Solved

Why Infrastructure Master cannot runs on a Global Catalog server ?

Posted on 2008-10-26
12
1,448 Views
Last Modified: 2012-05-05
I read from some articles saying Infrastructure Master cannot runs on a Global Catalog server. They should be installed on separate server when I have more than one domain. Can any one explain to me?
0
Comment
Question by:wuitsung
12 Comments
 
LVL 9

Expert Comment

by:waynewilliams
ID: 22807968
This is merely a recommendation from Microsoft.  I have all my FSMO roles on the one DC and it works fine.   More detailed info on placement of FSMO roles in this article here:

http://support.microsoft.com/kb/223346


0
 
LVL 31

Assisted Solution

by:Henrik Johansson
Henrik Johansson earned 400 total points
ID: 22808001
http://technet.microsoft.com/en-us/library/cc816619.aspx
"The infrastructure master is incompatible with the global catalog, and it must not be placed on a global catalog server."
0
 

Author Comment

by:wuitsung
ID: 22808127
Is there any easy way to understand?

0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 400 total points
ID: 22808301
http://support.microsoft.com/kb/223346
"Because the global catalog server holds a partial replica of every object in the forest, the infrastructure master, if placed on a global catalog server, will never update anything, because it does not contain any references to objects that it does not hold."

http://technet.microsoft.com/en-us/library/cc268210.aspx
"If an infrastructure master is placed on a global catalog server, it will not correctly identify outdated security principals from other domains."

With other words, replication will not work as expected with multiple domains if infrastructure master is placed on same server as a GC.
0
 

Author Comment

by:wuitsung
ID: 22808395
I read this before already, but I still don't understand what it means...

"global catalog server holds a partial replica of every object in the forest.."
But it holds full replica of its domain right?

It's saying if I put IM on GC, IM doesn't contain any reference to objects, so it will never update.

So why if the IM and GC are separate, then IM will contain reference???
0
 
LVL 31

Assisted Solution

by:Henrik Johansson
Henrik Johansson earned 400 total points
ID: 22808574
Yes, GC has full copy of objects in its own domain and partial copy of any object in other domains in the forest.
Infrastructure master communicates with GC. If placing infrastructure master on same server as GC, it will have the GC-data locally on same server and will not have a reference to compare what objects nead to be updated.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 22808590
minor typo in last post:
GC has full copy of all objects in its own domain and partial copy of all objects in other domains in the forest.
0
 

Author Comment

by:wuitsung
ID: 22809798
Sorry to ask you again.. Here is the one I read..

"If infrastructure master and GC is on the same server then infrastructure will not function because it will never find the data that is out of date."

I really want to know why the IM not able to find the data that is out of date?

And you said that it will have the GC-data locally, but why IM cannot ind the data locally??

Is there any easy example that can help me understand the concept?
0
 

Author Comment

by:wuitsung
ID: 22809885
Could you please tell me if I am right? I think maybe it's because the GC holds partial copy of all other domain, so when the the IM is on GC, IM think it alrady has the latest info, so IM will not do any update?? Am i right?
0
 
LVL 31

Assisted Solution

by:Henrik Johansson
Henrik Johansson earned 400 total points
ID: 22811963
Yes
If having infrastructure master on same server as GC, it will believe the GC has the current version of the replicated data retrieved from the other domain and will not update its GC with changes.
0
 

Author Comment

by:wuitsung
ID: 22819634
Sorry to keep you here so long. I just raised the point here for you.
This is what I THINK so far, please advice me if I am wrong...

I think IM knows nothing of outside world of its domain. It just keep comparing its data with GC, see if there is anything new. If there is something new in GC, it updates from GC and then replicate to other DCs in its domain. GC syncs with other GC in other domains. So GC always has the latest data.

If IM is on GC, IM will think it already has the latest data from GC, so it will never update.

Anything wrong? Thank you again.
0
 
LVL 59

Assisted Solution

by:Darius Ghassem
Darius Ghassem earned 100 total points
ID: 22825782
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now