AD DS multi-master environment Replication means that all domain controllers And the ability to focus on the same general time Modify the AD DS database. However, some Operation should only be performed by a system. In AD DS, domain operations master The controller performs a specific function within the In a domain environment.
Forest-Wide Operations Master Roles
Schema master and domain naming Master in the forest must be unique. Each Only one paper from the domain controller in the forest.
Domain Naming Master Role
When you add or remove a domain, and application partition, domain, our role is to Forest. When you add or remove a domain or an application partition, the main domain, we must Access to, or the operation will fail.
Schema Master Role
Holds the schema master role is responsible for making any changes to the domain controller Forest architecture. Read-only mode holds a copy of all the other domain controllers. When you need Modify the schema changes must be sent to the domain controller that hosts the schema Master role.
Domain-Wide Operations Master Roles
Each domain maintains three single-master operations: Relative Identifier (RID) master, Owners of infrastructure, the primary domain controller (PDC) emulator. Each role is performed by only one Domain controllers in the domain.
RID Master Role
RID master role RID host security identifier (SID) is generated plays an important part of the security Principals such as users, groups, and computers. SID security principals must be unique. Because of Any domain controller can create an account, and therefore, a SID mechanism is necessary to ensure that SID generated by the domain controller is unique. Active Directory domain controller generates SID By adding a unique domain SI D. Domain RID RID master assigned a unique pool Off each domain controller in the domain. Thus, each domain controller cannot be sure It is unique in that it produces small island developing States.
Infrastructure Master Role
Infrastructure master role In a multi-domain environment, which is a phenomenon is something other areas. For example, a group may include members from other domains. Its multi-valued attribute members It contains the distinguished name of each member. If the transfer to another member or domain rename, update infrastructure master domain object reference group.
PDC Emulator Role
PDC emulator role PDC emulator to perform multiple roles, the key functional domains: • In the domain-specific password update process to participate. When the user's password reset or change, make changes to the domain controller will immediately replicate these changes to the PDC Simulator. This particular domain controller replication to ensure understanding of the new password As soon as possible.
• Management domain Group Policy updates. If you change a GPO two domains At about the same time, the controller can have two versions of possible conflicts As GPO replication cannot be reconciled. To avoid this situation, PDC emulator default focus Point out to change all of the group policy.
• The primary time source domain. Many parts of Windows and technology Depending on the time stamp, the system time is synchronized with the entire domain is essential. PDC emulator the forest root domain is the master of time, by default. PDC emulator in each Forest root domain synchronizes time with PDC emulator. Other domain controllers in the domain synchronize their clocks for domain PDC emulator. All other members of the sync domain their time and their preferred domain controller.
• Act as a domain master browser. When you open Windows, you can see a list of Workgroup and domain, when you open a workgroup or domain, you'll see a list of computers.
Guidelines for Placing Operations Master Roles
• The role of high-performance field-level domain controller.
• Do not when the global catalog server domain-level master role, in addition to your forest contains only one domain or forest to all domain controllers are also global Directory.
• stay on a domain controller in the forest root domain of the forest-level two roles.
• PDC emulator workload adjustments, if necessary, by offloading non-AD DS role servers