Commvault has introduced Active Directory Pre Recover, a new cyber-recovery feature that keeps a ready copy of Microsoft Active Directory (AD) inside an isolated environment so it can be used when the production identity service becomes compromised or unreachable. The company says this approach can cut the time needed to restore trustworthy authentication services from hours to minutes, although the technology isn’t generally available yet: it will enter early access over the coming months.
Active Directory Pre Recover: the key points in 20 seconds
- Commvault keeps a clean copy of Active Directory inside its isolated Cleanroom environment.
- That copy can be used temporarily if the production AD becomes compromised or unreachable.
- Threat Scan analyzes the backups used to reduce the risk of restoring malicious content.
- It doesn’t replace the full Active Directory forest recovery process.
- It will arrive in early access over the coming months.
Active Directory remains one of the most delicate pieces of many enterprise infrastructures. An application server going down can take out one specific application. Losing the identity service can simultaneously block access to servers, applications, workstations, and various corporate resources.
The problem gets more complicated during a ransomware attack, because restoring Active Directory quickly isn’t the only goal. You need to recover a state that can be considered sufficiently trustworthy.
If you restore a copy that already contained changes made by the attacker, compromised accounts, persistence mechanisms, or tampered configurations, the organization can reintroduce part of the problem during its own recovery.
That’s why Commvault wants to separate two processes that are normally closely linked: quickly restoring identity services and completing the definitive restoration of Active Directory.
An Active Directory that’s ready before the incident happens
The idea behind Active Directory Pre Recover is to pre-create a clean, standby copy of Active Directory inside Commvault Cleanroom.
Cleanroom is the isolated environment Commvault uses for recovery and testing after incidents. It allows systems to be rebuilt in a space separate from the production infrastructure so they can be analyzed before being returned to the enterprise environment.
The new feature uses that infrastructure to keep AD on standby.
When the production identity service becomes unusable, the organization can temporarily switch over to that copy instead of waiting to immediately complete a full forest recovery.
The process Commvault proposes can be understood like this:
| Situation | Traditional recovery | Active Directory Pre Recover |
|---|---|---|
| Production AD compromised | Start recovery | Activate standby AD |
| Initial identity recovery | Depends on the restore | Target: minutes |
| Recovery environment | Rebuilt infrastructure | Isolated Cleanroom |
| Backup validation | Needed during recovery | Threat Scan already built in |
| Apps that depend on AD | Wait for availability | Can authenticate again sooner |
| Full forest recovery | Required | Still required |
That last difference is especially important.
Active Directory Pre Recover doesn’t remove the need to properly recover the original forest. What it offers is a provisional, trustworthy identity service while that process is underway.
Commvault talks about going from hours to minutes and near-real-time availability. These are the company’s targets and estimates, not guaranteed times for every infrastructure. The result will depend on the size and complexity of the directory, existing dependencies, and the incident itself.
Threat Scan tries to keep malware from coming back with the backup
Keeping a ready copy is only useful if that copy doesn’t reproduce the compromise that forced the recovery in the first place.
For this, Commvault uses Threat Scan, a technology already available within its platform that analyzes backup data for signs of malicious content.
The company notes that Active Directory Pre Recover will continuously run Threat Scan on the AD backups used to prepare the standby environment.
The goal is to reduce one of the classic risks of any post-ransomware recovery: restoring from a point that appears intact but already contains elements introduced during the intrusion.
That’s not the same as proving a copy is completely free of any compromise. No scan can, by itself, guarantee that a backup represents a perfect state. It does add one more check before turning that copy into the basis for recovery.
The process is thus split into several layers:
Backup: preserves earlier states of Active Directory.
Threat Scan: analyzes those backups for potentially malicious content.
Cleanroom: provides the isolated environment for preparing and running the recovery.
Pre Recover: keeps a ready AD instance available to temporarily take over authentication.
The approach also changes when part of the work gets done.
In a conventional recovery, much of the work only starts after the incident occurs. With a pre-prepared environment, some tasks can be run and checked before the infrastructure is actually needed.
It’s the same philosophy used in other areas of business continuity: the fastest recovery is usually the one that already has part of the work done before the outage.
Why recovering Active Directory isn’t like restoring a server
Active Directory has characteristics that make its recovery especially complicated.
It’s not simply a database that can be copied onto a new server. An enterprise environment may have a forest with multiple domains, numerous domain controllers, trust relationships, integrated DNS, group policies, Flexible Single Master Operations (FSMO) roles, service accounts, and applications that depend directly on LDAP or Kerberos.
What’s more, many modern attacks specifically target identity.
Once an attacker gains sufficient privileges over Active Directory, they can create users, modify groups, change policies, or set up various persistence mechanisms. That’s why Microsoft maintains specific forest recovery procedures for scenarios where the entire directory can no longer be trusted.
Recovery may require rebuilding domain controllers in a specific order and restoring essential services before bringing the rest of the infrastructure back in.
While that’s happening, a practical problem shows up: many applications need Active Directory to work.
A server can be intact, and an application can still have all its data, but if its users can’t authenticate, the service remains down from an operational standpoint.
Pre Recover tries to shrink precisely that gap.
Commvault says applications will be able to keep authenticating against trustworthy identity services without having to wait for the full forest recovery to finish, or maintain complex parallel synchronization mechanisms with another identity management system.
Identity is firmly entering cyber-recovery plans
The announcement reflects a shift that’s also happening beyond Commvault. Ransomware recovery strategies can no longer focus solely on keeping immutable copies of files, databases, and virtual machines — a point Commvault has also been building on through its integration with CrowdStrike, connecting the SIEM with the actual state of backups.
The infrastructure needed to actually use that data also needs to be recovered.
For a systems team, a complete recovery strategy should account for at least these different layers:
| Layer | Elements that need recovery |
|---|---|
| Identity | AD, DNS, accounts, authentication |
| Infrastructure | Hypervisors, cloud, networking, storage |
| Data | Databases, files, backups |
| Applications | ERP, email, internal services |
| Security | EDR, SIEM, certificates, controls |
| Administration | Privileged accounts and operational tools |
Order matters.
Restoring hundreds of servers before recovering the identity infrastructure they depend on can produce an environment that’s technically up but hard to actually use.
That also explains why Active Directory remains an attractive target for attackers. Compromising identity provides a way to escalate privileges and move through the organization, while destroying it or encrypting related systems can significantly complicate recovery.
Commvault is trying to build that dependency into its resilience platform, rather than treating AD as just another data set that needs to be included in the backup.
There are, however, aspects organizations will need to check once early access begins. The company hasn’t detailed, in its public announcement, all the technical conditions for switching over to the standby copy, which topologies are supported, or how every application and Active Directory dependency will behave during that provisional period.
Having a working directory available also shouldn’t be confused with having finished the incident response. After a serious compromise, it will still be necessary to investigate the source, determine which credentials were exposed, rotate secrets where appropriate, remove persistence mechanisms, and rebuild any infrastructure that can no longer be considered trustworthy.
Active Directory Pre Recover will join the Commvault Identity Resilience portfolio. The company plans to open early access over the coming months and says enterprise Active Directory customers will receive it under their existing license, including a reduced version of Cleanroom.
It will be available globally through Commvault’s partner network.
The proposal introduces an especially interesting idea for those in charge of systems and continuity: Active Directory’s recovery clock doesn’t have to start ticking when the attack happens. Keeping an isolated, ready copy in advance can get part of the work done ahead of time, while the definitive recovery of the forest continues to follow the procedures needed to bring the infrastructure back to a trustworthy state.

