Virtualized Active Directory Recovery Agent Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Active Directory recovery solutions face challenges in configuring virtual domain controllers when security software prevents batch file execution, limiting the ability to automate configuration steps in virtualized environments.

Innovation Solution

Installation of a recovery agent on domain controllers, which is added to the security software's trusted list, allows it to scan a known directory for command files and execute configuration commands, enabling configuration of virtualized domain controllers without batch files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software is installed on domain controllers to protect against threats, then security reliability is improved, but batch file execution is blocked which limits automation capability

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidautomation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent introduces a recovery agent as an intermediary component that mediates between the security software and the configuration process. The recovery agent is added to the security software's trusted list, allowing it to execute commands and batch files that would otherwise be blocked. This intermediary approach maintains security restrictions for regular processes while enabling automation for authorized recovery operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The recovery agent is pre-installed on domain controllers before the virtualization or recovery process begins. By establishing the trusted recovery agent in advance, the system prepares the security infrastructure to allow automated operations during critical recovery scenarios without compromising ongoing security protections.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If third-party virtualization software is used to create virtual test environments, then virtualization capability is improved, but configuration flexibility is limited due to reliance on native tools

Engineering Contradiction:
Improvevirtualization capabilityVSAvoidconfiguration flexibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The recovery agent serves as an intermediary that bridges the gap between the limited native virtualization tools and the need for comprehensive configuration capabilities. It enables the execution of custom batch files and commands that are not supported by standard virtualization interfaces, providing enhanced configuration flexibility while maintaining compatibility with third-party virtualization platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If exact copies of domain controllers are created in the virtual environment, then replication accuracy is improved, but security software restrictions are carried over blocking automation

Engineering Contradiction:
Improvereplication accuracyVSAvoidautomation capability
Core Design Contradiction:
Manufacturing precisionVSExtent of automation

Solution Approach 1:

The patent creates exact copies of domain controllers in the virtual environment, including copying the recovery agent and security software configurations. This ensures replication accuracy while the copied recovery agent maintains its trusted status, enabling automation in the virtual environment just as in the source environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10268550B2Virtualizing a secure active directory environment
Publication Date: 2019.04.23 QUEST SOFTWARE INC
  • US10268550B2 patent drawing
  • US10268550B2 patent drawing
  • US10268550B2 patent drawing

AI summary

A recovery solution can employ virtualization software to create a virtualized Active Directory forest from a source Active Directory forest. A recovery agent can be installed on the domain controllers prior to creating copies of the domain controllers in the virtualized forest. Additionally, the recovery agent can be added to a list of trusted applications if the domain controller includes security software. The recovery solution can employ the virtualization software to store a command file at a known directory path. This command file can include commands that should be executed on the virtualized domain controller to configure it properly. The recovery agent can be configured to periodically scan the known directory path to determine whether a command file has been stored in the directory. If the recovery agent locates a command file, it can extract and execute any commands in the command file.