Thursday 24 January 2019

Difference of Transferring and Seizing FSMO Roles

Whenever it's possible, you should transfer FSMO roles and do not seize them! Transferring is the recommended and cleaner way. But it requires that the DC, which currently owns the role you want to transfer, is still working and connected to the network. Transferring makes the old DC know that it does not own the role(s) any more.

If the DC is broken (e. g. hardware defect) and will never come back again, then you can seize the role on a remaining DC. It is very important that the old DC will never be connected to the network again, if it is connected again, this will cause conflicts and lead to an inconsistent AD. This is because the old DC will not notice the change and still feel responsible for tasks related to the role.

No comments:

Post a Comment

McAfee Endpoint Encryption 7.0 – Fatal Error: [0xEE0E0001]

Errors Fatal Error [ee000007] Internal initialization error Fatal error: File access error at startup  Fatal error: 0xEE0D0001 - Fail...