Active Directory Object Recovery Using Listeners and Production Tombstones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection systems struggle with granular recovery of active directory (AD) objects from virtual machines, requiring full backups and lacking efficient methods for tracking changes and managing backup schedules without agents in the production environment.

Innovation Solution

A backup server with AD listeners and recovery microservices tracks changes using resilient change block tracking, manages backup schedules, and provides granular recovery from production tombstones or VM backups, enabling agentless AD object recovery and efficient resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full backups of virtual machines are performed to protect AD objects, then data protection coverage is improved, but backup time and storage resources are increased

Engineering Contradiction:
Improvedata protection coverageVSAvoidbackup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the backup process by identifying and separately handling AD-related data within VM backups. The backup system parses VM backups to extract AD object data, enabling granular recovery of only AD objects rather than requiring full VM restoration. This segmentation allows selective backup and recovery of critical AD data, reducing overall backup time while maintaining protection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts AD object information from VM backups by parsing backup data to identify AD-specific data structures. The system extracts generation IDs, object identifiers, and AD object attributes from backup streams, enabling independent recovery of AD objects without restoring entire virtual machines. This extraction process significantly reduces recovery time for AD-specific recovery scenarios.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If agents are installed in the production environment to track AD object changes, then change tracking accuracy is improved, but system complexity and deployment difficulty are increased

Engineering Contradiction:
Improvechange tracking accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary approach by using AD listeners that monitor AD object changes through the AD protocol rather than requiring agents installed on each AD object source system. The listeners act as intermediaries between the backup system and AD objects, tracking changes by listening to AD replication traffic and change notifications. This eliminates the need for complex agent deployment while maintaining accurate change tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables self-service change tracking by leveraging the AD environment's existing replication and notification mechanisms. The AD listeners utilize AD's built-in change notification capabilities and replication traffic to automatically detect and track AD object changes without external intervention or additional software installation on AD domain controllers. This self-service approach reduces system complexity while maintaining tracking accuracy.

Inventive Principle:
Principle #25Self-service

3Reliability

If AD listeners are installed to track changes in real-time, then recovery freshness is improved, but computing resources and network bandwidth are consumed

Engineering Contradiction:
Improverecovery freshnessVSAvoidcomputing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic polling and event-driven listening mechanisms that balance real-time change detection with resource conservation. The AD listeners operate in a periodic manner, checking for changes at intervals or triggered by AD replication events, rather than continuously monitoring all AD traffic. This periodic action maintains recovery freshness by capturing changes promptly while reducing computing resource consumption compared to continuous real-time monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent dynamically adjusts listener operation parameters based on change activity levels and recovery requirements. The system modifies polling intervals, listener activation states, and monitoring intensity based on detected AD object change frequencies and recovery priority levels. This parameter adjustment optimizes the balance between recovery freshness and resource consumption, reducing overhead during stable periods while maintaining responsiveness during active changes.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If granular recovery of AD objects is enabled, then recovery flexibility is improved, but recovery process complexity is increased

Engineering Contradiction:
Improverecovery flexibilityVSAvoidrecovery process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates and maintains copies of AD object metadata and generation information in the backup catalog during the backup process. These copies include object identifiers, generation IDs, and hierarchical relationship data that enable rapid identification and recovery of specific AD objects. By pre-processing and storing this metadata information, the system simplifies the granular recovery process, allowing users to recover individual AD objects without navigating complex backup restoration procedures.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary parsing and organization of AD object data during the backup process, structuring backup data to facilitate future granular recovery operations. The system pre-identifies and tags AD objects within VM backup streams, organizing data by object type, hierarchy, and generation information before recovery is needed. This preliminary action reduces recovery process complexity by having all necessary information prepared and organized in advance, enabling straightforward selective recovery of AD objects.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12399787B1Detecting the most recent state of an active directory object and recovering using backups or production tombstones
Publication Date: 2025.08.26 DELL PROD LP
  • US12399787B1 patent drawing
  • US12399787B1 patent drawing
  • US12399787B1 patent drawing

AI summary

A method for managing data protection includes initiating, by a backup server, identifying an active directory (AD) application on the VM, wherein the AD application comprises a set of AD objects and a directory service for managing the set of AD objects, in response to identifying the AD application, installing a new AD listener in the production environment, performing listening on the AD application in the production environment to detect changes to the set of AD objects, monitoring, by the backup server, generating a VM backup of the VM and an AD application backup of the AD application, and storing the VM backup and the AD application backup in a backup storage system, based on the VM backup generation, and based on the listening, performing a backup schedule analysis on the backup schedule, and based on the backup schedule analysis, performing a backup schedule modification on the backup schedule.