The users should be able to log in but... I'm not sure you will be able to join any new machines to the domain. It may not be able to find the relative identifier. You can test this but... if this is a requirement, you may need to seize the roles in order to make it a fully functional domain.
Main Topics
Browse All Topics





by: oBdAPosted on 2009-10-28 at 13:55:47ID: 25688245
You do not need to worry, and you should do *nothing* with the roles!
om/kb/2233 46
Users *will* (well, "should") still be able to logon (provided they're using DNS servers that are still active). AD will continue to function, you will even be able to add new users and groups (to a certain extent), because each DC reserves a SID pool from the RID master and can use this pool even while the RID master is offline.
The *only* time when it's necessary to *seize* a role is when a DC dies and can't be recovered. The machine whose role(s) have been seized may NOT come online in the network anymore. *Move* roles if you want to retire a DC.
One note: make HQ2 a GC as well. The rule of not making the IM a GC doesn't apply to a single domain forest.
FSMO placement and optimization on Active Directory domain controllers
http://support.microsoft.c