Active Directory FSMO Roles Explained

-

|

Introduction

This article offers a simplified explanation of the 5 Active Directory FSMO (pronounced “FisMO”) roles.

Active Directory FSMO Roles

Active Directory (AD) operates a multi-master database model. Meaning that all Domain Controllers (DC) have writable copies of the AD Database. Though AD is multi-master database, there are some roles that has to be single-master roles.

Single-master roles means that one DC performs the operation and replicates to other DCs. These single-master operations roles are called FSMO (Flexible Single-Master Operations) roles.

The FSMO roles are sensitive roles that if performed by more than one DC will cause conflict. After going through this article you will have a better understanding of the 5 Active Directory FSMO roles.

The 5 Active Directory FSMO roles are:

  • RID Master
  • Schema Master
  • Domain Naming Master
  • Infrastructure Master and
  • PDS Emulator Master
Advertisement
When a DC assigned one of these roles performs an operation, the DC replicates the modified data to other DCs in the forest.

1
RID Master Active Directory FSMO Role

Domain Controllers create security principals like users, computers and so on. Every time a security principal is created the DC assigns the object a unique Security ID (SID). The SID has two components – Domain SID and a Relative ID (RID). Every object created in a domain has the same Domain SID. But the Relative ID (RID) is unique for each security principal created.

For a domain controller to assign RIDs, it has to have a pool of RIDs. The assignment of RID pools to DCs is a single master operations role. This operation is performed by the DC asigned the RID Master Flexible Single-Master Operations (FSMO) role.

2
Schema Master Active Directory FSMO Role

Transfer Schema Master Role

Active Directory Schema is a definition of object classes and their attributes. An example of an object class is Users. A user attribute is the User Name, Job title, etc.

Sometimes, an administrator may need to extend the Active Directory Schema. To extend a schema is to define a new object and its attributes. Schema extension operation is handled by one DC. The DC that handles addition and deletion of objects in the schema is called the Schema Master.

3
Domain Naming Master Active Directory FSMO Role

In an Active Directory forest, domains may be added or deleted. To avoid conflict, the addition and deletion of domains is a single-master operations role. The DC assigned the Domain Naming Master FSMO role handles domain addition and deletion in the AD forest.

The Domain Naming Master DC is also responsible for adding or removing cross references to domains in external directories.

4
Infrastructure Master Active Directory FSMO Role

In an AD forest with multiple domains, objects are cross-referenced from one domain to the other. The Domain Controller holding the Infrastructure Master FSMO role is responsible for keeping cross-domain object references up to date.

As an example, say an object in Domain-A is referenced by another object in Domain-B. When the referenced object is modified, the Infrastructure Master is responsible for updating the references.

A simple explanation of object referencing is when an object is accessed. For example, a user in Domain-A accesses a shared folder in Domain-B. When that shared folder changes, the Infrastructure Master FSMO role DC stores the updated object reference and replicates it to other DCs.

5
PDS Emulator Master Active Directory FSMO Role

The PDC Emulator FSMO Domain Controller handles user authentication, password change and time synchronization. The DC assigned the PDC Emulator role also handles account lockouts and forwards authentication failures (triggered by incorrect passwords) to other DCs.

Advertisement

Conclusion

The Active Directory multi-master model means that any Domain Controller (DC) can update the AD database. But there ate 5 operations reserved for one DC. These are called Flexible Single-Master Operations (FSMO) roles.

I hope this guide simplified the explanation of these 5 Active Directory FSMO roles.

If you have any question or comment about Active Directory FSMO roles use the “Leave a Reply” form at the end of the page. Alternatively, you can share your experience transferring or seizing Active Directory FSMO roles.

Other Helpful Guides

Additional Resources and References

LEAVE A REPLY

Please enter your comment!
Please enter your name here

FEATURED POSTS

How to Share a Folder in Windows 10 (3 Methods)

Introduction This guide demos how to share folder in windows 10. It covers 3 methods. Options...

How to Map Network Drive in Windows 10 (5 Methods)

Introduction This guide demos 5 methods to Map Network Drive in Windows 10. Options to...
How to Install Windows 10 1909 Preview Build

How to Install Windows 10 19H2 Preview Build

Introduction If you are a member of Windows 10 Insider Program you can install Windows 10 19H2 Preview Build....

How to Sign in to Windows 10 with a Microsoft Account

Introduction When you installed Windows 10 you may have created and signed in with a local account. You can...
Disable IPv6 in Windows 10

How to Disable IPv6 in Windows 10 (3 Methods)

Introduction This guide demos 3 methods to disable IPv6 in Windows 10: Disable IPv6 from...

Advertisement

TRENDING POSTS

Remote Desktop Connection

Remote Desktop Connection an Internal Error Has Occurred [Fixed]

Introduction I recently received the error message "Remote Desktop Connection an Internal Error Has Occurred". It was strange because...

Find My Samsung: Register and Use Samsung Find my Mobile

Introduction Ever wondered how you could find your Samsung phone if you lost it? Find my Samsung or Samsung...
What is the Difference Between PowerShell and CMD?

Windows Powershell vs CMD: Differences and Similarities

Introduction This short guide compares Windows PowerShell vs CMD (Windows command prompt). I will cover the history and nature...
Spotify No Longer Supports this Version of Microsoft Edge

Spotify No Longer Supports this Version of Microsoft Edge [Fixed]

Introduction When you open Spotify web player on Microsoft Edge, you may receive the error message "Spotify No Longer...
Windows 10 Won't Boot

Windows 10 Won’t Boot With Black Screen? 3 Ways to Fix It

Why Won't Windows 10 Boot Up? If your Windows 10 stops with a black screen, the first question in...

Advertisement

BEST OF ITECHGUIDES

Windows 7 Support End Date

Windows 7 Support Ends January 14, 2020: Your Upgrade Options

Introduction According to Microsoft, Windows 7 support end date is January 14, 2020. Microsoft recommends that you upgrade to...
windows safe mode

2 Easy Ways to Start Windows 10 Safe Mode

Introduction In previous versions of Windows you could start safe mode by pressing F8. But in Windows 10, F8...

How to Fix “BootMgr is Missing” Error in Windows 10

Introduction If you receive Fix "BootMgr is missing" Error in Windows 10, the default response is panic! But you...
Configure Group Policy for Windows Updates Server 2016 (WSUS Server 2016)

How to Configure Group Policy for WSUS in Windows Server 2016

Introduction This guide demos how to configure Group Policy for Windows Updates Server 2016 (WSUS Server 2016).
change computer name - rename a windows 10 pc

4 Methods to Rename (Change the Name of) a Windows 10 PC

Introduction This guide demos 4 methods you can use to change computer name for a Windows 10 PC. You...

RECENT POSTS

How to Enable Hyper-V in Windows 10 (3 Methods)

How to Enable Hyper-V in Windows 10 (3 Methods)

Introduction This guide demos 3 methods to enable Hyper-V in Windows 10. To install Hyper-V...
RSAT Tools in Windows 10 Explained: Plus How to Install RSAT

RSAT Tools in Windows 10 Explained: Plus How to Install RSAT

Introduction Starting from October 2018 (1809) update, RSAT Tools became part of Windows 10. From this version of Windows...

How to Enable RSAT for Active Directory in Windows 10 (3 Methods)

Introduction This guide demos 3 methods to enable Active Directory in Windows 10. It is not exactly enabling "Active...
How to Install Windows 10 1909 Preview Build

How to Install Windows 10 1909 (19H2) Preview Build

Introduction Windows 10 1909 Preview is available for Windows Insiders. Made available early September, 2019 you have to be...
How to Install RSAT in Windows 10 (3 Methods)

How to Install RSAT in Windows 10 (3 Methods)

Introduction This guide demos how to Install RSAT in Windows 10. Starting with Windows 10...

How to Share a Folder in Windows 10 (3 Methods)

Introduction This guide demos how to share folder in windows 10. It covers 3 methods. Options...
Configure Map Network Drive with Group Policy

Map Network Drive in Windows 10 with Group Policy

Introduction This guide demos how to map network drive with group policy. This guide is...

How to Map Network Drive in Windows 10 (5 Methods)

Introduction This guide demos 5 methods to Map Network Drive in Windows 10. Options to...
How to Download Windows 10 ISO with Media Creation Tool

How to Download Windows 10 ISO with Media Creation Tool

Introduction This guide demos the steps to download Windows 10 ISO. You can download Windows 10 ISO with Media...

How to Install Windows 10 from Network Boot (Via WDS Server)

Introduction This guide demos how to install Windows 10 from network boot. The steps discussed in...

Advertisement

MUST READ

windows server 2016 black screen after login

How to Fix Windows Server 2016 Black Screen After Login

Introduction A number of users have reported Windows Server 2016 black screen after login. The black screen happens:
powershell delete folder or File

How to Delete Folders or Files in PowerShell

Introduction You can delete folders and files in PowerShell using the Delete method or Remove-Item Cmdlet. This guide shows...
office 365 powershell

How to Import and Use Office 365 PowerShell Modules

Introduction Office 365 Powershell provides modules you can use to automate Office 365 tasks. But to access these modules...
the-user-profile-service-failed-the-logon-featured

How to Fix “The User Profile Service Failed the Logon” in Windows 10

Introduction "The user profile service failed the logon Windows" error is likely to occur after an upgrade to Windows...
Spotify No Longer Supports this Version of Microsoft Edge

Spotify No Longer Supports this Version of Microsoft Edge [Fixed]

Introduction When you open Spotify web player on Microsoft Edge, you may receive the error message "Spotify No Longer...

By using this website you agree to accept our Privacy Policy and Terms & Conditions