Solved

fsmo roles questions

Posted on 2009-07-01
6
901 Views
Last Modified: 2012-05-07
Just want a confirmation ...

I have an existing DC/GC (Win Srv 2003) and an addtional DC/GC (Win Srv 2008) in the same domain in that forest. I just want to confirm that there is no need to transfer any FSMO roles (including Domain Naming Master role, schema master, Specific RID Master, PDC Emulator, and Infrastructure Master FSMO Roles) to my additional Domain Controller (Win Srv 2008)  ?? From my understanding, I think the answer is NO.

In case if my primary DC goes down, then my additional DC will act as a backup, in that case do I loose anything if I hadn't transferred the FSMO roles ?

0
Comment
Question by:nabeel92
6 Comments
 
LVL 83

Assisted Solution

by:oBdA
oBdA earned 100 total points
ID: 24760850
You can leave the FSMO roles where they are. AD will continue to work for some time even if the FSMO role masters aren't available.
In case the FSMO holder dies completely and unrecoverably, you can still seize the roles from another machine (though seizing is the last resort); you won't lose anything.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 400 total points
ID: 24760860
No you don't lose anything if the current FSMO role holder goes down.  I'm assuming both are DNS and clients are pointing to both so if the Windows 2003  DC goes down clients should still be ok.
Now the bigger question is how long is your primary DC going to be down.  If we are talking about a major outage where you have to wait for a hardware part for a little while then at that point the question of  seizing the FSMO roles comes into play. (mainly the PDC emulator)
Brian Puhl from Microsofts internal AD team wrote a really good blog entry a few years ago on this subject
http://blogs.technet.com/bpuhl/archive/2005/12/07/415761.aspx
What to do with FSMO roles...
Thanks
Mike
0
 
LVL 4

Expert Comment

by:Macros82
ID: 24760864
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 

Author Comment

by:nabeel92
ID: 24760894
Yes, both are DC and actually ive tested by making the primary DC go down, clients are able to log into their accounts and use web just fine.
Basically, initially me and my boss planned to move the DC to a new server and we had created a document in which we wrote the procedure to move the fsmo roles across. Definetly in that scenario, FSMO roles would need to be moved across. But now for some management reason, we are using another server as an additional DC which will come into play only when this DC goes down (and we anticipating this DC to go down for 2-3 days). So I dont think I'd need to move FSMO roles. Out of curiosity, can I (if yes, how) move the fsmo roles. I read some theory and it said there can be only one schema master, Specific RID Master, PDC Emulator, etc at a time ?

Thanks guys for the quick reply !
0
 
LVL 83

Assisted Solution

by:oBdA
oBdA earned 100 total points
ID: 24760932
For two or three days, there should be no real need to move the FSMO roles.
But here's how to do it:
How to view and transfer FSMO roles in Windows Server 2003
http://support.microsoft.com/kb/324801
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 400 total points
ID: 24760938
Yes one schema master and domain naming master per forest
one PDC emulator, RID master, and Infrastructure master per domain.
So over at activedir.org (really good active directory listserv) there have been some vigorous debates about moving the FSMO roles even if you are just patching and rebooting.  The people that are for that say that lets say for some reason your DC doesn't come back up after the patches/reboot,  well if you have already transferred the roles you don't have to worry about them and moving the roles is a easy process.  
http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/31456/view/topic/Default.aspx
That is the thread I'm talking about.  Brian Desmond and Joe Richards (listmail) both come out in favor of the plan above.   If you are going to be down for 3 days I'd probably move the oles.
Thanks
Mike
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now