I'm not a heavyweight by any stretch of the imagination (at least not in the context of this thread) but I would move the roles prior to maintenance, since it takes about two minutes to do, there's a credible up-side and no real down-side.  I'm rather surprised that there's all this agonizing over what I've always considered to be a routine procedure.
 
Ed Crowley MCSE+Internet MVP (Exchange, NOT AD)
Freelance E-Mail Philosopher
Protecting the world from PSTs and Bricked Backups!™
 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rocky Habeeb
Sent: Tuesday, November 29, 2005 10:02 AM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] FSMO role transfer

OK,
I've been witing for this one.
If we have yet to move our 2K3 FFL DCs (Both Root Domain and Child Domain) to SP1 because of small concerns like "No one being able to log on", would you move the roles first (ie: Off the Forest Root FSMO and the Child Domain FSMO)?
 
Is that prudent?
 
A better question would be, how many of you heavyweights (joe, Dean, Al, Guido, Rick, Jorge, Deji, Brett, etc. etc., apologies to any other in the Heavyweight class not explicitly mentioned) [1] Did not move the roles, [2] Upgraded to SP1, [3] Went home to dinner with "NO" problems?
 
Thanks.
 
RH
______________________________-
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of Douglas M. Long
Sent: Tuesday, November 29, 2005 11:53 AM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] FSMO role transfer

It probably depends on what you’re doing during those 2 hours. If I were installing SP1 on a DC that had problems rebooting/booting in the past, or has known HW issues, or for some odd reason the machine is not on a UPS when installing a Service Pack, I think it would be easier to move the FSMO roles in the case of failure so that you don’t have to seize the roles and clean stuff up so quickly.

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Almeida Pinto, Jorge de
Sent: Tuesday, November 29, 2005 11:09 AM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] FSMO role transfer

 

First, look at each role and see what it does...

 

Forest FSMOs

* Schema Master --> needed when updating the schema

* Domain Naming master --> needed when adding or removing domains within the forest

 

Domain FSMOs

* PDC Emulator --> needed for legacy clients (NT4, W9x) when changing passwords, used for time sync, is used for pwd checking when a user enters an incorrect pwd at another DC, used by DFS roots to get DFS info

* RID Master --> needed to distribute RID pools to DCs that have exhausted their current RID pool for 50% (=250 RIDs)

* Infrastructure --> needed to update references between domains in a forest (does not do anything in a single domain forest)

 

If you look at this, there is no need to first transfer the FSMO roles to another DC, just to carry out maintenance activities. It also depends on the FSMO role. The most used ones in your case will be the RID and the PDC FSMO. Only if you create more than 500 security principals (users, groups and computers) during the moment that the DC with the RID FSMO is down, you will experience a problem on the DC that is left. If you still have legacy clients and they want to change the password that will not be possible. And if those clients have the DSClient installed that will not be an issue either.

 

In short: leave as is. it will be OK for those 2 hours

 

Cheers,

jorge

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Amy Hunter
Sent: Tuesday, November 29, 2005 16:43
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] FSMO role transfer

Hi guys,

 

We have two DC's, one which holds the Forest FSMO roles, the other which holds the domain FSMO roles.

 

I plan to take each server down at different times so that one of the two servers can provide authentication etc while the other gets maintained. 

 

Initially, I was planning on moving the FSMO roles to the other DC while maintainance work is carried out and transferring it back once it's online again. I would then do the same for the other DC.

 

I was then told that you don't need to move the FSMO roles when you perform maintenance on a DC holding the roles. Each server will be down for about 2hrs.

 

Does anyone have advice for me? I would like to move the roles for peace of mind knowing they are available, but if I don't need to do that, I won! 't bother

 

Is there any recommended practice?

 

Amy


To help you stay safe and secure online, we've developed the all new Yahoo! Security Centre.

This e-mail and any attachment is for authorised use by the intended recipient(s) only. It may contain proprietary material, confidential information and/or be subject to legal privilege. It should not be copied, disclosed to, retained or used by, any other party. If you are not an intended recipient then please promptly delete this e-mail and any attachment and all copies and inform the sender. Thank you.

Reply via email to