It's so simple to back up VMs in KCB, but what if the VM is a domain controller?  I already have KCB installed on the Hyper-V host backing up all guest VMs.  But in the case that there are multiple DCs should I instead install KCB on the VM directly and run an entire machine backup with Active Directory application-aware enabled?  To avoid the USN rollback as mentioned below?  I'm thinking that the answer is "yes", but wanted some feedback before I make any changes.

Per the Acronis documentation:

Protecting a domain controller

A machine running Active Directory Domain Services can be protected by application-aware backup. If a domain contains more than one domain controller, and you recover one of them, a nonauthoritative restore is performed and a USN rollback will not occur after the recovery.