Active Directory recovery is not ordinary server restore
Restoring a directory after a serious compromise is a specialised operation, not a server restore.
Restoring backups that already contain the attacker's changes reinstates the compromise. Doing it in the wrong order can reintroduce trust relationships you were trying to remove. Organisations that assume their normal backup process covers this discover during the incident that it does not, and the recovery takes weeks rather than days.
More on Windows and Active Directory
- Domain Admin is a forest-scale keyOne root under the whole forest
- Kerberos tickets are credentialsWhoever holds it, gets in
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
