All lessons Leer en español

Security in depth · Unit 24 · Lesson 14 of 14

Identity is a recovery dependency

Find circular recovery dependencies before treating a successful backup as a usable recovery plan.

3 minreadyShort lesson

Helpful before thisActive Directory

See all lessons in this topic

After this lesson you can

  • Explain why backup access and recovery instructions need an available, protected path during an identity outage.

A recovery key is useful only if authorized responders can reach it when the normal entrance is closed.

Recovery has prerequisites

Directory recovery depends on usable backups, documented procedures, protected recovery authority, and infrastructure such as DNS. A successful backup job proves a narrower fact than a successful recovery exercise.

Map how responders reach each prerequisite while ordinary identity services are unavailable. Protect independent recovery access with ownership and controlled use; do not make emergency access an unaccountable everyday alternative.

Identity outage → Protected recovery path → Trusted service restoredIdentity outageProtected recovery pathTrusted service restored
The middle step must remain usable during the specified outage. A backup status alone does not establish a protected path or restored trust.

Supplied record: the neighborhood foundation

The fictional foundation reviews this exercise packet:

01:00: the directory backup job reports success.
09:00 scenario: all domain controllers are unavailable.
Backup vault: new sign-in requires live AD authentication.
Recovery guide: stored on a share with the same requirement.
Independent access exercise: no evidence supplied.

Assume no existing sessions or alternate access are documented in the packet. Its recovery path is circular: responders need functioning AD to obtain materials needed for AD recovery. This finding concerns the documented design; it does not prove that no other arrangement exists elsewhere.

Write what would establish readiness

Assign owners to demonstrate protected independent access to the vault and guide during the stated outage. Acceptance also needs a supported recovery exercise with suitable backups, working identity dependencies, and approved access restored.

Diagnose the failure before choosing recovery scope; full forest restoration is not the default for every login failure. If compromise is suspected, backup selection must assess a trustworthy prior state, not simply choose the newest copy. Include the recovery time and any lost changes in the owner’s acceptance decision.

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. The backup succeeded, but both the vault and recovery guide require unavailable live AD authentication. What does the packet establish?

    Show the answer

    Correct answer: The documented recovery path has a circular dependency; backup success does not prove responders can begin recovery. Reaching the materials needed to restore identity requires that same identity service. The packet supplies no exercised independent access path.

Try it

  • WriteWrite a dependency review for the vault and recovery guide. Name each required identity service, the protected independent access evidence missing from the packet, its owner, and acceptance criteria for an outage exercise.
References