Register now or log in to join your professional community.
While Active Directory in general uses a multimaster replication scheme for replicating the directory database between domain controllers, there are certain directory functions that require they be performed on some specific domain controller. These functions are defined by flexible single master operations (FSMO) roles (pronounced "fiz-moe roles") and at any time these roles are uniquely assigned to specific domain controllers in different Active Directory domains. Let's begin by describing what these different FSMO roles are and why they are important, after which we'll outline some best practices for how you should assign these roles in your Active Directory environment.
Overview of FSMO RolesThere are five different FSMO roles and they each play a different function in making Active Directory work:
To summarize then, the Schema Master and Domain Naming Master roles are found only in the forest root domain, while the remaining roles are found in each domain of your forest. Now let's look at best practices for assigning these roles to different domain controllers in your forest or domain.
FSMO Roles Best PracticesProper placement of FSMO Roles boils down to three simple rules:
To summarize these three rules then and make them easy to remember: