Confirmed facts
The Restore‑WBBackupSet (or Restore‑WBItem) cmdlet restores files from a Windows Server Backup but does not perform any automatic integrity check. It requires elevated privileges and access to the backup catalog.
Likely explanation
To guarantee that every recovered file is bit‑for‑bit identical to its pre‑backup state, you must compare cryptographic hashes of the original source and the restored copy. Hash comparison detects any change in file content, while metadata such as timestamps or ACLs can be handled separately.
Steps to automate a comprehensive hash comparison
- Identify the original source path (the location that was backed up).
- Identify the restore destination path used with
‑Destination.
- Run the following PowerShell snippet (requires admin rights):
# Parameters – adjust as needed
$src = 'D:\Data' # original source
$dst = 'E:\Restore' # where Restore‑WBBackupSet wrote the files
# Get all files recursively
$srcFiles = Get-ChildItem -Path $src -File -Recurse
$dstFiles = Get-ChildItem -Path $dst -File -Recurse
# Build hash tables keyed by relative path
$srcHash = @{}
foreach ($f in $srcFiles) {
$rel = $f.FullName.Substring($src.Length).TrimStart('\\')
$srcHash[$rel] = (Get-FileHash -Path $f.FullName -Algorithm SHA256).Hash
}
$dstHash = @{}
foreach ($f in $dstFiles) {
$rel = $f.FullName.Substring($dst.Length).TrimStart('\\')
$dstHash[$rel] = (Get-FileHash -Path $f.FullName -Algorithm SHA256).Hash
}
# Compare
$allKeys = ($srcHash.Keys + $dstHash.Keys) | Sort-Object -Unique
$mismatch = @()
foreach ($k in $allKeys) {
if (-not $srcHash.ContainsKey($k)) { $mismatch += "$k : missing in source" }
elseif (-not $dstHash.ContainsKey($k)) { $mismatch += "$k : missing in destination" }
elseif ($srcHash[$k] -ne $dstHash[$k]) { $mismatch += "$k : hash mismatch" }
}
if ($mismatch.Count -eq 0) {
Write-Host "All files match – integrity verified."
} else {
Write-Warning "Integrity issues found:"
$mismatch | ForEach-Object { Write-Host $_ }
}
- If the script reports no mismatches, the restored data is identical in content to the original.
ACL preservation when restoring to a different volume
The restore operation does not retain NTFS ACLs by default. To preserve them, include the ‑PreserveSecurity switch when calling Restore‑WBItem (or ensure the backup policy was created with security preservation). Example:
Restore‑WBItem -Item $backupItem -Destination $dst -PreserveSecurity -Quiet
If you omitted this switch, you must re‑apply ACLs after the restore using tools like icacls or a PowerShell script that reads a backup of the ACLs (e.g., Get‑ACL exported before backup).
Generating a restoration manifest for audit
A simple manifest can be produced alongside the hash comparison:
# After computing hashes, output a CSV manifest
$manifest = foreach ($rel in $srcHash.Keys) {
[PSCustomObject]@{
RelativePath = $rel
SourceHash = $srcHash[$rel]
DestHash = if ($dstHash.ContainsKey($rel)) { $dstHash[$rel] } else { '' }
Match = if ($srcHash[$rel] -eq $dstHash[$rel]) { 'OK' } else { 'MISMATCH' }
}
}
$manifest | Export-Csv -Path 'C:\Temp\RestoreManifest.csv' -NoTypeInformation
Write-Host "Manifest written to C:\Temp\RestoreManifest.csv"
Missing diagnostic detail
If you need to verify that alternate data streams (ADS) or reparse points are also intact, please confirm whether such streams are present in your data; the hash‑only approach compares only the primary data stream.