Skip to main content
Support

FSMO Roles & Sites

Locate role holders and site topology

Intermediate~12 mincontoso.com
FSMO Roles & Sites
PS C:\>
Forest
Domain
DC
Sites

Step 1 of 7

What Are FSMO Roles?

Active Directory uses a multi-master replication model — every DC can process writes. But some operations must be handled by a single authority to prevent conflicts. These are the five Flexible Single Master Operations (FSMO) roles.

Forest-wide roles (one per forest):

  • Schema Master — controls schema changes
  • Domain Naming Master — controls adding/removing domains

Domain-wide roles (one per domain):

  • PDC Emulator — time sync, password changes, GPO coordination
  • RID Master — allocates unique ID pools to DCs
  • Infrastructure Master — resolves cross-domain references

Click "Continue" to start locating them.

Objectives

  • Forest-Wide Roles
  • Domain-Wide Roles
  • Roles Per DC
  • Global Catalog & Site Placement
  • Forest Sites
SourceSudo

Content sourced from Microsoft Documentation, MITRE ATT&CK Framework, NIST SP 800-63/171, adsecurity.org (Sean Metcalf), SpecterOps research, and SANS Reading Room. For educational purposes only.