Solved

FSMO Roles

Posted on 2013-01-08
14
472 Views
Last Modified: 2013-01-14
I need to move around all 5  FSMO roles between few servers. Can I do the move during the production hours. Will this effect the network or the end users ?
0
Comment
Question by:Lidka
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 3
  • +4
14 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38755707
It should not have any affect on the users.  Having said that I don't want to be a hypocrite.  I've always done changes during off hours (per policy where I work usually).

Thanks

Mike
0
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38755708
We have tried doing this in Windows 2003 & 2008 server environments. We had a problem during production hours on the 2003 server. In theory, it should be ok, but we made a decision to do all future role moves after production hours to be safe.
0
 
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 38755948
Transferring FSMO's is 5 Minute procedure but the change is big in Nature even if something breaks there may be major impact on domain ...However doing so will not affect end user under normal circumstances still such activities should be performed off Hours
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 96

Accepted Solution

by:
Lee W, MVP earned 500 total points
ID: 38755965
Agree with the above, it SHOULD be safe and transparent... HOWEVER, why risk it?

Another point - WHY are you doing this... why do you "need to move around all 5  FSMO roles between few servers."?  Once, I understand... maybe even twice.  But why a "few"?  And how many is a few?  I would suspect you could face other problems that aren't really FSMO problems but rather are problems because the roles are typically on the first DC built that is also a Global Catalog (that can cause issues) and if you haven't verified AD is healthy, if you start making changes and don't have healthy DCs on the network, you end up with problems.  (RUN DCDIAG First to ensure everything is good!)
0
 

Author Comment

by:Lidka
ID: 38756032
I have now all 5 roles on one server - server 1,
I will move

schema and domain naming to server 2
infrastructure to server 3 and I will turn off the GC on server 3

So the PDC and Rid will stay unattached on server 1
0
 
LVL 18

Expert Comment

by:Sushil Sonawane
ID: 38756057
As you mention plan is right because Infrastructure and GC both are not configure on the same server in network.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38756073
Try to make all your DCs GCs if you can.  That is the best practice.

Thanks

Mike
0
 
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 38756078
Why create such complex environment ..? When all DC's are GC it doesn't really matters where you are placing the IM role
0
 
LVL 96

Expert Comment

by:Lee W, MVP
ID: 38756084
How many DOMAINS (not domain controllers) do you have?  Are you planning on more?

How large is your environment?
0
 

Author Comment

by:Lidka
ID: 38756093
this is recommended by microsoft so I thought I will follow that and make sure I do not have all roles on one server as I do have now

Schema Master and Domain Naming Master to be on the same machine. This server should also be a GC
PDC Emulator and RID Master to be on the same machine as well. This should be a good machine to handle the load.

Infrastructure Master that do not host GC, but it is in the same side with another server hosting GC.
0
 
LVL 96

Expert Comment

by:Lee W, MVP
ID: 38756132
When people say something is recommended by Microsoft (especially FSMO placement) I find it's USUALLY because their misreading something.  Please tell us where you read this and how many domains and users.
0
 
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 38756147
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38756162
0
 
LVL 3

Expert Comment

by:mav7469
ID: 38757757
Moving most of the roles should be fine.  However, I agree with everyone else here.  It should be done after hours.

The only issue you will run into the the Schema Role is not one that moves very easily.  I would consider leaving that one on server 1 and move the rest.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question