Home › How domain controllers work › Step 6

Transferring and seizing FSMO roles

Step 6 of 6 in How domain controllers work · video 2:46

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Operations master roles sometimes have to move to another domain controller. A planned move, for example before decommissioning a server or to balance the load, is a transfer: the current holder is online and its latest data replicates to the new holder. An unplanned move after a hardware or system failure is a seizure, done only as a last resort because the original holder is gone and the new holder's data might be incomplete or out of date. The lesson maps each role to the snap-in that transfers it: Active Directory Schema for the schema master, Active Directory Domains and Trusts for the domain naming master, and Active Directory Users and Computers for the RID master, infrastructure master and PDC emulator. The snap-ins cannot seize roles; that needs ntdsutil.exe or Windows PowerShell, where Move-ADDirectoryServerOperationMasterRole with -Identity and -OperationMasterRole transfers roles and the -Force switch seizes them.

Check yourself

Answer in your head first, then open each question to see the answer.

1. You are about to decommission the domain controller that holds the PDC emulator role. Should you transfer or seize the role?

Transfer it. The move is planned and the current holder is online, so its latest data replicates to the target and nothing is lost; seizing is only for a holder that has failed.

2. Which snap-in do you use to transfer the domain naming master role?

Active Directory Domains and Trusts. The schema master is transferred in Active Directory Schema, and the three domain-level roles in Active Directory Users and Computers.

3. The schema master has failed for good. Can you take over the role with the Active Directory Schema snap-in?

No. The snap-ins can only transfer roles from a holder that is still running; to seize a role you must use ntdsutil.exe or Windows PowerShell.

4. What does Move-ADDirectoryServerOperationMasterRole -Identity DC2 -OperationMasterRole RIDMaster,PDCEmulator -Force do?

It moves the RID master and PDC emulator roles to DC2. The -Force switch makes it seize the roles when the current holder cannot hand them over; without -Force the command only performs a normal transfer.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← What are operations masters (FSMO roles)?Path complete - back to How domain controllers work →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.