Home › How domain controllers work › Step 5

What are operations masters (FSMO roles)?

Step 5 of 6 in How domain controllers work · video 5:46

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Some changes in AD DS can be made on only one domain controller. That domain controller holds an operations master role, also called a flexible single master operations (FSMO) role, and keeping these changes on a single server avoids conflicts caused by replication delay. The lesson lists the five roles: the schema master and domain naming master, one of each per forest, and the RID master, infrastructure master and PDC emulator, one of each per domain. The first domain controller in a new forest holds all five until you move them. For each role it explains the job and what goes wrong when the holder is offline: no new domains, no schema changes, running out of RIDs for new objects, and slower spread of password changes. It covers the PDC emulator as the domain time source and the default place where GPOs are edited, and the Get-ADForest and Get-ADDomain cmdlets that show who holds each role.

Good to know: one correction to the video. If the infrastructure master is offline, users can still sign in; what breaks sign-in is having no reachable global catalog, because universal group memberships cannot be checked. An offline infrastructure master only delays updates to references to objects in other domains.

Check yourself

Answer in your head first, then open each question to see the answer.

1. A forest has three domains. How many schema masters and how many RID masters does it have?

One schema master, because that role exists once per forest, and three RID masters, because each domain has its own RID master, infrastructure master and PDC emulator.

2. What happens if the RID master stays offline for a long time?

Domain controllers keep creating objects from the blocks of RIDs they already hold, but once those run out they cannot create new objects, because every new SID needs a unique RID that only the RID master hands out.

3. A user changes their password at head office and minutes later signs in at a branch whose domain controller has not yet replicated the change. Why does the sign-in still work?

Password changes are sent straight to the PDC emulator. When the branch domain controller sees a password it does not recognise, it checks with the PDC emulator for recent changes before rejecting the sign-in.

4. Which PowerShell cmdlet shows the current schema master and domain naming master?

Get-ADForest from the Active Directory module, because those two roles belong to the forest. The domain-level roles (RID master, infrastructure master and PDC emulator) are shown by Get-ADDomain.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← Domain controller SRV recordsNext: Transferring and seizing FSMO roles →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.