An authoritative restore is not the same as restoring a domain controller’s system state. A normal system-state restore puts that DC’s Active Directory database back to the backup point; an authoritative restore then marks selected objects or a container so the restored data replicates to other domain controllers. Use the object-restore procedure for deleted users, computers, or groups. Use Microsoft’s separate forest-recovery workflow when a domain controller, domain, forest, or SYSVOL must be recovered.
Choose the recovery operation before running a command
| Recovery goal | Documented approach | Scope and main risk |
|---|---|---|
| One deleted user, computer, group, or other object | Restore a suitable system-state backup, then run Ntdsutil restore object for that object. |
Smallest rollback scope; only the selected object is marked authoritative. |
| Several deleted objects in the same container | Restore the lowest common parent that contains them, using the subtree procedure only when that scope is acceptable. | Every object and attribute in the selected container can be rolled back to the backup point. |
| One domain controller, a domain, or an entire forest | Follow the applicable Active Directory forest-recovery procedures, including separate AD DS and SYSVOL steps. | Recovery order, DC roles, forest topology, and SYSVOL replication technology determine the correct sequence. |
Do not combine an object-level Ntdsutil operation with forest-recovery steps unless the matching Microsoft procedure explicitly calls for it.
Prerequisites and checks
- Have a valid, AD-aware system-state backup from an appropriate recovery point. Microsoft documents Windows Server Backup and wbadmin methods for backing up system state.
- Confirm that the backup explicitly contains system-state data. Microsoft states that a full-server backup intended only for full-server recovery does not, by itself, qualify for the documented system-state recovery procedure.
- Identify the deleted object’s exact distinguished name (DN), or the lowest common parent DN for a group of objects. Check the spelling, organizational units, and domain components before entering the command.
- Use the most current suitable backup, but first determine whether restoring it would roll back changes that must be preserved.
- Record the Windows Server version, forest and domain roles, backup method, and whether SYSVOL uses DFS Replication (DFSR) or legacy File Replication Service (FRS). Microsoft’s forest-recovery material covers Windows Server 2016, 2019, 2022, and 2025; use the procedure for the installed version.
- Plan a maintenance window and ensure that the recovery DC and replication partners can be isolated or controlled as the applicable procedure requires.
Authoritatively restore selected deleted AD objects
1. Restore the system state on the recovery DC
Use the AD-aware restore process for the recovery DC and restore the most current suitable system-state backup. This returns the local directory to the state represented by that backup; it does not yet make the restored object authoritative throughout the domain.
2. Restore one object with Ntdsutil
Microsoft’s documented command pattern is:
ntdsutil "authoritative restore" "restore object <object DN path>" q q
Replace <object DN path> with the object’s complete DN and retain the quotation marks. For example, an object DN might look like CN=Alice,OU=Sales,DC=corp,DC=example,DC=com; use the real DN from your directory, not this example. The operation marks that restored object as authoritative so its data can replicate outward according to the recovery procedure.
Recommended Free Tools
#1 Best Overall
3. Restore several objects only when the container scope is safe
If the deleted objects share a parent container, Microsoft says to target the lowest common parent. The subtree form is:
ntdsutil "authoritative restore" "restore subtree <container DN path>" q q
A subtree restore affects all objects and attributes in that container as they existed in the backup. It can therefore replace newer passwords, home-directory or profile-path values, contact information, group membership, and security descriptors. Choose this method only when that rollback is acceptable; individual restores require more operations but limit unrelated changes.
Rank #2
4. Restart and replicate
After the authoritative operation, restart the recovery DC in normal Active Directory mode and allow outbound replication as directed by Microsoft’s current object-recovery procedure. Restored memberships that involve objects in another domain can require additional backlink handling; Microsoft documents Ntdsutil-generated object and LDIF files for those cases. Follow the procedure matching your topology rather than copying only the command shown above. The detailed object semantics and syntax are in Restore user accounts and groups in AD.
5. Validate the result
- Confirm that the restored object has the expected DN, attributes, enabled state, and group relationships.
- Check the other domain controllers after replication and verify that the object is present with the intended values.
- For cross-domain memberships, verify both sides of the relationship and apply the documented backlink procedure if required.
- Keep the backup and recovery notes until replication and application sign-in tests are complete.
Forest recovery: AD DS and SYSVOL are separate operations
For a forest recovery, restoring an object with Ntdsutil is only a small part of the plan. Microsoft’s workflow performs a nonauthoritative AD DS restore and separately controls which SYSVOL copy becomes authoritative. See Perform a nonauthoritative restore of Active Directory Domain Services for the system-state requirement and recovery options.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
Use the system-state recovery option only in the matching forest procedure
The documented wbadmin command pattern includes:
wbadmin start systemstaterecovery <otheroptions> -authsysvol
The backup must explicitly include system-state data. The -authsysvol option belongs to the forest-recovery sequence and must not be treated as a generic switch for ordinary deleted-object recovery.
Authoritative SYSVOL is restricted to the first recovered writable DC
During forest recovery, Microsoft requires authoritative SYSVOL recovery for the first recovered writable domain controller in the forest-root domain so SYSVOL replication can restart from the selected copy. Do not perform the primary/authoritative SYSVOL restore on other domain controllers. Microsoft states:
Rank #4
“Warning Perform an authoritative (or primary) restore operation of SYSVOL only for the first DC to be restored in the forest root domain. Incorrectly performing primary restore operations of the SYSVOL on other DCs leads to replication conflicts of SYSVOL data.” — Microsoft Learn, AD Forest Recovery – Perform initial recovery
Determine whether the forest uses DFSR or legacy FRS and follow the corresponding Microsoft recovery path. The primary SYSVOL step for the first recovered DC must not be generalized to subsequent DCs.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Best Value
Common failure modes
- Assuming a normal restore is authoritative: a system-state restore changes the recovery DC’s local directory; it does not automatically make those objects win replication.
- Choosing an unnecessarily large subtree: the operation can roll back unrelated attributes and memberships. Use the narrowest DN that satisfies the recovery goal.
- Using a backup without system state: the documented wbadmin system-state procedure will not work with a full-server backup that lacks that component.
- Running primary SYSVOL restore on multiple DCs: in forest recovery, this can create SYSVOL replication conflicts.
- Ignoring replication technology: DFSR and FRS have different recovery instructions; identify the implementation first.
- Copying a command without checking the DN or topology: an incorrect distinguished name, recovery DC role, or cross-domain relationship can produce an incomplete or broader restoration than intended.
Microsoft procedures and command references
- Active Directory Forest Recovery – Procedures
- Restore user accounts and groups in AD
- Perform a nonauthoritative restore of Active Directory Domain Services
- AD Forest Recovery – Perform initial recovery
- Back up the System State data
- Microsoft’s authoritative restore command reference (previous-versions documentation)
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

