

Disaster Recovery Planning and Security Posture at Legal Firm Foulston Siefkin

Foulston Siefkin LLP, the largest Kansas-based law firm, transitioned from a fully on-premises Active Directory (AD) environment to a hybrid AD/Entra ID cloud identity environment in 2018. While working through the process of securing the hybrid environment, the company reviewed its business continuity practices and looked for a solution that would help the firm meet its identity system recovery and security posture goals.Implementing Semperis Active Directory Forest Recovery (ADFR) and Directory Services Protector (DSP) were key to the firm’s cyber resilience strategy, said Matt Spurlock, Foulston Siefkin CTO.

Our mission resonates with industry leaders

Experience a Personalized Demo

Request a Demo and one of our product experts will give you a spin of our solutions.

Active Directory Forest Recovery

Semperis protects some of the largest AD environments

Everything starts with an ID and password. First thing you need to recover is credentials to do any other type of recovery.

Kerry Kilker Former CISO
Walmart

Frequently asked questions

What is Active Directory Forest Recovery?

ADFR is the only backup and recovery solution purpose-built for recovering Active Directory from cyber disasters. ADFR fully automates the AD forest recovery process, reduces downtime, eliminates risk of malware reinfection, and enables post-breach forensics.

We rely on a traditional DR tool for recovery. Why do we need Semperis ADFR? 

Most backup and recovery products target servers, and Active Directory is included in the backup process because it is a role on the server. But if a cyberattack hits your AD, you need a solution that removes AD from the operating system so you don’t reinfect AD with the malware as part of the recovery process. Semperis ADFR can get AD back online—on a new, trusted server—within minutes, not days, and without reintroducing malware as part of the process.

We rely on a multi-data center warm failover solution. How would ADFR help in this scenario?

Typically, warm sites contain the necessary hardware, but do not contain the most recent version of the production site. Since data is not being consistently replicated between the production and warm site, there is greater latency for failover. ADFR is capable of restoring to alternate hardware and provides IP mapping to create an exact replica (or clone) of your production AD forest in an isolated lab. ADFR reduces the time and effort required to set up and maintain your warm failover site, making it feasible to replicate the production site more often and reduce data latency issues.

How does ADFR ensure the integrity of a backup?

ADFR validates each backup rule when it’s created to ensure it can be used to generate a valid forest backup set. By default, the ADFR backup validation process checks to ensure there is at least one DC hosting each partition in the backup set. The status of the backup rule validation process is displayed in the Backup Settings page of the ADFR Administration portal.

Why do I need ADFR when I already have a data protection solution?

Data protection solutions do not offer a cyber disaster recovery solution for Active Directory. They offer backup and recovery of individual domain controllers (DCs) and files. This is an important distinction, and one that applies to other backup vendors as well. Backup vendors can back up a DC, and they can restore a DC. But none can orchestrate the many steps required to correctly and successfully restore an AD forest.

In contrast, ADFR offers a fully automated forest recovery solution that enables you to recover AD even if DCs are infected or wiped out. ADFR automates every aspect of forest recovery, including cleaning up metadata, rebuilding the Global Catalog, and restructuring site topology. Manually rebuilding AD following a cyber incident is a time-consuming, error-prone process that can takes days or weeks.

Why are BMR and snapshots not recommended for Active Directory recovery?

Bare metal recovery (BMR) can be a convenient way to restore a computer’s operating system and settings, for example, if an OS upgrade goes wrong, or if you want to move a user or an application to a new machine. However, if a DC has been infected or disabled by a cyberattack, the BMR backups will likely contain boot files, other executables, and OS files where malware can hide. If you restore a DC from a BMR backup, you might also restore any malware present in the backup.

Does ADFR automatically detect problems with a backup and self-correct or trigger an alert?

When a backup set completes with an error or warning, ADFR automatically sends an email notification to designated recipients. In addition, you can opt into receiving email notifications for successful backups. The ADFR Administration portal also displays backup status information: 1) Dashboard provides a list of recent forest backup sets, showing both available and failed backups. 2) Backups Status & History page displays status details for each backup, including backups that failed and transfers of the backup to the distribution point that failed.

Can ADFR support large, complex AD environments?

ADFR is purpose-built for AD and can support the recovery needs of even the most complex AD environments, including multi-organization and multi-forest deployments. Organizations with some of the largest and most complex ADs in existence rely on Semperis to implement a cyber-first approach to disaster preparedness and recovery.