Windows 2000/2003 Active Directory domains utilize a Single Operation Master method called FSMO (Flexible Single Master Operation), as described in Understanding FSMO Roles in Active Directory.
---------------------------------------------------------------------------------------------------------------------------------------------------The five FSMO roles are:
- Schema master – Forest-wide and one per forest.
- Domain naming master – Forest-wide and one per forest.
- RID master – Domain-specific and one for each domain.
- PDC – PDC Emulator is domain-specific and one for each domain.
- Infrastructure master – Domain-specific and one for each domain.
---------------------------------------------------------------------------------------------------------------------------------------------------
FSMO Role
Loss implications
Schema
The schema cannot be extended. However, in the short term no one will notice a missing Schema Master unless you plan a schema upgrade during that time.
Domain Naming
Unless you are going to run DCPROMO, then you will not miss this FSMO role.
RID
Chances are good that the existing DCs will have enough unused RIDs to last some time, unless you‘re building hundreds of users or computer object per week.
PDC Emulator
Will be missed soon. NT 4.0 BDCs will not be able to replicate, there will be no time synchronization in the domain, you will probably not be able to change or troubleshoot group policies and password changes will become a problem.
Infrastructure
Group memberships may be incomplete. If you only have one domain, then there will be no impact.
*****************************************************************************************************************
Caution: Using the Ntdsutil utility incorrectly may result in partial or complete loss of Active Directory functionality.
- ---------------------------------------------------------------------------------------------------------------------------------------------------
* On any domain controller, click Start, click Run, type Ntdsutil in the Open box, and then click OK.
[
icrosoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.
C:\WINDOWS>ntdsutil
ntdsutil:
]
- ---------------------------------------------------------------------------------------------------------------------------------------------------
* Type roles, and then press ENTER.