fsmo roles & new updates

Upload: parthasarathy-sowrirajan

Post on 29-May-2018

221 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/9/2019 FSMO Roles & New Updates

    1/1

    Forest-wide operations master rolesSchema masterDomain naming master

    Domain-wide operations master rolesRelative ID (RID) masterPrimary domain controller (PDC) emulator masterInfrastructure master

    These roles are also known as FSMO roles flexible single master operation.

    Schema masterThe schema master domain controller controls all updates and modifications to the schema.There can be only one schema master in the entire forest

    Domain naming masterThe addition or removal of domains in the forest, there can be only one domain naming master in theentire forest.

    Relative ID (RID) master

    The RID master allocates sequences of relative IDs (RIDs) to each of the various domain controllers in itsdomainWhenever a domain controller creates a user, group, or computer object, it assigns the object a uniquesecurity ID (SID).

    PDC emulator masterIt processes password changes from clients and replicates updates to the BDCs,If a logon authentication fails at another domain controller due to a bad password then that domaincontroller will forward the authentication request to the PDC emulator before rejecting the log on attempt.PDC emulator master is also responsible for synchronizing the time on all domain controllers throughoutthe domain

    Infrastructure master

    The infrastructure master is responsible for updating references from objects in its domain to objects inother domains,

    Why should not Infrastructure master and global catalog in the same server?If the infrastructure master and global catalog are on the same domain controller, the infrastructuremaster will not function. The infrastructure master will never find data that is out of date, so it will neverreplicate any changes to the other domain controllers in the domain.

    What is KCC (Knowledge Consistency Checker?)A connection object is a connection that AD uses for replication. Connection objects are fault tolerant.When a communication fails, AD will automatically reconfigure itself to use another route to continuereplication. The process that creates connection objects is called Knowledge Consistency Checker(KCC)

    What is the SYSVOL folder?The sysVOL folder stores the server's copy of the domain's public files. The contents such as grouppolicy, users etc of the sysvol folder are replicated to all domain controllers in the domain. The sysvolfolder must be located on an NTFS volume.

    Where exactly do fault-tolerant DFS shares store information in Active Directory?In Partition Knowledge Table, this is then replicated to other domain controllers.