Active Directory Listeners for Agentless Object Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection systems struggle with granular recovery of active directory (AD) objects from virtual machine backups in production environments without requiring agents, and inefficient management of backup schedules and resource consumption.
Innovation Solution
A backup server enhances data protection services by installing AD listeners to track changes, managing backup schedules, and providing granular recovery of AD objects from production tombstones or VM backups, reducing the need for agents and optimizing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agents are installed in production environments to enable granular recovery of AD objects, then recovery capability is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent introduces AD listeners as intermediary components that monitor AD object changes in the production environment without requiring full agent installation. These listeners act as mediators between the backup server and AD objects, capturing change notifications and transmitting them to the backup server for incremental backup, thereby enabling granular recovery while minimizing system complexity
Solution Approach 2:
The patent extracts the essential monitoring function from a complete agent installation by implementing lightweight AD listeners that only perform change detection and notification. This extraction allows the system to obtain granular recovery capability without the overhead of full agent deployment, reducing system complexity while maintaining recovery effectiveness
2Reliability
If frequent backups are performed to ensure data availability for granular recovery, then data availability is improved, but resource consumption increases
Solution Approach 1:
The patent implements periodic incremental backups triggered by AD object changes rather than continuous or fixed-interval full backups. The AD listeners monitor for changes and initiate backup operations only when modifications occur, creating a event-driven periodic backup rhythm that ensures data availability while minimizing unnecessary resource consumption during stable periods
Solution Approach 2:
The patent changes the backup parameter from fixed time intervals to change-triggered intervals. By monitoring AD object modification parameters and using them to trigger backup operations, the system dynamically adjusts backup frequency based on actual data changes, optimizing the balance between data availability and resource consumption
3Productivity
If AD listeners are deployed to track changes for incremental backup, then backup efficiency is improved, but network traffic and processing overhead increase
Solution Approach 1:
The patent extracts only the essential change notification data from AD object modifications rather than transmitting complete object data or continuous state information. The AD listeners capture minimal change metadata (object identifier, change type, timestamp) and transmit only this extracted information to the backup server, improving backup efficiency while minimizing network traffic and processing overhead
Data Source
AI summary
A method for managing data protection includes initiating, by a backup server, identifying an active directory (AD) application on the VM, wherein the AD application comprises a set of AD objects and a directory service for managing the set of AD objects, in response to identifying the AD application, installing a new AD listener in the production environment, performing listening on the AD application in the production environment to detect changes to the set of AD objects, monitoring, by the backup server, generating a VM backup of the VM and an AD application backup of the AD application, and storing the VM backup and the AD application backup in a backup storage system, based on the VM backup generation, and based on the listening, performing a backup schedule analysis on the backup schedule, and based on the backup schedule analysis, performing a backup schedule modification on the backup schedule.


