Transferring FSMO Rules to new server

Hello all...

My 'main' server is experiencing problems with its RAID drive.  We are taking it down this weekend to remedy.  To cover all of my bases, I have added a new server to the network, and made it an AD server with the Global Catalog installed.

I am now in the process of moving the roles to that server. I have transferred over:

RID Master, PDC Emulator, Domain Naming Master, Schema Master (all with no problem)

When I go to change the Infrastructure Master, I get a warning:

(this server) is a Global Catalog (GC) server.The infratructure operations master role should not be transferred to a GC server...please see help, etc.

Are you certain you want to transfer?

Should I transfer it?  The other server that it is currently on is a GC server.  Are there any consequences, etc. I should watch out for when I do?

Insight appreciated,


Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.


In a multiple domain controller environment, the Infrastructure master should not be on a GC. If this is the only DC in this site, it should be okay however.



Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial

In every AD environment I've seen, Ive heard of this isuue... OK Let's see...

AD heavily relies on redundancy, which means at least two domains controllers. Let's say that only one of them holds the GC. If that DC fails, no more GC, which means only the domain admin has logon privileges... OK, so both DCs are now GC, but you have to do something about this damn infrastructure master ... OK Let's setup a third DC, not GC, whose role will be to safely host the infrastructure operations master role.... In a small organization, that would mean some money.

Would the conclusion be : Msft never thought about smaller companies when they developed AD ? Nah, I don't want to believe this. The point is I've seen many DCs host all FSMO roles flawlessy.

It's not considered a best practice, though, but if it's your only option, go ahead, it shouldn't hurt.

The other EE experts are right...but just in case you want MS' word

From here:

Domain-level role absence on a Global Catalog server

Do not host the infrastructure master on a domain controller that is acting as a global catalog server.

The infrastructure master updates the names of security principals for any domain-named linked attributes. For example, if a user from one domain is a member of a group in a second domain and the user’s name is changed in the first domain, then the second domain is not notified that the user’s name must be updated in the group’s membership list. Because domain controllers in one domain do not replicate security principals to domain controllers in another domain, the second domain never becomes aware of the change. The infrastructure master constantly monitors group memberships, looking for security principals from other domains. If it finds one, it checks with the security principal’s domain to verify that the information is updated. If the information is out of date, the infrastructure master performs the update and then replicates the change to the other domain controllers in its domain.

Two exceptions apply to this rule. *************First, if all the domain controllers are global catalog servers, the domain controller that hosts the infrastructure master role is insignificant because global catalogs do replicate the updated information regardless of the domain to which they belong. Second, if the forest has only one domain, the domain controller that hosts the infrastructure master role is not needed because security principals from other domains do not exist.*******************

Because it is best to keep the three domain-level roles together, avoid putting any of them on a global catalog server.

Cloud Class® Course: Microsoft Office 2010

This course will introduce you to the interfaces and features of Microsoft Office 2010 Word, Excel, PowerPoint, Outlook, and Access. You will learn about the features that are shared between all products in the Office suite, as well as the new features that are product specific.

tnormanAuthor Commented:
Everyone...thanks for the feedback on this.  I get the impression that the Infrastructure Role is mostly for multi-domain companies, which this one is not.

Let's say that the gods are willing, and the problem with my 'main' server is simply a defective drive in the RAID and it comes back no problem (after being replaced).  I now have

- 4 roles on one server
- 1 role (Infra) on another server
- GC on both servers

If you only have two AD controllers, (as noted above), where's the redundancy of for the GC if I only have it in one place?  Is the role distribution more important than GC?

I already got this company to by a separate server for redundancy...they will really question why I would need two more.

I realize I am not asking any specific questions here, but am looking for 'best practices' in a W2K3 network environment with two servers that have AD.


tnormanAuthor Commented:
Did the reboot this am, and oddly enough, the server came back fully functional (i.e. no disk problems.)

However, good info above.  Thanks everyone for their input.

Thanks for the assist points, happy to help out.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.