What is our primary use case?
Quest Identity Recovery is primarily used for active roles migration and recovery management for Active Directory. I have used Quest Identity Recovery following the accidental deletion of critical AD objects to identify who performed the deletion, what objects were deleted, when it was deleted, and to find a valid backup containing all those objects. Quest Identity Recovery was then used to restore the objects with their attributes, memberships, and permissions.
Quest Identity Recovery also handles SID and security considerations by validating the SID of the object, verifying group memberships and access control permissions, and checking that the application reliance on AD groups continues to function.
What is most valuable?
Quest Identity Recovery offers several best features including AD object and attribute recovery, domain controller recovery, recovery of deleted users, groups, computers, and OUs, authoritative and non-authoritative AD recovery, Recycle Bin integration, Forest recovery scenarios, backup validation and health checks, recovery of group policy objects, comparison of AD objects before and after recovery, and integration with Quest Change Auditor for audit purposes.
I rely most on the restore of objects and integration with Change Auditor for audit purposes. The comparison and recovery capability of Quest Identity Recovery compares the missing object, changes attributes, group membership, object permission, and differences between the backup and the production, which significantly helps in restoring.
Quest Identity Recovery has positively impacted my organization as it is one of the most reliable tools, providing confidence that any human error can be recovered. It has definitely helped in reducing downtime through instances where human errors resulted in objects being deleted. The tool quickly detects these incidents when integrated with Change Auditor and avoids downtime by enabling rapid restoration upon notification. It uses granular recovery and prioritizes critical identities such as restoring service accounts, service groups, administrators, and business-critical users first. It also avoids unnecessary DC rebuilds, allowing recovery of AD objects from existing backups rather than performing lengthy domain controller rebuilds. It validates replication immediately and allows automation for certain objects, reducing time and adding business value.
What needs improvement?
Quest Identity Recovery could be improved with better automation, faster recovery, and reduced storage usage to lower infrastructure costs and investments.
Quest Identity Recovery's AI capabilities still need improvement regarding governance and security. It should recommend a specific recovery point, automatically identify which objects were affected by an incident, predict dependencies between users, groups, GPOs, application service accounts, and generate a recovery plan before execution.
Regarding the accuracy and reliability of output from Quest Identity Recovery's AI capabilities, it provides some overview of the capabilities, but there is still room for improvement with better planning before execution.
What other advice do I have?
A situation that would prompt the use of Quest Identity Recovery for cloud-only Entra ID objects is the accidental deletion of cloud-only users, groups, and other identity objects, administrative errors, or an identity management incident where the object does not have an on-premises source of authority. The key difference observed is that with Entra Connect synchronization, the on-premises Active Directory object is normally the source of authority. If a synchronized user is deleted in Entra ID, recovery can often be performed by restoring the on-premises AD object and allowing synchronization to recreate or restore the cloud representation depending on the scenarios and object state.
My advice to others looking into using Quest Identity Recovery is to first identify the most critical identity recovery scenarios before implementing Quest Identity Recovery. Do not view it simply as a backup product, but as a part of an identity disaster recovery strategy. I have been using Quest products for almost ten years and would rate this product an eight out of ten.
Which deployment model are you using for this solution?
On-premises