SlideShare ist ein Scribd-Unternehmen logo
1 von 3
Downloaden Sie, um offline zu lesen
MS-Windows: Active Directory
Flexible Single Master Operations (FSMO) Roles
First published: 22-Feb-2010
SekChek International Email: inbox@sekchek.com
www.sekchek.com
© 2010-2013 SekChek IPS. All rights reserved.
Purpose of this Document:
Prior to Active Directory, only one domain controller (DC) was allowed to process changes to the
directory database. This master DC was called the Primary Domain Controller (PDC).
Active Directory extends this single-master model to include multiple roles, and the ability to
transfer these roles to any DC in the enterprise.
Active Directory has five of these roles, which are are named Flexible Single Master Operations
(FSMO) roles:
 Domain Naming Master
 Infrastructure Master
 PDC Emulator
 RID Master
 Schema Master
This document explains: the function of each FSMO role; how to determine which DC owns a
particular role; and how to transfer a role to another DC.
Domain Naming Master:
The Domain Naming Master role holder is the DC responsible for making changes to the forest-
wide domain name space of the directory. This DC is the only one that can add or remove a
domain from Active Directory.
The Domain Naming Master role is unique in an enterprise.
Infrastructure Master:
When an object in one domain is referenced by another object in a different domain, Active
Directory represents the reference by the GUID, the SID (for references to security principals), and
the DN of the Active Directory object being referenced.
The Infrastructure Master role holder is the DC responsible for updating an object's SID and
distinguished name in a cross-domain object reference.
The Infrastructure Master role is unique per domain.
PDC Emulator:
The PDC Emulator role holder performs the following functions:
 Synchronisation of time
 Password changes performed by other DCs in the domain are replicated preferentially to
the PDC emulator
 Authentication failures that occur at a given DC in a domain because of an incorrect
password are forwarded to the PDC emulator before a bad password failure message is
reported to the user
 Account lockouts
The PDC Emulator role is unique per domain.
RID Master:
The RID Master is responsible for assigning pools of RIDs to other DCs on the domain. Each DC on
a domain is allowed to create new security principal objects.
The RID Master issues each DC with a pool of RIDs to assign to these newly created objects. Once
the pool falls below a threshold, the DC issues a request to the RID Master for an additional pool of
RIDs.
The RID Master role is unique per domain.
MS-Windows: Active Directory
Flexible Single Master Operations (FSMO) Roles
First published: 22-Feb-2010
SekChek International Email: inbox@sekchek.com
www.sekchek.com
© 2010-2013 SekChek IPS. All rights reserved.
Schema Master:
The Schema Master is responsible for processing updates to the AD schema. Once the Schema
Master updates the AD schema, these changes are replicated to other DCs on the domain.
The Schema Master role is unique in an enterprise.
Checking and transferring the FSMO roles assigned to DCs:
This section illustrates how to check and change the FSMO roles assigned to DCs using Windows’
GUI interface. The screenshots provided are from a Windows 2003 DC.
1. RID Master, PDC Emulator and Infrastructure Master Roles
Use the Active Directory Users and Computers interface to determine
which DCs hold the RID Master, PDC Emulator and Infrastructure
Master roles in a domain.
Click on the domain (e.g. olympus.com), select Operations Masters.
To assign the role to another DC, you must connect to the domain via
that DC.
Right-click on the domain and select Connect to Domain Controller.
Use the Operations Masters interface to pass on the relevant role.
2. Domain Naming Master Role
Use the Active Directory Domains and Trusts interface to determine
which DC in the forest has the Domain Naming Master role.
Click Active Directory Domains and Trusts, select Operations Master.
To assign the role to a different DC, you must connect to the target DC.
Right-click on Active Directory Domains and Trusts and select Connect
to Domain Controller.
3. Schema Master Role
You can use the Schema Master tool to transfer the Schema Master role. Note that the
Schmmgmt.dll dynamic-link library must be registered in order to make the Schema Master
tool available as an MMC snap-in.
Registering the Schema Tool:
1. Go to the Command Prompt: Click Start, select Run.
2. Type regsvr32 schmmgmt.dll, click OK. A message should be displayed stating that the
registration was successful.
Transferring the Schema Master Role:
1. Click Start, click Run, type mmc, click OK
2. Click File -> Add/Remove Snap-in
3. Add Active Directory Schema
4. Right-click Active Directory Schema, select Change Domain
Controller
5. Click Specify Domain Controller, type the name of the
domain controller that will be the new role holder, click OK
6. Right-click Active Directory Schema, select Operation
Master
MS-Windows: Active Directory
Flexible Single Master Operations (FSMO) Roles
First published: 22-Feb-2010
SekChek International Email: inbox@sekchek.com
www.sekchek.com
© 2010-2013 SekChek IPS. All rights reserved.
Glossary of terms used in this document:
FSMO: Flexible Single Master Operations
GUID: Globally Unique Identifier
PDC: Primary Domain Controller
RID: Relative Identifier
SID: Security Identifier
Additional Resources:
Microsoft Knowledge-Base articles:
 Windows 2000 Active Directory FSMO roles. http://support.microsoft.com/kb/197132
 Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller.
http://support.microsoft.com/kb/255504
This paper was written by Sanjay Pather, an Operations
Manager at SekChek Information Protection Services.
Sanjay is responsible for the quality of SekChek reports
and research and testing of security controls on the various
platforms supported by SekChek.

Weitere ähnliche Inhalte

Andere mochten auch

Examen teorico valladolid 1_c_leon_2010
Examen teorico valladolid 1_c_leon_2010Examen teorico valladolid 1_c_leon_2010
Examen teorico valladolid 1_c_leon_2010Miriam Valle
 
Matriz de la problemática pedagógica 2012 simon bolivar
Matriz de la problemática pedagógica  2012  simon bolivarMatriz de la problemática pedagógica  2012  simon bolivar
Matriz de la problemática pedagógica 2012 simon bolivarNilton Centeno
 
14 desde bella vista par sil
14 desde bella vista par sil14 desde bella vista par sil
14 desde bella vista par silrosalinocar
 
Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...
Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...
Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...Alejandro Martinez
 
01 silvicutura corte_secado_imunizacion
01 silvicutura corte_secado_imunizacion01 silvicutura corte_secado_imunizacion
01 silvicutura corte_secado_imunizacioncaeirojoao
 
Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...
Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...
Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...Rocio Martinez
 
Lista de preturi februarie 2014
Lista de preturi   februarie 2014Lista de preturi   februarie 2014
Lista de preturi februarie 2014Spanda Project
 
Presentacion del proyecto "Agua Salá"
Presentacion del proyecto "Agua Salá"Presentacion del proyecto "Agua Salá"
Presentacion del proyecto "Agua Salá"Alejandro Diego Pérez
 
Locais de treinamento das seleções na Copa do Mundo
Locais de treinamento das seleções na Copa do MundoLocais de treinamento das seleções na Copa do Mundo
Locais de treinamento das seleções na Copa do MundoPortal NE10
 
Accelerated partial breast irradiation
Accelerated partial breast irradiationAccelerated partial breast irradiation
Accelerated partial breast irradiationBharti Devnani
 
El treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturals
El treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturalsEl treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturals
El treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturalsMargalida Castells
 
Music & DJ Raport 2016 (05/06)
Music & DJ Raport 2016 (05/06)Music & DJ Raport 2016 (05/06)
Music & DJ Raport 2016 (05/06)Music & DJ Raport
 
[Avanet] Fiesta del Libro y la Cultura Medellín
[Avanet] Fiesta del Libro y la Cultura Medellín[Avanet] Fiesta del Libro y la Cultura Medellín
[Avanet] Fiesta del Libro y la Cultura MedellínSorey García
 

Andere mochten auch (18)

Redes
RedesRedes
Redes
 
Examen teorico valladolid 1_c_leon_2010
Examen teorico valladolid 1_c_leon_2010Examen teorico valladolid 1_c_leon_2010
Examen teorico valladolid 1_c_leon_2010
 
Matriz de la problemática pedagógica 2012 simon bolivar
Matriz de la problemática pedagógica  2012  simon bolivarMatriz de la problemática pedagógica  2012  simon bolivar
Matriz de la problemática pedagógica 2012 simon bolivar
 
14 desde bella vista par sil
14 desde bella vista par sil14 desde bella vista par sil
14 desde bella vista par sil
 
Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...
Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...
Oficios urbanos tradicionales: El lado invisible de la cultura laboral regiom...
 
Ac&m jul11 stat_eng
Ac&m jul11 stat_engAc&m jul11 stat_eng
Ac&m jul11 stat_eng
 
01 silvicutura corte_secado_imunizacion
01 silvicutura corte_secado_imunizacion01 silvicutura corte_secado_imunizacion
01 silvicutura corte_secado_imunizacion
 
para ti posa
para ti posapara ti posa
para ti posa
 
Calendario academico 2011
Calendario academico 2011Calendario academico 2011
Calendario academico 2011
 
Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...
Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...
Trabajo Social: aportaciones al diagnostico social. Autoras:Rocío Martínez y ...
 
Lista de preturi februarie 2014
Lista de preturi   februarie 2014Lista de preturi   februarie 2014
Lista de preturi februarie 2014
 
Convergent Media Group
Convergent Media GroupConvergent Media Group
Convergent Media Group
 
Presentacion del proyecto "Agua Salá"
Presentacion del proyecto "Agua Salá"Presentacion del proyecto "Agua Salá"
Presentacion del proyecto "Agua Salá"
 
Locais de treinamento das seleções na Copa do Mundo
Locais de treinamento das seleções na Copa do MundoLocais de treinamento das seleções na Copa do Mundo
Locais de treinamento das seleções na Copa do Mundo
 
Accelerated partial breast irradiation
Accelerated partial breast irradiationAccelerated partial breast irradiation
Accelerated partial breast irradiation
 
El treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturals
El treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturalsEl treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturals
El treball col·laboratiu en xarxa. Eines 2.0 per a projectes culturals
 
Music & DJ Raport 2016 (05/06)
Music & DJ Raport 2016 (05/06)Music & DJ Raport 2016 (05/06)
Music & DJ Raport 2016 (05/06)
 
[Avanet] Fiesta del Libro y la Cultura Medellín
[Avanet] Fiesta del Libro y la Cultura Medellín[Avanet] Fiesta del Libro y la Cultura Medellín
[Avanet] Fiesta del Libro y la Cultura Medellín
 

Ähnlich wie windows-active-directory-fsmo-roles

Active Directory FSMO Roles in Windows Server
Active Directory FSMO Roles in Windows ServerActive Directory FSMO Roles in Windows Server
Active Directory FSMO Roles in Windows Servermrat hein kyaw
 
Operation Masters
Operation MastersOperation Masters
Operation MastersShilpi Goel
 
Active directory domain administration tools
Active directory domain administration toolsActive directory domain administration tools
Active directory domain administration toolsImran Khan
 
Introduction_of_ADDS
Introduction_of_ADDSIntroduction_of_ADDS
Introduction_of_ADDSHarsh Sethi
 
Case Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdf
Case Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdfCase Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdf
Case Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdfAmansupan
 
Server 2008 r2 ppt
Server 2008 r2 pptServer 2008 r2 ppt
Server 2008 r2 pptRaj Solanki
 
Windows 2008 Active Directory Branch office Management_MVP Sampath Perera
Windows 2008 Active Directory Branch office Management_MVP Sampath PereraWindows 2008 Active Directory Branch office Management_MVP Sampath Perera
Windows 2008 Active Directory Branch office Management_MVP Sampath PereraQuek Lilian
 
Introduction to React JS
Introduction to React JSIntroduction to React JS
Introduction to React JSArno Lordkronos
 
32 Most Commonly Asked Windows Server Administrator Interview Questions (With...
32 Most Commonly Asked Windows Server Administrator Interview Questions (With...32 Most Commonly Asked Windows Server Administrator Interview Questions (With...
32 Most Commonly Asked Windows Server Administrator Interview Questions (With...Temok IT Services
 
Windows Server 2008 (Active Directory Yenilikleri)
Windows Server 2008 (Active Directory Yenilikleri)Windows Server 2008 (Active Directory Yenilikleri)
Windows Server 2008 (Active Directory Yenilikleri)ÇözümPARK
 
IRJET- Research Paper on Active Directory
IRJET-  	  Research Paper on Active DirectoryIRJET-  	  Research Paper on Active Directory
IRJET- Research Paper on Active DirectoryIRJET Journal
 
Active directory installation windows 2003 1
Active directory installation windows 2003 1Active directory installation windows 2003 1
Active directory installation windows 2003 1tameemyousaf
 
Rodc features
Rodc featuresRodc features
Rodc featurespothurajr
 

Ähnlich wie windows-active-directory-fsmo-roles (20)

Active Directory FSMO Roles in Windows Server
Active Directory FSMO Roles in Windows ServerActive Directory FSMO Roles in Windows Server
Active Directory FSMO Roles in Windows Server
 
Operation Masters
Operation MastersOperation Masters
Operation Masters
 
Active directory domain administration tools
Active directory domain administration toolsActive directory domain administration tools
Active directory domain administration tools
 
Windows server Interview question and answers
Windows server Interview question and answersWindows server Interview question and answers
Windows server Interview question and answers
 
Introduction_of_ADDS
Introduction_of_ADDSIntroduction_of_ADDS
Introduction_of_ADDS
 
70 640 Lesson04 Ppt 041009
70 640 Lesson04 Ppt 04100970 640 Lesson04 Ppt 041009
70 640 Lesson04 Ppt 041009
 
Case Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdf
Case Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdfCase Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdf
Case Project 12-2 Devising an AD DS Design with RODC, AD RMS, and A.pdf
 
70 640 Lesson02 Ppt 041009
70 640 Lesson02 Ppt 04100970 640 Lesson02 Ppt 041009
70 640 Lesson02 Ppt 041009
 
Server 2008 r2 ppt
Server 2008 r2 pptServer 2008 r2 ppt
Server 2008 r2 ppt
 
Windows 2008 Active Directory Branch office Management_MVP Sampath Perera
Windows 2008 Active Directory Branch office Management_MVP Sampath PereraWindows 2008 Active Directory Branch office Management_MVP Sampath Perera
Windows 2008 Active Directory Branch office Management_MVP Sampath Perera
 
Introduction to React JS
Introduction to React JSIntroduction to React JS
Introduction to React JS
 
32 Most Commonly Asked Windows Server Administrator Interview Questions (With...
32 Most Commonly Asked Windows Server Administrator Interview Questions (With...32 Most Commonly Asked Windows Server Administrator Interview Questions (With...
32 Most Commonly Asked Windows Server Administrator Interview Questions (With...
 
MCITP
MCITPMCITP
MCITP
 
Ad ds rodc
Ad ds rodcAd ds rodc
Ad ds rodc
 
FSMO
FSMO FSMO
FSMO
 
Windows Server 2008 (Active Directory Yenilikleri)
Windows Server 2008 (Active Directory Yenilikleri)Windows Server 2008 (Active Directory Yenilikleri)
Windows Server 2008 (Active Directory Yenilikleri)
 
IRJET- Research Paper on Active Directory
IRJET-  	  Research Paper on Active DirectoryIRJET-  	  Research Paper on Active Directory
IRJET- Research Paper on Active Directory
 
Active Directory
Active DirectoryActive Directory
Active Directory
 
Active directory installation windows 2003 1
Active directory installation windows 2003 1Active directory installation windows 2003 1
Active directory installation windows 2003 1
 
Rodc features
Rodc featuresRodc features
Rodc features
 

windows-active-directory-fsmo-roles

  • 1. MS-Windows: Active Directory Flexible Single Master Operations (FSMO) Roles First published: 22-Feb-2010 SekChek International Email: inbox@sekchek.com www.sekchek.com © 2010-2013 SekChek IPS. All rights reserved. Purpose of this Document: Prior to Active Directory, only one domain controller (DC) was allowed to process changes to the directory database. This master DC was called the Primary Domain Controller (PDC). Active Directory extends this single-master model to include multiple roles, and the ability to transfer these roles to any DC in the enterprise. Active Directory has five of these roles, which are are named Flexible Single Master Operations (FSMO) roles:  Domain Naming Master  Infrastructure Master  PDC Emulator  RID Master  Schema Master This document explains: the function of each FSMO role; how to determine which DC owns a particular role; and how to transfer a role to another DC. Domain Naming Master: The Domain Naming Master role holder is the DC responsible for making changes to the forest- wide domain name space of the directory. This DC is the only one that can add or remove a domain from Active Directory. The Domain Naming Master role is unique in an enterprise. Infrastructure Master: When an object in one domain is referenced by another object in a different domain, Active Directory represents the reference by the GUID, the SID (for references to security principals), and the DN of the Active Directory object being referenced. The Infrastructure Master role holder is the DC responsible for updating an object's SID and distinguished name in a cross-domain object reference. The Infrastructure Master role is unique per domain. PDC Emulator: The PDC Emulator role holder performs the following functions:  Synchronisation of time  Password changes performed by other DCs in the domain are replicated preferentially to the PDC emulator  Authentication failures that occur at a given DC in a domain because of an incorrect password are forwarded to the PDC emulator before a bad password failure message is reported to the user  Account lockouts The PDC Emulator role is unique per domain. RID Master: The RID Master is responsible for assigning pools of RIDs to other DCs on the domain. Each DC on a domain is allowed to create new security principal objects. The RID Master issues each DC with a pool of RIDs to assign to these newly created objects. Once the pool falls below a threshold, the DC issues a request to the RID Master for an additional pool of RIDs. The RID Master role is unique per domain.
  • 2. MS-Windows: Active Directory Flexible Single Master Operations (FSMO) Roles First published: 22-Feb-2010 SekChek International Email: inbox@sekchek.com www.sekchek.com © 2010-2013 SekChek IPS. All rights reserved. Schema Master: The Schema Master is responsible for processing updates to the AD schema. Once the Schema Master updates the AD schema, these changes are replicated to other DCs on the domain. The Schema Master role is unique in an enterprise. Checking and transferring the FSMO roles assigned to DCs: This section illustrates how to check and change the FSMO roles assigned to DCs using Windows’ GUI interface. The screenshots provided are from a Windows 2003 DC. 1. RID Master, PDC Emulator and Infrastructure Master Roles Use the Active Directory Users and Computers interface to determine which DCs hold the RID Master, PDC Emulator and Infrastructure Master roles in a domain. Click on the domain (e.g. olympus.com), select Operations Masters. To assign the role to another DC, you must connect to the domain via that DC. Right-click on the domain and select Connect to Domain Controller. Use the Operations Masters interface to pass on the relevant role. 2. Domain Naming Master Role Use the Active Directory Domains and Trusts interface to determine which DC in the forest has the Domain Naming Master role. Click Active Directory Domains and Trusts, select Operations Master. To assign the role to a different DC, you must connect to the target DC. Right-click on Active Directory Domains and Trusts and select Connect to Domain Controller. 3. Schema Master Role You can use the Schema Master tool to transfer the Schema Master role. Note that the Schmmgmt.dll dynamic-link library must be registered in order to make the Schema Master tool available as an MMC snap-in. Registering the Schema Tool: 1. Go to the Command Prompt: Click Start, select Run. 2. Type regsvr32 schmmgmt.dll, click OK. A message should be displayed stating that the registration was successful. Transferring the Schema Master Role: 1. Click Start, click Run, type mmc, click OK 2. Click File -> Add/Remove Snap-in 3. Add Active Directory Schema 4. Right-click Active Directory Schema, select Change Domain Controller 5. Click Specify Domain Controller, type the name of the domain controller that will be the new role holder, click OK 6. Right-click Active Directory Schema, select Operation Master
  • 3. MS-Windows: Active Directory Flexible Single Master Operations (FSMO) Roles First published: 22-Feb-2010 SekChek International Email: inbox@sekchek.com www.sekchek.com © 2010-2013 SekChek IPS. All rights reserved. Glossary of terms used in this document: FSMO: Flexible Single Master Operations GUID: Globally Unique Identifier PDC: Primary Domain Controller RID: Relative Identifier SID: Security Identifier Additional Resources: Microsoft Knowledge-Base articles:  Windows 2000 Active Directory FSMO roles. http://support.microsoft.com/kb/197132  Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller. http://support.microsoft.com/kb/255504 This paper was written by Sanjay Pather, an Operations Manager at SekChek Information Protection Services. Sanjay is responsible for the quality of SekChek reports and research and testing of security controls on the various platforms supported by SekChek.