Monday 21 March 2011

FSMO Roles in Active Director


The Five FSMO Roles

  • Schema Master - A domain controller (DC) with this FSMO role controls all schema updates and modifications. There can only be one Schema Master in a forest. To update the schema of a forest, you must have access to the Schema Master domain controller.
  • Domain Naming Master - Controls the addition or removal of domains in the forest. This DC can also add or remove any cross-references to domains in external (Lightweight Directory Access Protocol) LDAP directories. there can only be one Domain Naming Master in a forest.
  • Infrastructure Master - Responsible for updating references from objects in the lodlcal domain to objects in other domains. There is one Infrastructure Master DC per domain.
  • Relative ID (RID) Master - Processes RID pool requests from all DCs in the local domain. These pool requests are a sequence of unique RID values. These RID values are the unique part of the Security Identifier (SID). There is one RID Master DC per domain.
  • PDC Emulator - Advertises itself as the PDC to workstations, member servers, and BDCs running Windows NT. Other jobs of this role include acting as the Domain Master Browser, handling Active Directory password changes, maintenance of trust relationships, and synchronizing time for servers and clients within a domain. There is one PDC Emulator per domain.

No comments:

Post a Comment