Backups Don't Matter Test your readiness

Identity-first recovery and sequencing

Why do you restore Active Directory or Entra first after an attack?

Identity is the dependency underneath every other dependency.

Identity is the dependency under every dependency

Active Directory, Entra ID and DNS sit beneath almost everything else. User logins, service-to-service trust, Kerberos tickets, group policy, certificate validation and name resolution all rely on them. When identity is down, an application server can be perfectly restored and still be useless, because no one and nothing can authenticate to it.

What happens if you restore apps first

  • Applications come up but reject every login, so the business still cannot operate.
  • Service accounts fail, integrations break, and you burn hours chasing symptoms that all trace back to missing identity.
  • You may wire freshly restored systems to a directory that is still compromised, handing the attacker control of the environment you just rebuilt.

Why identity is also the hardest to restore dirty

Directories are a primary target. Attackers plant persistence in Active Directory through techniques that forge tickets, add hidden administrators, or manipulate replication. If you restore a compromised directory, you restore the attacker with it. That is why identity is not just first in order, it is the piece that most needs to come from a known-clean point and be handled with care.

The identity-first sequence

  1. Recover a clean identity foundationRestore Active Directory or reestablish Entra from a known-clean point, using authoritative or forest-level recovery where the whole directory is suspect.
  2. Restore DNS and core network servicesName resolution and core services come up alongside identity, because the rest of recovery depends on them too.
  3. Rotate and review credentialsReset privileged credentials, rotate the Kerberos KRBTGT secret twice, and review privileged accounts and trusts for anything the attacker added.
  4. Then bring back dependencies and appsWith clean identity in place, restore shared services and applications in the order the business needs.

Common mistakes

  • Treating a domain controller like any other server and skipping the special handling a directory needs.
  • Restoring a single domain controller without considering forest-level recovery when the directory itself is compromised.
  • Forgetting to rotate KRBTGT, which can leave forged tickets valid after recovery.
  • Bringing back DNS late, so everything else stalls waiting on name resolution.

How KELYN makes this operational

KELYN sequences identity first in every recovery plan it builds on Commvault, restoring a clean directory and DNS before the applications that depend on them, and rehearsing that sequence in an isolated environment so it holds up under pressure. Identity-first is not a preference, it is the order the technology requires.

Sources

Your next backup will run

Will your business come back?

You can prove it in two minutes. Test your recovery readiness and see where the gaps are before an attacker does.