Active Directory is multi-master: any writable DC can accept most changes. A few operations cannot safely happen in two places at once, so AD assigns them to single DCs called Flexible Single Master Operations (FSMO) role holders, also called operations masters. There are five roles. Two are forest-wide (one per forest) and three are domain-wide (one per domain).
The forest-wide roles are the schema master, the only DC that can modify the schema (for example when installing Exchange or raising the forest to add new attributes), and the domain naming master, which controls adding and removing domains and application partitions. The domain-wide roles are the RID master, which hands out pools of relative identifiers (RIDs) to each DC so every new security principal gets a unique security identifier (SID); the PDC emulator, which is the authoritative time source for the domain (the forest root PDC should sync with an external time source), receives urgent password changes, processes account lockouts, and is the default target for Group Policy editing; and the infrastructure master, which updates references to objects in other domains.
Placement guidance follows from what each role does. In a small environment it is fine to keep all five on one well-connected, well-protected DC. The PDC emulator should sit on a powerful DC in a central site because clients and other DCs contact it often. The RID master is usually placed with the PDC emulator. The classic rule says not to put the infrastructure master on a global catalog server unless every DC in the domain is a global catalog or the AD Recycle Bin is enabled, because a GC already holds all objects and the infrastructure master would never see stale references. Use netdom query fsmo or Get-ADDomain and Get-ADForest to see where roles live.
Moving a role has two forms. A transfer is a graceful move while both the current and new holder are online: they replicate, hand over, and nothing is lost. You do this before planned maintenance or decommissioning. A seizure forces the new DC to take the role when the old holder is permanently gone. After a seizure, the old DC must never come back online as it was; you clean up its metadata and, if you ever recover it, rebuild it. Seizing the RID master in particular risks duplicate RID pools if the old holder reappears.
# Transfer (both DCs online)
Move-ADDirectoryServerOperationMasterRole -Identity DC2 -OperationMasterRole PDCEmulator,RIDMaster
# Seize (old holder is dead)
Move-ADDirectoryServerOperationMasterRole -Identity DC2 -OperationMasterRole SchemaMaster -Force
The same cmdlet does both jobs: without -Force it attempts a transfer; with -Force it seizes if a transfer fails. The older ntdsutil tool also offers transfer and seize commands under roles. Brief outages of most role holders go unnoticed, but losing the PDC emulator quickly shows up as time drift, lockout problems and password-change delays.
Key terms
- FSMO role
- A single-master operation in AD assigned to one DC per forest or domain.
- RID master
- Allocates pools of relative IDs to DCs so each new user, group or computer gets a unique SID.
- PDC emulator
- Domain-wide role handling time synchronization, urgent password changes, lockouts and GPO editing by default.
- Transfer
- A graceful role move while both the old and new holders are online.
- Seize
- A forced role takeover when the old holder is permanently unavailable; the old DC must not return.
DC1, holding all five roles, suffers a failed motherboard and will be rebuilt from scratch. The admin seizes all roles to DC2 with Move-ADDirectoryServerOperationMasterRole -Force, runs metadata cleanup for DC1, and later promotes the rebuilt hardware as a new DC with a new name.
Check yourself
Which FSMO role is the authoritative time source for a domain and handles account lockouts?
The PDC emulator.
When should you seize rather than transfer a role?
Only when the current holder is permanently offline and cannot be recovered; otherwise transfer so both DCs hand over cleanly.
How many FSMO roles exist in a single-domain forest?
Five: schema master and domain naming master (forest-wide) plus RID master, PDC emulator and infrastructure master (domain-wide).