Home › How domain controllers work › Step 5
What are operations masters (FSMO roles)?
Step 5 of 6 in How domain controllers work · video 5:46
What you will learn
- The five FSMO roles and which exist per forest or per domain
- What stops working when each role holder is unavailable
- Why the PDC emulator matters for time, passwords and GPO editing
- How to find role holders with Get-ADForest and Get-ADDomain
About this lesson
Some changes in AD DS can be made on only one domain controller. That domain controller holds an operations master role, also called a flexible single master operations (FSMO) role, and keeping these changes on a single server avoids conflicts caused by replication delay. The lesson lists the five roles: the schema master and domain naming master, one of each per forest, and the RID master, infrastructure master and PDC emulator, one of each per domain. The first domain controller in a new forest holds all five until you move them. For each role it explains the job and what goes wrong when the holder is offline: no new domains, no schema changes, running out of RIDs for new objects, and slower spread of password changes. It covers the PDC emulator as the domain time source and the default place where GPOs are edited, and the Get-ADForest and Get-ADDomain cmdlets that show who holds each role.
Check yourself
1. A forest has three domains. How many schema masters and how many RID masters does it have?
One schema master, because that role exists once per forest, and three RID masters, because each domain has its own RID master, infrastructure master and PDC emulator.
2. What happens if the RID master stays offline for a long time?
Domain controllers keep creating objects from the blocks of RIDs they already hold, but once those run out they cannot create new objects, because every new SID needs a unique RID that only the RID master hands out.
3. A user changes their password at head office and minutes later signs in at a branch whose domain controller has not yet replicated the change. Why does the sign-in still work?
Password changes are sent straight to the PDC emulator. When the branch domain controller sees a password it does not recognise, it checks with the PDC emulator for recent changes before rejecting the sign-in.
4. Which PowerShell cmdlet shows the current schema master and domain naming master?
Get-ADForest from the Active Directory module, because those two roles belong to the forest. The domain-level roles (RID master, infrastructure master and PDC emulator) are shown by Get-ADDomain.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.