How to manually back up and restore the ADSelfService Plus database in the same application instance

Last updated on:

Objective

This article provides detailed step-by-step instructions on how to manually back up and restore the ADSelfService Plus database within the same application instance. The ADSelfService Plus database stores all user self-service configurations, enrollment records, MFA policy assignments, and audit data. Losing this data can disrupt password reset workflows, MFA enrollment, and access management across your Active Directory environment.

This process is essential for:

  • Creating secure copies of the ADSelfService Plus database for disaster recovery.
  • Restoring data after accidental deletion or corruption.
  • Maintaining periodic backups for compliance purposes.

Backup frequency recommendation: Perform a manual backup before major configuration changes or product upgrades. Treat this backup as a required component of your broader disaster recovery plan—document the restore procedure, store backup files off the production server, and keep the backup password secured separately from the backup file itself.

Prerequisite

  • Have administrator privileges on the ADSelfService Plus server.
  • Before restoring the database, you must stop the ManageEngine ADSelfService Plus service. Failure to do so can result in a corrupted database.

Steps to back up and restore the database

Part 1: Back up the database

Follow these steps to create a manual backup of your application's database.

  1. On the server hosting ADSelfService Plus, open Command Prompt as an administrator.
  2. Navigate to the \bin directory within the ADSelfService Plus installation folder using the cd command. The default path is:
    C:\Program Files\ManageEngine\ADSelfService Plus\bin
  3. Execute the backup script:
    backupDB.bat
  4. The script will run and create a Backup folder inside the main installation directory (e.g., C:\Program Files\ManageEngine\ADSelfService Plus\Backup). Inside this folder, you will find the database backup stored as a compressed .ezip file (e.g., OfflineBackup_20250813160300.ezip).

Do not leave the backup file only on the production server. If the server becomes unavailable, a backup stored locally on that server cannot be accessed during recovery. As soon as the backup completes, copy the .ezip file to at least one secondary location, such as:

  • A network share or mapped drive on a separate machine
  • An external drive stored off-site
  • A cloud storage location (e.g., SharePoint, OneDrive, or an S3-compatible bucket)

Store the backup password in a secure location—such as a password manager or your documented disaster recovery plan—independently of the server, so it remains accessible even if the server is down.

Part 2: Manually restore the database

Follow these steps to restore the database from a previously created backup file.

Note:

This action will overwrite your current database with the data from the backup file.

  1. Stop the ManageEngine ADSelfService Plus service via the services.msc console.
  2. Open Command Prompt as an administrator.
  3. Navigate to the \bin directory using the cd command. The default path is:
    C:\Program Files\ManageEngine\ADSelfService Plus\bin
  4. Execute the restoreDB.bat script using the following command format. You must provide the full path to the backup file.
    restoreDB.bat "C:\Program Files\ManageEngine\ADSelfServicePlus\Backup\your_backup_filename.ezip" -p <password>

    Example:

    restoreDB.bat "C:\Program Files\ManageEngine\ADSelfServicePlus\Backup\OfflineBackup_20250813160300.ezip" -p <YourBackupPassword>
    The password required for the restore command (-p <password>) depends on how your environment was configured when the backup was created:
    • Default password: If no custom password was set, the password is the reverse string of the backup filename excluding the .ezip extension. For a file named OfflineBackup_20250813160300, the password would be 00306131805202_pukcaBenilffO.
    • Admin-configured password: If a password was configured in the admin portal, use that password. This setting is located under Admin > Product Settings > Security and Privacy > Privacy Settings in the Encrypt database backup files field.
    • Forgotten password: If you have forgotten the admin-configured password, it can be found in the customer-config.xml file located in the <Installation_Dir>\conf folder. Contact the ADSelfService Plus support team to decrypt the file and retrieve the password. Without the password or access to this file, the backup cannot be restored.
  5. Once the restoration is complete, start the ManageEngine ADSelfService Plus service, then work through the following verification checklist to confirm the restore was successful:
    • Log in to the ADSelfService Plus portal with an administrator account and confirm access is normal.
    • Navigate to Configuration > Self-Service > Policy Configuration and confirm that enrollment policies and domain configurations are intact.
    • Go to Reports > Audit and confirm that historical audit records are present up to the date of the backup.
    • Test the end-user self-service workflow: Attempt a password reset or account unlock from the self-service portal to confirm the service is functioning correctly.
    • Confirm that MFA configurations—enrolled methods and policy assignments—are intact for at least one test user account.
  6. If any data appears missing or configurations do not match the expected state, do not make further changes. Contact the ADSelfService Plus support team with the restore log for assistance.

Troubleshooting common issues

Issue: The restore command fails immediately

Solution: Ensure the ADSelfService Plus service is fully stopped before running restoreDB.bat. Running the restore while the service is active will cause the command to fail and may leave the database in an inconsistent state.

Issue: Incorrect password error during restore

Solution: Check whether a custom backup password was configured under Admin > Product Settings > Security and Privacy > Privacy Settings. If you are unsure which password was used, refer to the customer-config.xml file in the \conf folder, or contact support to decrypt it.

Issue: The .ezip file cannot be found

Solution: If you moved the backup file from the default Backup folder, provide the full path to its current location in the restoreDB.bat command. Ensure there are no typos in the path and that the file has not been renamed or moved again since the path was noted.

Issue: Data appears incomplete after restore

Solution: The restore recovers data only up to the point when the backup was taken. Any configurations or enrollment changes made after that backup will not be present. If a more recent backup exists, restore from that file instead.

Frequently asked questions

How often should I back up the ADSelfService Plus database?

At a minimum, perform a backup once per day. In environments with frequent configuration changes or active user enrollment, back up before and after any significant change. Treat the backup as a required step in your change management and disaster recovery process.

Can I automate the ADSelfService Plus database backup?

Yes. The backupDB.bat script can be scheduled using Windows Task Scheduler to run automatically at a defined interval. Create a scheduled task that runs the script as an administrator on a daily or more frequent schedule to eliminate dependence on manual execution.

Where should I store the backup file?

Do not rely solely on the default local Backup folder on the production server. Copy the .ezip file to a secondary location—such as a network share, external drive, or cloud storage—immediately after each backup completes. If the server becomes unavailable, a backup stored only on that server will be inaccessible during recovery.

What does the ADSelfService Plus database backup contain?

The backup captures all data within ADSelfService Plus's internal database: user self-service configurations, enrollment records, MFA policy assignments, audit logs, and product settings. It does not back up the Windows Server operating system, Active Directory, SYSVOL, or any other system components—those require separate backup procedures such as a system state backup.

What if I forget the backup password?

The password can be found in the customer-config.xml file in the \conf folder, though it is stored in encrypted form. Contact ADSelfService Plus support to decrypt and retrieve it. To prevent this situation, document the backup password in a secure location independently of the ADSelfService Plus server.

How is this different from a Windows Server or Active Directory backup?

This procedure backs up only the ADSelfService Plus application database. It does not back up Active Directory, SYSVOL, the Windows registry, or other system state components. A system state backup or Windows Server Backup captures those elements separately. Both types serve different purposes and should both be part of your organization's overall disaster recovery plan.