FSMO N AD
FSMO N AD
The schema master FSMO role holder is the DC responsible for performing updates to
the directory schema, that is, the schema naming context or LDAP. This DC is the only
one that can process updates to the directory schema. Once the Schema update is
complete, it's replicated from the schema master to all other DCs in the directory.
There's only one schema master per forest.
The domain naming master FSMO role holder is the DC responsible for making changes
to the forest-wide domain name space of the directory, that is, the Partitions\
Configuration naming context or LDAP://CN=Partitions, CN=Configuration,
DC=<domain>. This DC is the only one that can add or remove a domain from the
directory. It can also add or remove cross references to domains in external directories.
The RID master FSMO role holder is the single DC responsible for processing RID Pool
requests from all DCs within a given domain. It's also responsible for removing an object
from its domain and putting it in another domain during an object move.
A domain SID that's the same for all SIDs created in a domain.
A relative ID (RID) that's unique for each security principal SID created in a
domain.
Each Windows DC in a domain is allocated a pool of RIDs that it's allowed to assign to
the security principals it creates. When a DC's allocated RID pool falls below a threshold,
that DC issues a request for additional RIDs to the domain's RID master. The domain RID
master responds to the request by retrieving RIDs from the domain's unallocated RID
pool, and assigns them to the pool of the
In a Windows domain, the PDC emulator role holder retains the following functions:
The GUID
The SID (for references to security principals)
The DN of the object being referenced
The infrastructure FSMO role holder is the DC responsible for updating an object's SID
and distinguished name in a cross-domain object reference.
dit
log
res 1.log
log
chk