Backtrack:  
 
showing posts of June 11th, 2025
 
edited by on June 11th 2025, at 12:39
If for some reason, the PDC dies horribly, you are left with a semi-working domain. While the basic functionality will still be operational, certain aspects of the domain can no longer be reconfigured. If the broken DC can no longer be rescued, you need to transfer the five FSMO roles to a working DC as soon as possible as to ensure your domain will remain healthy.

If FSMO roles are not transferred time, it can have implications on the following items, depending on the roles that are located on the offline DC:

FSMO roleImplications of lossSchemaThe schema cannot be extended or reconfigured. This is not a problem unless you wish to perform a schema upgrade during the outage.Domain NamingPro  ...
edited by on June 11th 2025, at 12:34

Based on recommendations and best practices from Microsoft, and information I found here, I compiled a FSMO placement scenario for 2 domain controllers:

DC1DC2
PDC Emulator
RID Master
Infrastructure Master
Schema Master
Domain Naming Master
Global Catalog

Also, if your domain is top-level in the AD forest, configure DC1 to sync with external time sources.

To transfer roles, it is recommended to use Powershell's Move-ADDirectoryServerOperationMasterRole.

 
showing posts of June 11th, 2025
 
 
« June 2025»
SunMonTueWedThuFriSat
1234567
891011121314
15161718192021
22232425262728
2930     
 
Links
 
Quote
« If the batteries of a TV remote run out, why do we press the buttons so much harder? »