close

Windows 2000/2003 Active Directory domains utilize a Single Operation Master method called FSMO (Flexible Single Master Operation), as described in Understanding FSMO Roles in Active Directory.

---------------------------------------------------------------------------------------------------------------------------------------------------The five FSMO roles are:

  • Schema master – Forest-wide and one per forest.
  • Domain naming master – Forest-wide and one per forest.
  • RID master – Domain-specific and one for each domain.
  • PDC – PDC Emulator is domain-specific and one for each domain.
  • Infrastructure master – Domain-specific and one for each domain.

---------------------------------------------------------------------------------------------------------------------------------------------------

FSMO Role
Loss implications

Schema
The schema cannot be extended. However, in the short term no one will notice a missing Schema Master unless you plan a schema upgrade during that time.

Domain Naming
Unless you are going to run DCPROMO, then you will not miss this FSMO role.

RID
Chances are good that the existing DCs will have enough unused RIDs to last some time, unless you‘re building hundreds of users or computer object per week.

PDC Emulator
Will be missed soon. NT 4.0 BDCs will not be able to replicate, there will be no time synchronization in the domain, you will probably not be able to change or troubleshoot group policies and password changes will become a problem.

Infrastructure
Group memberships may be incomplete. If you only have one domain, then there will be no impact.

*****************************************************************************************************************

Caution: Using the Ntdsutil utility incorrectly may result in partial or complete loss of Active Directory functionality.

  1. ---------------------------------------------------------------------------------------------------------------------------------------------------
    * On any domain controller, click Start, click Run, type Ntdsutil in the Open box, and then click OK.

[
icrosoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.
C:\WINDOWS>ntdsutil
ntdsutil:

]

  1. ---------------------------------------------------------------------------------------------------------------------------------------------------
    * Type roles, and then press ENTER.
    [

    ntdsutil: roles
    fsmo maintenance:

    ]

    Note: To see a list of available commands at any of the prompts in the Ntdsutil tool, type ?, and then press ENTER.

    ---------------------------------------------------------------------------------------------------------------------------------------------------
    * Type connections, and then press ENTER.
    [
    fsmo maintenance: connections
    server connections:

    ]

    ---------------------------------------------------------------------------------------------------------------------------------------------------
    * Type connect to server <servername>, where <servername> is the name of the server you want to use, and then press ENTER.

    [
    server connections: connect to server server100
    Binding to server100 ...
    Connected to server100 using credentials of locally logged on user.
    server connections:

    ]
    ---------------------------------------------------------------------------------------------------------------------------------------------------
    *At the server connections: prompt, type q, and then press ENTER again.
    [
    server connections: q
    fsmo maintenance:

    ]
    ---------------------------------------------------------------------------------------------------------------------------------------------------
    * Type seize <role>, where <role> is the role you want to seize. For example, to seize the RID Master role, you would type seize rid master:
    [
    Seize domain naming master
    Seize infrastructure master
    Seize PDC
    Seize RID master
    Seize schema master

    ]

    ---------------------------------------------------------------------------------------------------------------------------------------------------
    * You will receive a warning window asking if you want to perform the seize. Click on Yes.http://www.petri.com/images/seize1.gif

    [
    fsmo maintenance: Seize infrastructure master
    Attempting safe transfer of infrastructure FSMO before seizure.
    ldap_modify_sW error 0x34(52 (Unavailable).
    Ldap extended error message is 000020AF: SvcErr: DSID-03210300, problem 5002 (UNAVAILABLE)
    , data 1722

    Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holde
    r could not be contacted.)
    )
    Depending on the error code this may indicate a connection,
    ldap, or role transfer error.
    Transfer of infrastructure FSMO failed, proceeding with seizure ...
    Server "server100" knows about 5 roles
    Schema - CN=NTDS Settings,CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
    Domain - CN=NTDS Settings,CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
    PDC - CN=NTDS Settings,CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
    RID - CN=NTDS Settings,CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
    Infrastructure - CN=NTDS Settings,CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
    fsmo maintenance:

    ]

    ---------------------------------------------------------------------------------------------------------------------------------------------------

    Note: All five roles need to be in the forest. If the first domain controller is out of the forest then seize all roles. Determine which roles are to be on which remaining domain controllers so that all five roles are not on only one server.

    1. 1. Repeat steps 6 and 7 until you‘ve seized all the required FSMO roles.
    2. 2. After you seize or transfer the roles, type q, and then press ENTER until you quit the Ntdsutil tool.


    Note:
    Do not put the Infrastructure Master (IM) role on the same domain controller as the Global Catalog server. If the Infrastructure Master runs on a GC server it will stop updating object information because it does not contain any references to objects that it does not hold. This is because a GC server holds a partial replica of every object in the forest.

     

arrow
arrow
    全站熱搜

    trex0002006 發表在 痞客邦 留言(0) 人氣()