Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

fsmo roles questions

Posted on 2009-07-01
6
Medium Priority
?
941 Views
Last Modified: 2012-05-07
Just want a confirmation ...

I have an existing DC/GC (Win Srv 2003) and an addtional DC/GC (Win Srv 2008) in the same domain in that forest. I just want to confirm that there is no need to transfer any FSMO roles (including Domain Naming Master role, schema master, Specific RID Master, PDC Emulator, and Infrastructure Master FSMO Roles) to my additional Domain Controller (Win Srv 2008)  ?? From my understanding, I think the answer is NO.

In case if my primary DC goes down, then my additional DC will act as a backup, in that case do I loose anything if I hadn't transferred the FSMO roles ?

0
Comment
Question by:nabeel92
6 Comments
 
LVL 85

Assisted Solution

by:oBdA
oBdA earned 400 total points
ID: 24760850
You can leave the FSMO roles where they are. AD will continue to work for some time even if the FSMO role masters aren't available.
In case the FSMO holder dies completely and unrecoverably, you can still seize the roles from another machine (though seizing is the last resort); you won't lose anything.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 1600 total points
ID: 24760860
No you don't lose anything if the current FSMO role holder goes down.  I'm assuming both are DNS and clients are pointing to both so if the Windows 2003  DC goes down clients should still be ok.
Now the bigger question is how long is your primary DC going to be down.  If we are talking about a major outage where you have to wait for a hardware part for a little while then at that point the question of  seizing the FSMO roles comes into play. (mainly the PDC emulator)
Brian Puhl from Microsofts internal AD team wrote a really good blog entry a few years ago on this subject
http://blogs.technet.com/bpuhl/archive/2005/12/07/415761.aspx
What to do with FSMO roles...
Thanks
Mike
0
 
LVL 4

Expert Comment

by:Macros82
ID: 24760864
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:nabeel92
ID: 24760894
Yes, both are DC and actually ive tested by making the primary DC go down, clients are able to log into their accounts and use web just fine.
Basically, initially me and my boss planned to move the DC to a new server and we had created a document in which we wrote the procedure to move the fsmo roles across. Definetly in that scenario, FSMO roles would need to be moved across. But now for some management reason, we are using another server as an additional DC which will come into play only when this DC goes down (and we anticipating this DC to go down for 2-3 days). So I dont think I'd need to move FSMO roles. Out of curiosity, can I (if yes, how) move the fsmo roles. I read some theory and it said there can be only one schema master, Specific RID Master, PDC Emulator, etc at a time ?

Thanks guys for the quick reply !
0
 
LVL 85

Assisted Solution

by:oBdA
oBdA earned 400 total points
ID: 24760932
For two or three days, there should be no real need to move the FSMO roles.
But here's how to do it:
How to view and transfer FSMO roles in Windows Server 2003
http://support.microsoft.com/kb/324801
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 1600 total points
ID: 24760938
Yes one schema master and domain naming master per forest
one PDC emulator, RID master, and Infrastructure master per domain.
So over at activedir.org (really good active directory listserv) there have been some vigorous debates about moving the FSMO roles even if you are just patching and rebooting.  The people that are for that say that lets say for some reason your DC doesn't come back up after the patches/reboot,  well if you have already transferred the roles you don't have to worry about them and moving the roles is a easy process.  
http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/31456/view/topic/Default.aspx
That is the thread I'm talking about.  Brian Desmond and Joe Richards (listmail) both come out in favor of the plan above.   If you are going to be down for 3 days I'd probably move the oles.
Thanks
Mike
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

963 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question