What are the FSMO roles? Who has them by default? What
happens when each one fails?



What are the FSMO roles? Who has them by default? What happens when each one fails?..

Answer / dror bijo

FSMO stands for the Flexible single Master Operation
It has 5 Roles: -


Schema Master:

The schema master domain controller controls all updates
and modifications to the schema. Once the Schema update is
complete, it is replicated from the schema master to all
other DCs in the directory. To update the schema of a
forest, you must have access to the schema master. There
can be only one schema master in the whole forest.

Domain naming master:

The domain naming master domain controller controls the
addition or removal of domains in the forest. This DC is
the only one that can add or remove a domain from the
directory. It can also add or remove cross references to
domains in external directories. There can be only one
domain naming master in the whole forest.

Infrastructure Master:

When an object in one domain is referenced by another
object in another domain, it represents the reference by
the GUID, the SID (for references to security principals),
and the DN of the object being referenced. The
infrastructure FSMO role holder is the DC responsible for
updating an object's SID and distinguished name in a cross-
domain object reference. At any one time, there can be only
one domain controller acting as the infrastructure master
in each domain.

Note: The Infrastructure Master (IM) role should be held by
a domain controller that is not a Global Catalog server
(GC). If the Infrastructure Master runs on a Global Catalog
server it will stop updating object information because it
does not contain any references to objects that it does not
hold. This is because a Global Catalog server holds a
partial replica of every object in the forest. As a result,
cross-domain object references in that domain will not be
updated and a warning to that effect will be logged on that
DC's event log. If all the domain controllers in a domain
also host the global catalog, all the domain controllers
have the current data, and it is not important which domain
controller holds the infrastructure master role.

Relative ID (RID) Master:

The RID master is responsible for processing RID pool
requests from all domain controllers in a particular
domain. When a DC creates a security principal object such
as a user or group, it attaches a unique Security ID (SID)
to the object. This SID consists of a domain SID (the same
for all SIDs created in a domain), and a relative ID (RID)
that is unique for each security principal SID created in a
domain. Each DC in a domain is allocated a pool of RIDs
that it is allowed to assign to the security principals it
creates. When a DC's allocated RID pool falls below a
threshold, that DC issues a request for additional RIDs to
the domain's RID master. The domain RID master responds to
the request by retrieving RIDs from the domain's
unallocated RID pool and assigns them to the pool of the
requesting DC. At any one time, there can be only one
domain controller acting as the RID master in the domain.

PDC Emulator:

The PDC emulator is necessary to synchronize time in an
enterprise. Windows 2000/2003 includes the W32Time (Windows
Time) time service that is required by the Kerberos
authentication protocol. All Windows 2000/2003-based
computers within an enterprise use a common time. The
purpose of the time service is to ensure that the Windows
Time service uses a hierarchical relationship that controls
authority and does not permit loops to ensure appropriate
common time usage.

The PDC emulator of a domain is authoritative for the
domain. The PDC emulator at the root of the forest becomes
authoritative for the enterprise, and should be configured
to gather the time from an external source. All PDC FSMO
role holders follow the hierarchy of domains in the
selection of their in-bound time partner.
:: In a Windows 2000/2003 domain, the PDC emulator role
holder retains the following functions:
:: Password changes performed by other DCs in the domain
are replicated preferentially to the PDC emulator.
Authentication failures that occur at a given DC in a
domain because of an incorrect password are forwarded to
the PDC emulator before a bad password failure message is
reported to the user.
Account lockout is processed on the PDC emulator.
Editing or creation of Group Policy Objects (GPO) is always
done from the GPO copy found in the PDC Emulator's SYSVOL
share, unless configured not to do so by the administrator.
The PDC emulator performs all of the functionality that a
Microsoft Windows NT 4.0 Server-based PDC or earlier PDC
performs for Windows NT 4.0-based or earlier clients.
This part of the PDC emulator role becomes unnecessary when
all workstations, member servers, and domain controllers
that are running Windows NT 4.0 or earlier are all upgraded
to Windows 2000/2003. The PDC emulator still performs the
other functions as described in a Windows 2000/2003
environment.

Is This Answer Correct ?    5 Yes 1 No

Post New Answer

More Microsoft Certifications Interview Questions

How I Should get Microsoft Certification

1 Answers  


How many HDD we can connect to one system

8 Answers   Team Lease,


What is Server OS? What is Domain Controler?

2 Answers  


what is the process to check server health

2 Answers  


What do you do to install a new Windows 2003 DC in a Windows 2000 AD?

1 Answers  






Name some OU design considerations.

3 Answers  


What is WINS server? where we use WINS server? difference between DNS and WINS?

4 Answers   ADP, Wipro,


Name three booting files?

8 Answers   HS, Wipro,


Hi, I am gayathri.Could anyone of u who see this question plz answer and help me in this regard.I want to do .NET certification...I want to know the centres which offers this certification.

3 Answers  


hi friends...is thr anybd who can tel me how to c logs of internet useage of each system...and hoe to delete those logs and from wer???

1 Answers  


question related to education gap and studies i would be very thankful if u guide in creating my career.i did my degree(bachelor of computer applications)from 1999 to 2002 but passed in 2007. am unemployed till now without further qulaification. how to rebuild my career. what is the option for me to do the job. how do u guide me to build my career again so that i can gt a job. which field to select. let me please know step my step process thanks...

1 Answers  


What are administrative templates?

2 Answers  


Categories
  • Cisco Certifications Interview Questions Cisco Certifications (2321)
  • Microsoft Certifications Interview Questions Microsoft Certifications (171)
  • Sun Certifications Interview Questions Sun Certifications (45)
  • CISA Certification Interview Questions CISA Certification (744)
  • Oracle Certifications Interview Questions Oracle Certifications (64)
  • ISTQB Certification Interview Questions ISTQB Certification (109)
  • Certifications AllOther Interview Questions Certifications AllOther (295)