Two operations master roles exist in each forest:
- Schema master - govern all changes to the schema
- Domain naming master - add and remove domains to and from the forest
- Primary domain controller (PDC) emulator - process all replication requests from Microsoft Windows NT 4.0 backup domain controllers and processes all password updates for clients that are not running Active Directory–enabled client software
- Relative identifier (RID) master - allocate RIDs to all domain controllers to ensure that all security principals have a unique identifier
- Infrastructure master - maintain a list of the security principals from other domains that are members of groups within its domain
Certain FSMO roles depend on the DC being a Global Catalog (GC) server as well. For example, the Infrastructure Master role must not be housed on a domain controller which also houses a copy of the global catalog in a multi-domain forest (unless all domain controllers in the domain are also global catalog servers), while the Domain Naming Master role should be housed on a DC which is also a GC. When a Forest is initially created, the first Domain Controller is a Global Catalog server by default. The Global Catalog provides several functions. The GC stores object data information, manages queries of these data objects and their attributes as well as provides data to allow network logon.
Certain domain and enterprise-wide operations that are not well suited to multi-master updates must be performed on a single domain controller in the domain or in the forest. The purpose of having a single-master owner is to define a well-known target for critical operations and to prevent the introduction of conflicts or latency that could be created by multi-master updates. Having a single-operation master means that the relevant FSMO role owner must be online, discoverable, and available on the network by computers that have to perform FSMO-dependent operations.
The PDC emulator and the RID master should be on the same DC, if possible. The Schema Master and Domain Naming Master should also be on the same DC. To provide fault tolerance, there should be at least 2 domain controllers available within each domain of the Forest. Furthermore, the Infrastructure Master role holder should not also be a Global Catalog Server, as the combination of these two roles on the same host will cause unexpected (and potentially damaging) behaviour in a multi-domain environment.
References:
1. How Operations Masters Work
http://technet.microsoft.com/en-us/library/cc780487%28v=ws.10%29.aspx
2. Flexible single master operation
http://en.wikipedia.org/wiki/Flexible_single_master_operation
3. FSMO placement and optimization on Active Directory domain controllers
http://support.microsoft.com/kb/223346
No comments:
Post a Comment