Loading
September 30 2026

Cohesity Identity Resilience automates the last mile of AD recovery

See how to get started with new automated provisioning, clean-room drills, and ADFR built within one control plane on the Cohesity Data Cloud.

Identity Resilience

Today we’re bringing two new major enhancements to how organizations use Cohesity Identity Resilience: Active Directory Forest Recovery (ADFR) powered by Semperis is now built directly into the self-managed deployment of Helios, and every recovery is now automated end to end. These enhancements accelerate the “last mile” of AD recovery. Your identity, security, and backup teams can now move with greater efficiency and efficacy for identity resilience.

What’s new in Cohesity Identity Resilience

These new enhancements directly address what needs to happen before a recovery can start. Before these enhancements, setting up and starting a recovery or drill was a largely manual effort: spinning up servers, pulling configurations from S3 buckets, and more. That manual process could delay recovery time or cause teams to skip regular testing altogether. Now, one console automates recovery infrastructure provisioning for both drills and the most complex AD recoveries.

ADFR, built into self-managed Helios. The ADFR UI is now embedded natively inside self-managed Helios (the single-pane-of-glass management platform and control plane for Cohesity Data Cloud). Admins can perform identity recovery in the familiar interface. Access is gated by Cohesity Data Cloud role-based access control, and every configuration change is captured in audit logs. 

Automated recovery infrastructure for recoveries and drills.* Cohesity Data Cloud now orchestrates AD forest recovery processes including:

  • Automated VM provisioning from Windows Server gold templates, built to the technical specification ADFR requires.
  • Automated ADFR server setup and any required agent deployment.
  • Orchestrated data recovery once the environment is ready.
  • Automated DR testing and cyber drills, including new IPs and hostnames separate from production environments.
  • Automated lifecycle management, so clean-room environments tear themselves down when the drill is over.

*To take advantage of this integration, customers will need Cohesity RecoveryAgent or the Enterprise Edition of Cohesity Data Cloud in addition to Cohesity Identity Resilience. 

The new integration in action

Running an AD recovery from inside self-managed Helios. Instead of opening a separate ADFR console mid-incident, operators access ADFR from a dedicated tile in the Identity Resilience section of Helios. Administrators configure their ADFR endpoint once. From there, RBAC governs who can access it, and the workflow stays inside the same interface used for the rest of your recovery operations. With all your identity resilience capabilities in a single view, there's no new console to learn in the middle of an incident and no lost time switching context when speed matters most.

  1. Click on the ADFR app in Helios. Here you can see all ADFR capabilities in the same console you use to recover all your critical workloads.

  2. Register and connect your ADFR management server and point its protection output to the configured backup destination of your choice.

  3. Log in to Cohesity ADFR, powered by Semperis. Access is controlled via role-based access control, so only authorized administrators can access sensitive AD recovery capabilities.

Kicking off a real recovery



Figure 1: Cohesity Identity Resilience automates the workflow for a full Active Directory Forest Recovery from server setup, deploying ADFR agents, and beyond.

  1. When it's time to recover, Cohesity provisions the servers ADFR needs directly from your configured recovery templates. These servers are built to spec automatically, rather than requested and hand-built by your infrastructure team. 


  2. Cohesity then sets up the ADFR server, deploys any required agents, and orchestrates the data recovery itself.


  3. Initiate the AD recovery in the same workflow and UI, then push it to production once the recovery is validated.

Recovery testing 



Figure 2: The same orchestration extends to testing. You can automate the process of testing an AD Forest Recovery, which makes it easier to actually schedule these drills. Regular drills are a critical part of strengthening your overall cyber resilience.

  1. Point the same workflow at a clean-room environment, and Cohesity provisions new IPs and hostnames, so the drill runs in full isolation from production.
  2. Once the drill's lifecycle expires, the environment tears itself down automatically. This means no manual cleanup, no sandbox left running (and exposed) longer than it needs to be, and no potential charges for idle/unused infrastructure.

Proven identity resilience means accounting for every step of recovery

If you're already using Cohesity Identity Resilience for AD protection and recovery, this closes the operational gap between having backups and every step of getting back online, without adding a new console, a new vendor relationship, or a new process to learn from scratch. In fact, it makes the console you already use even easier to use and more powerful in a cyber incident response scenario. 

For organizations evaluating Identity Resilience for the first time, this newly automated and fully integrated experience is a look at what "recoverable" should mean when it comes to your most critical identity workload.

Already running Cohesity Identity Resilience? Learn more about the fully automated recovery and rehearsal workflows in the tech docs. 

Learn more about Cohesity Identity Resilience: 

Written By