answersLogoWhite

0


Best Answer

FSMO Role Loss implications

Schema The schema cannot be extended. However, in the short term no one will notice a missing Schema Master unless you plan a schema upgrade during that time.

Domain Naming Unless you are going to run DCPROMO, then you will not miss this FSMO role.

RID Chances are good that the existing DCs will have enough unused RIDs to last some time, unless you're building hundreds of users or computer object per week.

PDC Emulator Will be missed soon. NT 4.0 BDCs will not be able to replicate, there will be no time synchronization in the domain, you will probably not be able to change or troubleshoot group policies and password changes will become a problem.

Infrastructure Group memberships may be incomplete. If you only have one domain, then there will be no impact.

FSMO seizing restrictions:

FSMO Role Restrictions

Original must be reinstalled

Schema

Domain Naming

Can transfer back to original

RID

PDC Emulator

Infrastructure

steps to seize and transfer

1. On any domain controller, click Start, click Run, type Ntdsutil in the Open box, and then click OK.

C:\WINDOWS>ntdsutil

ntdsutil:

1. Type roles, and then press ENTER.

ntdsutil: roles

fsmo maintenance:

Note: To see a list of available commands at any of the prompts in the Ntdsutil tool, type ?, and then press ENTER.

1. Type connections, and then press ENTER.

fsmo maintenance: connections

server connections:

1. Type connect to server <servername>, where <servername> is the name of the server you want to use, and then press ENTER.

server connections: connect to server server100

Binding to server100 ...

Connected to server100 using credentials of locally logged on user.

server connections:

1. At the server connections: prompt, type q, and then press ENTER again.

server connections: q

fsmo maintenance:

1. Type seize <role>, where <role> is the role you want to seize. For example, to seize the RID Master role, you would type seize rid master:

Options are:

Seize domain naming master

Seize infrastructure master

Seize PDC

Seize RID master

Seize schema master

1. You will receive a warning window asking if you want to perform the seize. Click on Yes.

fsmo maintenance: Seize infrastructure master

Attempting safe transfer of infrastructure FSMO before seizure.

ldap_modify_sW error 0x34(52 (Unavailable).

Ldap extended error message is 000020AF: SvcErr: DSID-03210300, problem 5002 (UNAVAILABLE)

, data 1722

Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holde

r could not be contacted.)

)

Depending on the error code this may indicate a connection,

ldap, or role transfer error.

Transfer of infrastructure FSMO failed, proceeding with seizure ...

Server "server100" knows about 5 roles

Schema - CN=NTDS Settings,CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net

Domain - CN=NTDS Settings,CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net

PDC - CN=NTDS Settings,CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net

RID - CN=NTDS Settings,CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net

Infrastructure - CN=NTDS Settings,CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net

fsmo maintenance:

Note: All five roles need to be in the forest. If the first domain controller is out of the forest then seize all roles. Determine which roles are to be on which remaining domain controllers so that all five roles are not on only one server.

1. Repeat steps 6 and 7 until you've seized all the required FSMO roles.

2. After you seize or transfer the roles, type q, and then press ENTER until you quit the Ntdsutil tool.

Note: Do not put the Infrastructure Master (IM) role on the same domain controller as the Global Catalog server. If the Infrastructure Master runs on a GC server it will stop updating object information because it does not contain any references to objects that it does not hold. This is because a GC server holds a partial replica of every object in the forest

User Avatar

Wiki User

12y ago
This answer is:
User Avatar
More answers
User Avatar

Wiki User

12y ago

Domain Naming Master (p. 94)

This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: What type of FSMO role can be transfered from one domain controller to another using the active directory domain and trust mmc snap-in?
Write your answer...
Submit
Still have questions?
magnify glass
imp
Related questions

Do you have to install active directory in server 2008?

No, you do not. You only install Active Directory if the system is going to be a domain controller. If it is a member server or a standalone server Active Directory should not be installed.


Which is a physical object domain controller or forest in active directory?

Domain controller is the physical object.


Which Windows Server 2008 features enables you to perform certain Active Directory maintenance functions without needing to reboot the domain controller?

The Restartable Active Directory, that allows you to have the ntds.dit in offline mode WITHOUT rebooting the domain controller.


Active directory information is stored on each domain controller in a file called?

The Active Directory database is stored on each domain controller in a file called NTDS.DIT


What can you transfer from one domain controller to another using the Active Directory Domains and Trusts MMC snap-in?

Domain Naming Master


What is the name of domain controller database used by windows server 2008?

In Windows Server 2011 it is called Active Directory.


What is the default user created when active directory is installed?

Domain Controller


What fsmo can you transfer from one domain controller to another using the active directory domains and trust mmc snap-in?

Domain Naming Master


Which windows server 2008 feature enables you to perform certain Active Directory maintenance function without needing to reboot the domain controller?

Restartable Active Directory


Active directory information is stored on each domain controller in a file called what?

NTDS.DIT


How do you deete active directory?

You run the 'dcpromo' command to remove active directory and demote a domain controller to a member server. To remove AD completely you would have to do this process on all domain controllers.


What is AD-integrated zones?

An AD-integrated zone is a DNS zone that is integrated with Active Directory. Typically this occurs on a Domain Controller (dc), which requires DNS to answer queries from Active Directory (LDAP).