{"id":1401,"date":"2011-11-14T20:35:16","date_gmt":"2011-11-14T20:35:16","guid":{"rendered":"http:\/\/www.obieta.com\/?p=1401"},"modified":"2011-11-14T20:35:16","modified_gmt":"2011-11-14T20:35:16","slug":"transferring-fsmo-roles-in-windows-server-2008","status":"publish","type":"post","link":"http:\/\/obieta.com\/?p=1401","title":{"rendered":"Transferring FSMO Roles in Windows Server 2008"},"content":{"rendered":"<div>\n<p>The five\u00a0<strong>FSMO roles<\/strong> are:<\/p>\n<ol>\n<li><strong>Schema Master<br \/><\/strong><\/li>\n<li><strong>Domain Naming Master<br \/><\/strong><\/li>\n<li><strong>Infrastructure Master<br \/><\/strong><\/li>\n<li><strong>Relative ID (RID) Master<br \/><\/strong><\/li>\n<li><strong>PDC Emulator<\/strong><\/li>\n<\/ol>\n<p><span style=\"font-size: x-small;\">The FSMO roles are going to be transferred, using the following three MMC snap-ins :<\/span><\/p>\n<ul>\n<li><span style=\"font-size: x-small;\"><strong>Active Directory Schema snap-in<\/strong> : Will be used to transfer the\u00a0<strong>Schema Master role<\/strong><br \/><\/span><\/li>\n<li><span style=\"font-size: x-small;\"><strong>Active Directory Domains and Trusts snap-in<\/strong> : Will be used to transfer the\u00a0<strong>Domain Naming Master role<br \/><\/strong><\/span><\/li>\n<li><span style=\"font-size: x-small;\"><strong>Active Directory Users and Computers snap-in<\/strong> : Will be used to transfer the\u00a0<strong>RID Master<\/strong>,\u00a0<strong>PDC Emulator<\/strong>, and\u00a0<strong>Infrastructure Master roles<\/strong><\/span><\/li>\n<\/ul>\n<p><strong>Note: The following steps are done on the Windows Server 2008 machine that I intend to set as the roles holder ( transfer the roles to it )<\/strong><\/p>\n<p>Lets start transferring the FSMO roles.<\/p>\n<ul>\n<li><span style=\"font-size: x-small;\"><strong>Using <\/strong><strong>Active Directory Schema snap-in to transfer the Schema Master role\n<p><\/strong>You have to register\u00a0<strong>schmmgmt.dll<\/strong> in order to be able to use the\u00a0<strong>Active Directory Schema snap-in<\/strong><br \/><\/span><\/li>\n<\/ul>\n<ol>\n<li>Click\u00a0<strong>Start<\/strong> &gt;\u00a0<strong>Run\n<p><\/strong><\/li>\n<li>Type\u00a0<strong>regsvr32 schmmgmt.dll\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/1-schmmgmt-snapin.png\" alt=\"\" width=\"421\" height=\"253\" \/><\/p>\n<p><\/strong><\/li>\n<li>Click\u00a0<strong>OK\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/2-schmmgmt-registered.png\" alt=\"\" width=\"371\" height=\"124\" \/><\/p>\n<p><\/strong>A popup message will confirm that\u00a0<strong>schmmgmt.dll<\/strong> was successfully registered. Click\u00a0<strong>OK<\/p>\n<p><\/strong><\/li>\n<li>Click\u00a0<strong>Start <\/strong>&gt;\u00a0<strong>Run<\/strong>, type\u00a0<strong>mmc<\/strong>, then click\u00a0<strong>OK\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/3-mmc.png\" alt=\"\" width=\"422\" height=\"259\" \/><\/p>\n<p><\/strong><\/li>\n<li>Click\u00a0<strong>File<\/strong> &gt; then click\u00a0<strong>Add\/Remove Snap-in&#8230;<\/strong>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/4-file-add-snapin.png\" alt=\"\" width=\"600\" height=\"411\" \/><\/p>\n<\/li>\n<li>From the left side, under\u00a0<strong>Available Snap-ins<\/strong>, click on\u00a0<strong>Active Directory Schema<\/strong>, then click\u00a0<strong>Add &gt;<\/strong> and then click\u00a0<strong>OK<br \/><\/strong><br \/><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/5-click-add-schema.png\" alt=\"\" width=\"674\" height=\"467\" \/>\n<\/li>\n<li>Right click\u00a0<strong>Active Directory Schema<\/strong>, then click\u00a0<strong>Change Active Directory Domain Controller&#8230;<\/strong>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/6-change-domain-controller-schema.png\" alt=\"\" width=\"594\" height=\"408\" \/><\/p>\n<\/li>\n<li>From the listed Domain Controllers, click on the domain controller that you want to be the schema master role holder and then click on\u00a0<strong>OK<\/strong>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/7-select-new-schema-master.png\" alt=\"\" width=\"630\" height=\"422\" \/><\/p>\n<p>You will receive a message box stating that the schema snap-in is not connected to a schema operations master. That is for sure, as we have not yet set this Windows Server 2008 domain controller as a Schema Master role holder. This will be done in the next step. Click\u00a0<strong>OK<\/strong><\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/8-not-a-schema-master.png\" alt=\"\" width=\"409\" height=\"165\" \/><\/p>\n<\/li>\n<li>In the console tree, right click\u00a0<strong>Active Directory Schema [DomainController.DomainName]<\/strong>, and then click\u00a0<strong>Operations Master&#8230;<\/strong>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/9-operations-master.png\" alt=\"\" width=\"653\" height=\"410\" \/><\/p>\n<\/li>\n<li>On the\u00a0<strong>Change Schema Master <\/strong>page, the current schema master role holder will be displayed ( ex. ELMAJ-DC.ELMAJDAL.NET) and the targeted schema holder as well (ex. ELMAJ-DC2K8.ELMAJDAL.NET). Once you click\u00a0<strong>Change<\/strong>, the schema master holder will become\u00a0<strong><br \/>ELMAJ-DC2K8.ELMAJDAL.NET<\/strong> , click\u00a0<strong>Change<\/strong><strong><br \/><\/strong><br \/><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/10-operations-master-change.png\" alt=\"\" width=\"350\" height=\"255\" \/>\n<p>Click\u00a0<strong>Yes<\/strong> to confirm the role transfer<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/10-operations-master-change-are-you-sure.png\" alt=\"\" width=\"373\" height=\"144\" \/><\/p>\n<p>The role will be transferred and a confirmation message will be displayed. Click\u00a0<strong>OK\u00a0<br \/><\/strong><br \/><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/11-operations-master-transferred-ok.png\" alt=\"\" width=\"307\" height=\"142\" \/><\/p>\n<p>Then click\u00a0<strong>Close<\/strong>, as you can see in the below snapshot, the current schema master is\u00a0ELMAJ-DC2K8.ELMAJDAL.NET<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/11-master-operation-completed.png\" alt=\"\" width=\"348\" height=\"253\" \/><\/p>\n<\/li>\n<\/ol>\n<ul>\n<li><span style=\"font-size: x-small;\"><strong>Using Active Directory Domains and Trusts snap-in to transfer the Domain Naming Master Role<\/strong><br \/><\/span><\/li>\n<\/ul>\n<\/div>\n<div>\n<ol>\n<li>Click\u00a0<strong>Start <\/strong>&gt;\u00a0<strong>Administrative Tools<\/strong> &gt; then click\u00a0<strong>Active Directory Domains and Trusts\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/12-domains-trust-snap-in.png\" alt=\"\" width=\"655\" height=\"535\" \/><br \/><\/strong><\/li>\n<li>Right click\u00a0<strong>Active Directory Domains and Trusts<\/strong>, then click\u00a0<strong>Change Active Directory Domain Controller&#8230;\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/13-domains-trust-change-dc.png\" alt=\"\" width=\"798\" height=\"294\" \/><br \/><\/strong><\/li>\n<li>From the listed Domain Controllers, click on the domain controller that you want to be the Domain Naming master role holder and then click on<strong>OK<\/strong>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/14-listed-dc.png\" alt=\"\" width=\"630\" height=\"424\" \/><\/p>\n<\/li>\n<li>Right click\u00a0<strong>Active Directory Domains and Trusts<\/strong>, then click\u00a0<strong>Operations Master&#8230;\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/15-domains-trust-operations-master.png\" alt=\"\" width=\"798\" height=\"299\" \/><\/p>\n<p><\/strong><\/li>\n<li>On the Operations Master page, we are going to change the Domain Naming role holder from\u00a0<strong>ELMAJ-DC.ELMAJDAL.NET <\/strong>to<strong> ELMAJ-DC2K8.ELMAJDAL.NET<\/strong>, Click\u00a0<strong>Change<\/strong>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/16-domain-naming-master-change.png\" alt=\"\" width=\"384\" height=\"269\" \/><\/p>\n<p>Click\u00a0<strong>YES<\/strong> to confirm the transfer of the Domain Naming role<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/17-domain-naming-are-you-sure.png\" alt=\"\" width=\"415\" height=\"145\" \/><\/p>\n<p>The role will be transferred and a confirmation message will be displayed. Click\u00a0<strong>OK <\/strong>, then click\u00a0<strong>Close<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/18-operations-master-transferred-domain-naming.png\" alt=\"\" width=\"348\" height=\"142\" \/><\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/18-operations-master-transferred-domain-naming-2.png\" alt=\"\" width=\"383\" height=\"266\" \/><br \/><\/strong><\/li>\n<\/ol>\n<\/div>\n<p>Till now, we have successfully transferred two FSMO roles, the Schema Master role and the Domain Naming role. The last three roles can be transferred using a single Snap-in.<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li><span style=\"font-size: x-small;\"><strong>Using Active Directory Users and Computers snap-in to transfer the RID Master, PDC Emulator, and Infrastructure Master Roles<\/strong><br \/><\/span><\/li>\n<\/ul>\n<ol>\n<li>Click\u00a0<strong>Start<\/strong> &gt;\u00a0<strong>Administrative Tools<\/strong> &gt; then click\u00a0<strong>Active Directory Users and Computers\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/19-AD-users-computers.png\" alt=\"\" width=\"651\" height=\"536\" \/><\/p>\n<p><\/strong><\/li>\n<li>Right click\u00a0<strong>Active Directory Users and Computers<\/strong>, then click\u00a0<strong>All Tasks<\/strong> &gt;\u00a0<strong>Operations Master&#8230;\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/20-AD-ALLTasks-Operations-master.png\" alt=\"\" width=\"763\" height=\"347\" \/><\/p>\n<p><\/strong><\/li>\n<li>You will have three Tabs, representing three FSMO roles (RID, PDC, Infrastructure). Click the\u00a0<strong>Change <\/strong>button under each of these three tabs to transfer the roles.\u00a0\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/20-AD-Operations-master-change.png\" alt=\"\" width=\"400\" height=\"446\" \/><\/p>\n<p>Click\u00a0<strong>Yes<\/strong> to confirm the role transfer<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/21-AD-are-you-sure-role-transfer.png\" alt=\"\" width=\"398\" height=\"143\" \/><\/p>\n<p>The role will be transferred and a confirmation message will be displayed. Click\u00a0<strong>OK\u00a0<br \/><\/strong><br \/><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/21-AD-trasnferred-ok.png\" alt=\"\" width=\"368\" height=\"144\" \/><\/p>\n<p>As for the\u00a0<strong>Infrastructure<\/strong> role, once you click on the\u00a0<strong>Change<\/strong> button you will receive the below message<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/22-infra-role-change.png\" alt=\"\" width=\"426\" height=\"167\" \/><\/p>\n<p>By default, when you first install your first Domain Controller, it holds the five roles and beside that it is a Global Catalog. If your environment is a multi-domain\/forest, then you should think about structuring your FSMO roles and transfer the Infrastructure role to a none Global Catalog domain controller. Else if you have small number of domain controllers ( ex. two domain controllers) then you should not worry about this. Click\u00a0<strong>Yes<\/strong><\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/21-AD-trasnferred-ok.png\" alt=\"\" width=\"368\" height=\"144\" \/><\/p>\n<\/li>\n<li>The Tabs should now look like this:\n<p><img loading=\"lazy\" src=\"http:\/\/www.elmajdal.net\/win2k8\/Transferring_FSMO_Roles_in_Windows_Server_2008\/23-RID-PDC-Infra.png\" alt=\"\" width=\"830\" height=\"895\" \/><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>That&#8217;s it, by now, you have successfully transferred the five FSMO roles to the Windows Server 2008 Domain Controller.<\/p>\n<p><span style=\"font-size: x-small;\"><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Summary<\/p>\n<p><\/strong>There are five FSMO roles in a forest, to transfer any of these roles you have to use the appropriate Active Directory snap-in. In my next article, I will be showing you the complete steps required to successfully migrate\/upgrade your domain controller to a new hardware server.<\/p>\n<p><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The five\u00a0FSMO roles are: Schema Master Domain Naming Master Infrastructure Master Relative ID (RID) Master PDC Emulator The FSMO roles are going to be transferred, using the following three MMC snap-ins : Active Directory Schema snap-in : Will be used to transfer the\u00a0Schema Master role Active Directory Domains and Trusts snap-in : Will be used [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,1],"tags":[],"_links":{"self":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts\/1401"}],"collection":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1401"}],"version-history":[{"count":0,"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts\/1401\/revisions"}],"wp:attachment":[{"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1401"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}